Issue 01 · Volume 2026 Kitchener, Ontario Edition: Editorial
Kitchener, ON · Happily building

Rutvik
Patel.

Securing distributed systems through Zero Trust and high-fidelity automation. Three years of building the boring kind of breach — the one that never happens.

Portrait of Rutvik Patel, security engineer ◦ Portrait · 001
30 → 5
Day MTTR · Vulnerability remediation
Currently
System Technical Analyst
London Language Institute · London, ON
01

Impact, by the numbers

Three years measured in outcomes rather than job titles. Every figure below traces to a system I actually ran.

01
30→5
Days
MTTR cut on vulnerability remediation
Enterprise vulnerability lifecycle · TCS
02
Zero Trust
Enforced
Entra ID Conditional Access and MFA across the org
London Language Institute
03
OWASP
Top 10
Web & network penetration assessments
Tech-Defence Labs · VAPT
04
SQLi
Critical finding
Production SQL injection, reported and patched
Found in the first week of the engagement
05
100%
Pass
Internal security audits cleared
Policy, DR and access controls
06
2
Certifications
CISM (ISACA) · CompTIA Security+
Verified and current
02

Where I've worked

Defence, then offence, then defence again — which is why I rank findings by what an attacker reaches first rather than by what a scanner colours red.

Mar 2025 — Present
London, ON

System Technical Analyst

London Language Institute

Administer and secure the organisation's Azure environment — virtual machines, networks and load balancers — and enforce a Zero Trust access model through Entra ID Conditional Access and MFA. Infrastructure deployment is automated with Terraform and ARM templates, so configuration is version-controlled rather than remembered.

AzureEntra IDTerraformZero TrustLog Analytics
Jul 2022 — Jun 2023
Ahmedabad, India

Assistant System Engineer

Tata Consultancy Services

Ran the enterprise vulnerability lifecycle through Intigriti — validating critical submissions and driving remediation with engineering teams inside SLA — and operationalised CybelAngel threat intelligence to detect brand abuse and coordinate takedown of phishing domains and leaked credentials.

IntigritiCybelAngelThreat IntelVulnerability Mgmt
Read the remediation case study →
Jan 2022 — Jun 2022
Ahmedabad, India

Intern Security Analyst

Tech-Defence Labs

Black-box and gray-box web application assessments with Burp Suite Pro, identifying and validating OWASP Top 10 vulnerabilities including SQL injection. Post-exploitation with Metasploit to test whether endpoint detection and incident response actually worked, documented against MITRE ATT&CK and NIST SP 800-115.

Burp Suite ProMetasploitOWASPMITRE ATT&CK
03

How I think about security

I grew up in India taking the family PC apart to see what happened. That curiosity turned into cybersecurity once I realised I cared more about how systems break than how they're assembled. After a B.Tech in Computer Science at Ganpat University and stints at Tech-Defence Labs and TCS, I moved to Canada for a Master of Applied Computing at the University of Windsor.

I'm now in Kitchener, Ontario, running the security stack at London Language Institute end to end. Off the clock I'm usually reading threat intel reports for fun or out on Ontario's trails.

Security isn't a product — it's a process. I build systems that assume breach and respond faster than an attacker can pivot.

Automate the boring

If I do something more than twice it should be a script. People make decisions; machines repeat.

Assume breach

Every system I build assumes the perimeter already failed. Defence in depth is the starting point, not the upgrade.

Measure everything

Security without metrics is guesswork. Track detection rates, response times and coverage gaps — then move them.

04

What I've built

Two systems I'd rebuild from scratch tomorrow, because they actually worked.

Azure · Entra ID

Zero Trust access for a multi-site organisation

Took an environment with inconsistent MFA coverage and manual deployments to enforced Conditional Access with break-glass accounts, legacy authentication blocked, and privileged roles reviewed.

Infrastructure is deployed through Terraform and ARM templates rather than the portal, so access policy and network configuration are version-controlled and reviewable instead of remembered.

Entra IDConditional AccessTerraformARMNSG
Wazuh · Tines

Automated threat remediation (SOAR)

An end-to-end automation pipeline for incident response. Wazuh detects, Tines orchestrates the workflow, Python validates the indicator against VirusTotal, and AWS WAF blocks confirmed malicious addresses at the edge.

The point wasn't speed for its own sake — it was removing the human from the slow path so that analysts spend their time on decisions instead of copy-paste.

WazuhTinesPythonVirusTotalAWS WAF
05

Case studies

CS-02 · SOAR · Incident response automation

Cut vulnerability remediation from 30 days to 5.

The team was running a quarterly-patch culture: a scanner finds something, a ticket sits, a patch window eventually happens, everyone hopes. I replaced it with an event-driven pipeline that triages, assigns and verifies, with proof of remediation built in rather than assumed.

30 → 5Day MTTR
SLAAuto-routed by severity
VerifiedClosed-loop re-scan on patch
  1. Normalised findings from multiple scanners into a single queue.
  2. Enriched each finding with asset owner, criticality and exploit-in-the-wild status.
  3. Auto-ticketed with an SLA per severity; isolated actively exploited CVEs.
  4. Re-scanned on patch deployment and reopened automatically on regression.
WazuhTinesPythonVirusTotalAWS WAF
06

What I'm good at

SIEM & detection engineering

Custom detection rules and threat hunting across cloud and on-prem, tuned so alerts mean something.

Azure cloud security

Zero Trust architecture, Conditional Access design, MFA rollout and privileged role review.

Penetration testing

OWASP and MITRE-aligned web and network assessments, reported with remediation steps rather than raw output.

SOAR & incident response

End-to-end automated response, from detection through validation to enforcement at the edge.

Vulnerability management

Enterprise vulnerability lifecycles from intake through remediation to verified closure.

Scripting & automation

Python and PowerShell for API integration, enrichment pipelines and infrastructure as code.

Microsoft SentinelSplunkWazuhTines AzureEntra IDTerraformKQL PythonPowerShellBurp Suite ProMetasploit NessusWiresharkMITRE ATT&CKNIST CSFISO 27001
07

Work with me

Available for scoped security engagements alongside my full-time role.

Assessment

Microsoft 365 & Azure hardening review

Read-only assessment against the CIS Azure Foundations Benchmark. You get a scored posture report, findings ranked by real exploitability rather than raw CVSS, and a plain-English remediation plan your team or MSP can execute.

From $300
Implementation

Entra ID Conditional Access & MFA rollout

Phased Zero Trust rollout. Break-glass accounts created and excluded first, every policy run in report-only before it is enforced, staged to a pilot group, and handed over with a runbook your team can maintain.

From $450

Engagements can run through Upwork for contracting and payment protection, or direct — whichever you prefer.

08

Credentials & education

Active

Certified Information Security Manager (CISM)

ISACA · Certified Nov 2025 · Valid to Jan 2029
Verify — certificate no. on request →
Active

CompTIA Security+ (SY0-701)

CompTIA · Issued Mar 2025 · Valid to Mar 2028
Verify — code on request →
Master of Applied ComputingUniversity of Windsor · Ontario, Canada
Sep 2023 — Dec 2024
B.Tech, Computer ScienceGanpat University · CGPA 8.48 · WES-verified Canadian equivalency
Nov 2018 — Dec 2022
09

Let's talk security.

Hiring

Looking for a security engineer

Open to roles where I own the security stack rather than file tickets about it.

Security EngineerSOC AnalystCloud Security
Get in touch →
Engagement

Need something secured

Tell me what you're running and what's worrying you. I'll give you an honest read on whether it's something I can help with — including if the answer is no.

M365 & Azure reviewEntra ID rolloutDetection engineering
Start a conversation →

Currently available · Response within 24 hours · Eligible to work in Canada on an open work permit.