Press any key or click to skip

Back to Portfolio

Ekonkar Singh

Cloud & AI Security Analyst

Profile Summary

I'm a security analyst working on cloud compliance and identity. Most of my work is turning written security requirements into something that can be checked automatically. I write controls as Policy-as-Code, test them, and build the tooling around them in Python, PowerShell and C#.

Outside work I focus on AI security. I contribute to Microsoft PyRIT, an open-source AI red-teaming framework, and presented research on network anomaly detection at CCIDSA 2026.

Certifications

  • Microsoft Certified: Cybersecurity Architect Expert (SC-100)
  • Microsoft Certified: Identity and Access Administrator Associate (SC-300)
  • Microsoft Certified: Fabric Analytics Engineer Associate (DP-600)
  • CompTIA Security+
  • ITIL v4 Foundation (ITIL 4)

Technical Skills

Identity & Access

Microsoft Entra ID, Conditional Access, Identity Governance, RBAC, Cross-Tenant Migrations

Security & Compliance

ITSG-33, NIST 800-53, Zero Trust, CIS Benchmarks, TBS Guardrails, SAST / DAST

Automation

Python, PowerShell, C# (.NET), Bash, Go, Policy-as-Code, OPA / Rego

Cloud & Platforms

Microsoft Azure, Microsoft 365, Microsoft Fabric, MSSQL, PostgreSQL, Git / CI/CD

Enterprise Tools

Jira, Power BI, Power Apps, Power Automate, Quest On Demand, ShareGate, Log Analytics

AI Security & Research

PyRIT, AI Red Teaming, PyTorch, Scikit-Learn, Self-Supervised Learning, Drift Detection

Security Tooling

nuclei, httpx, checkov, Kali Linux

Professional Experience

Support Analyst, ITBLAS

Shared Services Canada · Thunder Bay, Ontario

Jul 2025 – Present

What I do

  • Policy-as-Code (OPA/Rego): write security controls as policy for a live multi-tenant compliance platform, then run functional testing, troubleshoot failures and document each control.
  • Python: built a script that parses the source security standard and cross-checks the policy engine's controls against it one-to-one.
  • Azure, MSSQL: directing the move of a legacy local compliance database to an Azure database to reduce its attack surface, and wrote the documentation for the effort.
  • C#, .NET: optimized legacy code as part of the same database modernization.
  • CI/CD, Git: built pipelines with SAST and DAST scanning to catch vulnerabilities before deployment.
  • Tenant migrations: coordinated and tested the migration tooling, including Microsoft's Orchestrator tool while in preview. Prepared test cases, readied tenants, executed migrations and validated results, with heatmap dashboards for transfer status.
  • Power Apps, Power Automate: built a ticketing and change-tracking workflow with management reporting, which another team adopted.
  • Jira, Jira API: built custom workflows, and now building a portal that creates and searches issues through the API.

Co-op Student, Cloud Security and Compliance

Shared Services Canada · Thunder Bay, Ontario

Jul 2023 – May 2024

What I did

  • Microsoft 365: managed and configured tenant environments against baseline configurations and Microsoft implementation standards.
  • Microsoft Entra ID, RBAC: built and documented identity and role-based access workflows for administrative boundaries.
  • Compliance monitoring: implemented automated checks against M365 baseline configurations and tuned security logging.
  • Stakeholders: worked with TBS and CCCS on cloud guardrails, and facilitated weekly M365 Working Group sessions for partner departments.

Senior Conference Associate and Technical Analyst

Lakehead University, Conference Services · Thunder Bay, Ontario

Jan 2023 – Aug 2026

What I did

  • Data migration: led the move from the legacy on-prem booking system to Tripleseat as subject-matter expert, handling vendor communication and the rollout plan.
  • PCI-DSS: worked with the university's IT team to validate the new payment vendor's compliance.
  • Python, Bash: built automated pipelines to monitor system health.
  • AV and networking: set up and supported audio-visual, live-streaming and network systems for conferences across multiple venues.

Key Projects

Open-Source Security Contributions

github.com/ThryLox

Merged pull requests to Microsoft PyRIT, ProjectDiscovery httpx and uncover, and the Terraform AzureRM provider.

PythonGoAI Red TeamingCloud SecurityOpen Source

Aegis Sentinel — Agentic Security Auditor

github.com/ThryLox/aegis-sentinel

Autonomous cloud security auditor with zero-trust permission boundaries for AI agents.

JavaScriptTypeScriptAuth0AI AgentsCloud Security

Project Gavel — AI Compliance Auditor

github.com/ThryLox/project-gavel

Automated technical security & regulatory compliance auditing framework for enterprise LLMs.

PythonOllamaOpenAI APIAI SafetyLegal Tech

SSL-IDS — Anomaly Detection & Representation Learning

github.com/ThryLox/ssl-ids-2026

Research repository on contrastive self-supervised learning (SSL) for network flow anomaly detection under distribution shift.

PyTorchPythonMachine LearningNetwork SecurityResearch

Publications

  • Contrastive Representation Learning for Network Flow Anomaly Detection Under Distribution Shift. CCIDSA 2026, Lakehead University
  • Manifold-Based Novelty Detection for Network Intrusion: A Contrastive Self-Supervised Approach