Springboard Cybersecurity Trainee - Capstone Project:
End-to-End Penetration Testing Engagement
Performed a five-phase penetration test following industry methodologies from reconnaissance through executive reporting.
Conducted a comprehensive end-to-end penetration testing engagement for a fictional enterprise, simulating a real-world external security assessment. The project followed a structured five-phase methodology, including OSINT reconnaissance, network discovery and enumeration, vulnerability assessment, threat analysis, and executive reporting. Using industry-standard tools such as Nmap, Nessus, OpenVAS, Burp Suite, Nikto, Wapiti, and Metasploit, I identified critical security weaknesses, prioritized risks using CVSS scoring, and developed actionable remediation recommendations aligned with NIST and OWASP best practices. The engagement concluded with a professional technical report and executive summary designed to communicate findings to both technical teams and business leadership.
Springboard Cybersecurity Trainee Project:
OWASP Top 10 Web Application Security Assessment
Conducted a security assessment of a fictional e-commerce web application using the OWASP Top 10 (2025) framework to identify and evaluate critical web application vulnerabilities. The assessment focused on analyzing risks such as Injection and Broken Access Control, evaluating their potential impact on customer data and business operations, and developing practical remediation strategies. Recommendations included implementing parameterized queries, server-side input validation, role-based access control (RBAC), secure coding practices, and continuous security testing with SAST and DAST tools. This project demonstrates my understanding of application security, secure development principles, vulnerability analysis, and industry best practices for protecting modern web applications.
Springboard Cybersecurity Trainee Project:
Web Application Vulnerability Remediation
Developed a comprehensive remediation plan for a fictional e-commerce web application by analyzing critical security vulnerabilities identified through the OWASP Top 10 framework. The project assessed risks including SQL Injection, Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), Sensitive Data Exposure, and Insufficient Logging & Monitoring, prioritizing each based on potential business impact. I proposed practical remediation strategies such as parameterized queries, input validation, encryption, Content Security Policy (CSP), secure authentication controls, centralized logging, SIEM monitoring, and Secure SDLC practices. This project demonstrates my ability to translate vulnerability findings into actionable security improvements that strengthen application resilience and reduce organizational risk.
Springboard Cybersecurity Trainee Project:
Security Monitoring: Merging Cybersecurity Infrastructures
During a Global Hotel Chain Acquisition
Developed a strategic cybersecurity integration plan for a fictional global hotel chain merger, focusing on maintaining security visibility and minimizing risk during infrastructure consolidation. The project outlined a phased approach to asset discovery, risk assessment, SIEM integration, network security, identity and access management, ERP integration, and policy standardization. Emphasizing governance, continuous monitoring, and industry best practices, the plan demonstrated how effective security operations can support a successful merger while strengthening the organization’s overall cybersecurity posture.

