Calgary, Alberta, Canada M.Eng (Computer Networks) CISSP-Certified

DIIPESSH MISTRY

Senior Security Engineer • Vulnerability Management • Cloud Security Architect

Over 15+ years of cross-domain IT infrastructure and security engineering experience, with 10+ years dedicated to cyber defense, vulnerability discovery, remediation pipelines, and attack surface elimination across multi-cloud (Azure, Google Cloud Platform, AWS), Windows, Linux, and industrial ICS/OT environments. Proven leadership serving Government of Canada critical assets, enterprise telematics, and high-assurance digital platforms.

Core Practice Profile

Independent Advisory & Enterprise Security Engineering

15+
Years in Enterprise IT
10+
Years Cyber Defense
100%
Automated Remediation
Multi-Cloud
Azure • GCP • AWS
Founder & Chief Architect exaltissystems.com →
Leading Exaltis Systems in architecting managed vulnerability posture management, vCISO advisory, and cloud infrastructure security frameworks.

Professional Experience

Demonstrated track record of delivering enterprise-scale threat protection, vulnerability automation, and security posture engineering across high-stakes environments.

Technology Lead - Security

Infosys Public Services • Government of Canada Engagement
Jan 2025 – Present Calgary, AB (Remote)
  • Protect and harden internet-facing web assets and the cloud platform hosting the client's most critical public sector systems, closing misconfigurations before breaching compliance baselines.
  • Drive vulnerability management: execute recurring scans, steer remediation workflows with system owners, and report exposure through risk-management dashboards and executive briefings.
  • Detect and respond: analyze Microsoft Sentinel telemetry to identify and intercept bot attacks, malicious crawlers, and hostile activity targeting public assets.
  • Analyze malware samples and publish threat intelligence reports covering phishing, DLP events, and incidents induced by misconfigured cloud systems.
  • Designed phishing and vishing simulation programs and security awareness campaigns, complete with metric tracking dashboards presented directly to executive leadership.
Microsoft Sentinel Azure Security Vulnerability Remediation ITSG-33 Threat Intelligence Malware Analysis

Senior Security Administrator / Security System Administrator

Geotab Inc.
May 2019 – Jan 2025 (5.5+ Years) Remote / Global Fleet Telematics
  • Automated vulnerability scanning and reporting via Bash and RESTful API integrations across Tenable.io (Nessus) and Qualys; automated Google Cloud Platform firewall rule configuration and asset tagging.
  • Conducted technical security assessments and penetration tests; architected robust security controls across AWS and GCP environments with timely remediation pipelines.
  • Executed comprehensive security design and impact reviews on proposed architectures before release to neutralize regressions and integrated automated security gates into CI/CD pipelines.
  • Enforced strict least-privilege access governance on Google Cloud (IAM, RBAC, service accounts, Cloud Firewall) and automated role provisioning through custom PowerShell and Bash portals.
  • Deployed and managed enterprise security tooling across the fleet: CrowdStrike Falcon, Tenable Nessus agents, Duo MFA, Splunk SIEM, and Zscaler.
  • Automated vulnerability audits, patch management, and baseline system hardening across heterogeneous operating systems (Windows, Linux) and network infrastructure.
Google Cloud Platform AWS Tenable.io Qualys CrowdStrike Falcon Splunk SIEM Bash Automation Duo MFA Zscaler

Cybersecurity Specialist - ICS

BBA Engineering Ltd.
Nov 2019 – Apr 2020 Calgary, AB
  • Formulated industrial control system (ICS/OT) site-assessment methodologies to expose vulnerability postures and threat vectors across operational technology environments.
  • Authored compliance-ready consulting assessments and architecture roadmaps for mission-critical instrumentation, safety systems, and industrial networking.
  • Standardized reusable assessment templates, oversaw patch deployment procedures, and implemented advanced threat detection tooling within SCADA ecosystems.
ICS / SCADA Security OT Risk Assessment Site Audit Methodologies Safety Instrumented Systems

Security Operations Center Analyst

Uzado Inc.
Mar 2019 – May 2019 Vaughan, ON
  • Conducted vulnerability scanning, prioritized remediation tracking, and compliance validation utilizing Qualys.
  • Analyzed SIEM telemetry, deep network traffic packet captures, and host security event logs to generate actionable intelligence for stakeholders.
SOC Operations Qualys VM SIEM Analysis Network Traffic Analysis

Senior Systems Analyst / Team Lead

WBM Technologies Inc.
Oct 2013 – Aug 2018 (5 Years) Calgary, AB / Regina, SK
  • Resolved critical escalated operational and security incidents, monitored attack trends, and maintained enterprise firewall and IDS/IPS controls across data centers.
  • Led the province-wide executive rollout of the Government of Saskatchewan Next Generation Desktop and MDM platform, overseeing engineering personnel, incident workflows, and crisis simulation exercises.
Firewall & IDS/IPS Enterprise MDM Incident Management Public Sector Deployments

Education & Industry Certifications

Rigorous academic foundation in computer networking coupled with globally recognized vendor and governance certifications.

Academic Credentials

Master of Engineering (M.Eng) in Computer Networks
Toronto Metropolitan University (formerly Ryerson University)
Toronto, ON • Conferred October 2019
Post-Graduate Diploma, Information Technology Professionals
Lambton College of Applied Arts and Technology
Sarnia, ON • Conferred December 2011
Bachelor of Technology (B.Tech) in Computer Engineering
Ganpat University
Gujarat, India • Conferred August 2009

Professional Certifications

CISSP – Certified Information Systems Security Professional
(ISC)² • Global Cybersecurity Leadership Standard
Credentialed
CCNA Routing & Switching • CCNA Security
Cisco Systems • Enterprise Network Defense
Certified
MCSA – Microsoft Certified Solutions Associate
Microsoft • Server Infrastructure & Identity
Certified
CompTIA Network+ • CompTIA Project+
CompTIA • Network Architecture & Delivery Management
Certified
Fortinet Network Security Expert (NSE 1, 2 & 3)
Fortinet • Firewall & Perimeter Security
Certified

Technical Arsenal

Battle-tested engineering competencies across enterprise security platforms, orchestration scripting, and regulatory controls.

Vulnerability Discovery
Tenable.io & Qualys VM
End-to-end scanning orchestration, API automation, vulnerability prioritization, and enterprise patch verification.
Multi-Cloud Security
GCP, Azure & AWS Hardening
Strict least-privilege IAM, service account posture, Cloud Firewall rule optimization, and multi-tenant isolation.
Detection & SIEM
Microsoft Sentinel & Splunk
KQL analytics, threat hunting queries, automated alert correlation, and hostile bot interception.
Endpoint & Zero Trust
CrowdStrike, Zscaler & Duo
Falcon EDR enterprise management, cloud-delivered proxy filtering, and multi-factor access authentication.
Security Automation
Bash & PowerShell Scripting
Automated vulnerability reporting pipelines, REST API workflows, and custom role provisioning portals.
DevSecOps Integration
CI/CD Pipeline Security Gates
Pre-commit vulnerability auditing, dynamic application analysis, and container security integration.
Application Security
Aqua & Netsparker DAST
Dynamic application scanning, container image posture audits, and web application attack surface minimization.
Network Defense
FortiGate, SonicWall & IDS/IPS
Deep packet inspection, enterprise gateway policies, intrusion detection/prevention, and perimeter defense baselining.
Public Sector Compliance
ITSG-33 & Government of Canada PBMM
Government of Canada security control cataloging, FedRAMP alignment, SOC 2 readiness, and risk reporting.
Enterprise Governance
SOC 2, ISO 27001 & CMMC L2
Multi-cloud compliance alignment, security controls gap analysis, audit readiness, and technical evidence validation.
Industrial Security
ICS / SCADA Posture Assessment
Operational technology security methodologies, safety instrumentation analysis, and segmented zone audits.
Human Risk Engineering
KnowBe4 Phishing & Vishing
High-fidelity simulation campaign design, executive risk briefings, and metric-tracked employee awareness programs.

Practice Areas

Strategic cyber advisory, automated vulnerability operations, and enterprise defense offered through Exaltis Systems.

PRACTICE // 01

Enterprise Vulnerability Management

Building scalable, repeatable vulnerability discovery pipelines. Automating scanning routines across Tenable and Qualys with programmatic ticket creation and stakeholder reporting.

  • API-driven scanning automation
  • Risk-based triage & scoring
  • Executive vulnerability scorecards
PRACTICE // 02

Cloud Infrastructure Hardening

Securing Microsoft Azure and Google Cloud environments against configuration drift and lateral movement. Rigorous enforcement of least-privilege IAM and granular Cloud Firewall governance.

  • IAM & RBAC privilege reduction
  • Cloud perimeter firewall auditing
  • Multi-cloud compliance alignment
PRACTICE // 03

vCISO & Regulatory Alignment

Executive cybersecurity oversight for scaling organizations and public sector contractors. Navigating complex compliance baselines including ITSG-33, PBMM, ISO 27001, and SOC 2.

  • Security design & impact reviews
  • Audit readiness & Gap mitigation
  • Executive & Board-level risk reporting

Security Architecture Scope Estimator

Calculate estimated engineering capacity, engagement model, and governance deliverables tailored to your organizational scale.

Small Business (20) Mid-Market (500) Enterprise (1,500+)
Recommended Architecture Model
Directed Sprint (4–6 Weeks)
Designed for standard infrastructures: API automated scanning pipelines, least-privilege IAM hardening, and an executive gap-remediation roadmap.
Apply to Engagement Request

Initiate Consultation

Available for enterprise security advisory, vulnerability architecture engagements, and confidential consultations.

Direct Contact Details

Direct inquiries are typically acknowledged within 1 business day (Mountain Time).

Direct Email
Direct Telephone
LinkedIn Profile
Corporate Platform