Skip to content
mdhimancsPublic

About

aboutme5

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

52 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Munish Dhiman — Cybersecurity & IAM Portfolio

Production Build Security Standard Architecture

CISO / dyCISO Track | Principal Cybersecurity & IAM Architect - IAM, Digital Security, Directory Entitlements | Former SVP, Goldman Sachs

Transforming enterprise security posture through Zero Trust Architecture, Scalable IAM Governance & AI-Driven Risk Resilience. 21+ years protecting Fortune 100 infrastructures across Goldman Sachs and global tech leaders.


🛡️ Executive Summary

  • 21+ Years directing enterprise defense, identity architecture, and security governance across Tier-1 financial institutions.
  • 5M+ Identities Protected: Scaled modern identity fabrics across workforce, multi-cloud workloads, and machine/non-human identities.
  • Unblemished Regulatory Record: 0 audit findings across SOX 404, GLBA, and GRC controls over 3+ consecutive years.
  • Zero Standing Privilege: Engineered JIT PAM modernization driving a 98.4% reduction in privileged credential exposure.

⚡ Key Highlights & Core Capabilities

  • Executive Strategy & Board Governance: C-suite cyber governance, $18.5M modernization budgets, Architecture Review Board (ARB) leadership, and regulatory audit compliance.
  • Identity Fabric & Access Architecture: OAuth 2.0, OIDC, SAML 2.0 federation, hybrid Entra ID / Active Directory Tier-0 hardening, SailPoint IGA, and privileged access workflows.
  • Zero Trust Architecture (NIST 800-207): Continuous verification, phishing-resistant FIDO2 WebAuthn authentication, micro-segmentation, and zero standing privilege (ZSP / JIT).
  • Hybrid Multi-Cloud Security: Enterprise PKI / Hardware Security Modules (HSMs), AWS & Azure Cloud Security Posture Management (CSPM), and high-frequency trading enclaves.
  • Autonomous Threat Detection: Real-time operational intelligence, SIEM/SOAR automation, and dynamic perimeter deny lists.

🚀 Getting Started

Prerequisites

  • Node.js: v18.0.0 or higher (v20+ recommended)
  • npm or bun

Installation & Development

# Clone the repository
git clone https://github.com/mdhimancs/portfolio.git
cd portfolio

# Install dependencies
npm install

# Start local development server (runs on port 3000)
npm run dev

Open http://localhost:3000 in your browser.

Production Build & Verification

# Compile and build the production bundle
npm run build

# Run TypeScript linting verification
npm run lint

🔒 Security & Defense Implementation

The application incorporates strict defense-in-depth measures:

  • Content Security Policy (CSP): Hardened CSP restricting script, object, and style evaluation.
  • Mandatory HTTP Headers: HSTS, X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, and strict Permissions-Policy.
  • Zero-Trust Resource Gate: Protected executive blueprints, case studies, and patents gated by Firebase Authentication and Firestore allowlist RBAC.
  • Time-Bound Sessions: Cryptographically signed access links valid for 8 hours for executive search partners and board committees.
  • Anti-Abuse Safeguards: Form honeypot defense, client-side submission rate limiting, and server-side IP throttling.

For complete architectural specifications, see PROJECT_GUIDE.md and 4_webSecurity.md.


📚 Project Documentation

  • PROJECT_GUIDE.md: Master deployment, security, and architectural documentation.
  • 2_DEPLOYMENT.md: Hosting guides for GitHub Pages, Vercel, Netlify, and Cloud Run.
  • 4_webSecurity.md: Web security policies, HTTP headers, and access control specs.
  • 3_Ideas.md: UI/UX design blueprints and segmented tab design systems.
  • Ideas.md: Future capabilities and strategic feature roadmap.

📬 Contact & Connect

About

aboutme5

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages