Justin Min

Cybersecurity & GRC Specialist

📄 View Resume 📫 Contact Me

View My GitHub Profile

☁️ Cybersecurity Cloud Risk Analyst Internship: GSU Capstone

Role: Lead Cloud Risk Analyst

Client: Georgia State University Cybersecurity Services Team

Duration: Spring 2025 (Jan - April)

Tools: AWS CloudShell, Prowler (CLI), Qualys TotalCloud, Microsoft Teams, Google Meets


📌 Project Executive Summary

Engaged as a Cybersecurity Cloud Risk Analyst to conduct a comprehensive Cloud Security Posture Management (CSPM) assessment of the Georgia State University AWS Sandbox environment. The objective was to identify security misconfigurations, validate compliance against federal standards, and deliver a strategic remediation plan to the GSU Cybersecurity Services Team.

Operating within a 5-person team, I facilitated the deployment of both open-source (Prowler) and enterprise (Qualys TotalCloud) scanning tools. We successfully identified critical vulnerabilities including Identity and Access Management (IAM) and Storage (S3), mapped these findings to NIST SP 800-171, and presented a formal risk mitigation strategy to client stakeholders.


🛠️ Technical Implementation & Methodology

1. Automated Vulnerability Scanning (CSPM & CNAPP)

We utilized a dual-tool approach to ensure comprehensive coverage of the AWS environment.

2. Framework Cross-Walking & Compliance Mapping

A major challenge identified during the project was that Qualys TotalCloud did not provide native mapping to our required standard, NIST SP 800-171.

3. Risk Calculation & Matrix Development

To translate technical jargon into business intelligence, we developed a custom 4x4 Risk Matrix.


🚨 Key Findings & Remediation

During the assessment, we identified several critical security gaps. Two notable examples included:

Finding 1: Lack of MFA on Root Account (Critical)

Finding 2: S3 Bucket Public Access Block Not Enabled (High)


🧠 Challenges Overcome


📂 Project Artifacts

Below are the documents and presentations delivered to the Georgia State University Cybersecurity Team:


💡 Skills & Competencies Demonstrated

Technical Skills GRC & Strategy Soft Skills
AWS Cloud Security (IAM, S3, VPC) NIST RMF & 800-171 Executive Presentation
Linux CLI (Bash, Shell Scripting) ISO 27001 & SOC 2 Client Relationship Mgmt
Vulnerability Scanning (Prowler, Qualys) Risk Scoring & Matrices Technical Writing
Python (Script execution) Compliance Mapping Team Leadership

Back to Projects

Back to Main Portflio Home