Available for Full-Time Roles

Bridging technical security
with governance,
risk & compliance.

Cybersecurity professional based in Melbourne. ISO/IEC 27001 Lead Auditor with two years of enterprise security experience at Bosch supporting Honda Japan. Currently completing my Master of Cyber Security at RMIT University.

Location Melbourne, AU
Focus GRC · Risk · Audit
Status Open to opportunities
Jeshta M Rao at the Melbourne Cricket Ground
Cybersecurity · GRC
Jeshta M Rao
Credentials
ISO 27001 Lead Auditor + GRC Mastery
Experience
2+ years at Bosch (Honda Japan)
Currently
M.Cyber @ RMIT (final year)
Stack
ServiceNow GRC, NIST, Essential Eight, ISM

From signing automotive ECUs
to shaping security policy.

I'm an engineer who fell in love with the business side of security, the conversations, the trade-offs, the stories behind the controls.

My foundation is in computer science, but cybersecurity is where I found my craft. At Bosch Global Software Technologies, I spent two years on automotive cybersecurity for Honda Japan, radar and video ECU projects, secure on-board communication, secure monitoring, and secure lifecycle management. I learned what it means to engineer trust into systems that people depend on every single day.

Now in the final year of my Master of Cyber Security at RMIT University, my focus has shifted decisively toward GRC. My strengths are deep analytical thinking, structured reasoning, and clear stakeholder communication. I genuinely enjoy documentation, control reviews, and translating technical risk into business language that leadership can act on.

I bring a rare combination to the table: an engineer who has implemented controls in production, who now wants to design, govern and audit them at the organisational level.

2+
Years enterprise security experience at Bosch
6+
Industry certifications & verifiable credentials
3.3
GPA · Master of Cyber Security, RMIT
JP
Honda Japan global engineering customer projects
Core Strengths
Analytical Thinking Stakeholder Communication Documentation & Review Risk Translation Structured Reasoning Decision Making

A practitioner's path
to governance.

Feb 2025, Dec 2026 (Expected) Now
Master of Cyber Security
RMIT University · Melbourne, Australia · GPA 3.3 / 4.0
  • Specialising in governance, risk and compliance, secure software development, and security management.
  • Building a portfolio of GRC artefacts mapped to ISO/IEC 27001, NIST CSF and the ACSC Essential Eight.
  • Conducting group research on insider threat detection through adaptive behaviour analysis (see Research section).
Aug 2023, Dec 2024
Senior Engineer, Cyber Security
Bosch Global Software Technologies · Bengaluru, India · Honda Japan engagement
  • Managed enterprise security monitoring and access controls for Honda Japan, overseeing security event triage and coordinating incident investigation across cross-functional teams.
  • Coordinated vulnerability remediation with technical and business stakeholders, improving patch compliance and reducing organisational risk exposure.
  • Contributed to incident response workflows aligned to documented response procedures and SLA requirements.
  • Implemented Secure Boot for automotive Video ECUs using HSM-based signature verification, ensuring firmware authenticity and integrity.
  • Conducted security testing of in-vehicle communication protocols (SecOC over CAN/Ethernet), validating controls against defined security requirements.
  • Applied AUTOSAR security architecture principles to align embedded technical controls with organisational security requirements.
Feb 2023, Jul 2023
Cyber Security Intern
Bosch Global Software Technologies · Bengaluru, India
  • Contributed to implementation of secure monitoring and logging controls aligned with organisational security baseline requirements.
  • Performed security debugging using Trace32 for real-time memory inspection, peripheral monitoring, and breakpoint analysis.
  • Collaborated with domain experts on proof-of-concept security implementations for automotive embedded systems.

Bosch, presenting the work.

Beyond the day-to-day engineering, I've represented the cybersecurity practice at internal Bosch events, presenting our ADAS Security portfolio (Secure Boot, SecOC, secure logging, vulnerability monitoring) to stakeholders from across the organisation.

Bosch ADAS Security ESD-XC team at internal showcase
ADAS Security · Team Showcase
The ADAS Security ESD-XC stall, Bosch Bengaluru
Jeshta presenting ADAS Sensor Portfolio
Presenting
Walking through the ADAS Sensor Portfolio
Jeshta presenting ADAS Product Security Portfolio
Showcase
Explaining the Product Security Portfolio
Jeshta at Bosch Bengaluru campus
Bosch HQ
On-site, Bosch Bengaluru campus

GRC Through the Lens.

My ongoing publication where governance, risk and compliance frameworks meet real-world scenarios, not theory in isolation, but ISO 27001 and NIST controls mapped to the risks they were actually built to manage.

Independent Publication · Active

Where frameworks meet
the real world.

A growing collection of writeups exploring GRC the way it actually shows up at work, audits and the miscalculations made inside them, what a GRC analyst should actually do during a live attack, framework comparisons, and a recurring series mapping ISO/IEC 27001 Annex A controls to the risks they're designed to address.

ISO/IEC 27001 Annex A Controls Risk Mapping Audit Incident Response NIST CSF
Read the publication
A.5.15
Access Control Risk
A.8.16
Monitoring Gap
A.5.30
BCP Failure
A.8.28
Insecure Coding

Work I've shipped.

Live Project · Solo Build
/ 01

GRC Drift Lab, Original Framework + Interactive Web App

Personal Initiative · Oct 2025 – Present

An original GRC framework I designed, the GRC Drift Model, paired with a public interactive web application that teaches it. The Drift Model is a six-stage lifecycle showing how compliance and security reality drift apart over time, the controls that exist on paper but don't work in practice. The Lab features a live animated dual-cycle diagram (documented ideal vs silent reality), real-world breach mappings (Optus, Medibank, Latitude, Equifax, Wells Fargo) sourced from primary documents, and planned AI-marked scenario exercises.

Original Framework Next.js TypeScript Breach Research GRC Education
View Live Lab
Hands-on · ServiceNow GRC
/ 02

ISO 27001 & NIST Control Implementation on ServiceNow GRC

Personal Project · Active

Building practical GRC artefacts hands-on inside the ServiceNow GRC platform, configuring control libraries, authoring policy and control statements, mapping ISO/IEC 27001 Annex A and NIST CSF controls to risks, and producing risk registers, gap analyses, and control assurance summaries. Designed to demonstrate end-to-end GRC tooling fluency, not just theoretical framework knowledge.

ServiceNow GRC ISO 27001 NIST CSF Control Mapping Risk Register
Group Project
/ 03

Secure Voting Platform, Voter Registration System

Secure SDLC · RMIT University · 2025

Designed a secure voter registration and voting workflow with emphasis on integrity, authentication, and role-based access control. Applied secure SDLC principles to align technical controls with trust, audit, and compliance objectives. Group project for RMIT's Secure Software Development unit.

Secure SDLC RBAC Authentication Threat Modelling
View on GitHub
Best Project · 2023
/ 04

Automated Nutrition Tracker for Mid-Day Meals

Bachelor's Final Year Project · 2023

A computer-vision system supporting India's Anemia Mukt Bharat initiative. Students photograph their mid-day meal; the system identifies the dish, computes calorie and nutrient values, and tracks attendance via facial recognition. Provides a live dashboard for authorities to monitor child nutrition outcomes in government schools. Recognised as one of the best final year projects of 2023.

Computer Vision Facial Recognition Public Health Tech Dashboard
Bosch · Production
/ 05

Secure Boot & SecOC for Automotive ECUs

Bosch · Honda Japan Programme

Implemented HSM-based Secure Boot signature verification for Video ECUs to ensure firmware authenticity and integrity across the boot chain. In parallel, conducted security validation of Secure On-board Communication (SecOC) protocols across CAN and Automotive Ethernet, reporting findings to programme stakeholders.

Secure Boot HSM SecOC AUTOSAR

Investigating insider threat
through behaviour.

In Progress · RMIT University

Preventing Data Exfiltration by Malicious Insiders and Malware: An Adaptive Behaviour Analysis and Anomaly Detection Framework

Group Research · Master of Cyber Security · 2025–2026

A research initiative exploring how adaptive behaviour analytics and anomaly detection can be combined to identify data exfiltration attempts, both from malicious insiders and from malware acting on their behalf. The project sits at the intersection of technical detection (UEBA, anomaly modelling) and governance (insider threat policy, monitoring controls, privacy considerations), the kind of cross-domain problem that GRC roles increasingly face.

Insider Threat Data Exfiltration UEBA Anomaly Detection Behavioural Analytics Monitoring Controls

Frameworks, tools
& operating knowledge.

GRC & Frameworks
  • ISO/IEC 27001 Lead Auditor
  • NIST Cybersecurity Framework
  • ACSC Essential Eight
  • Risk Assessment
  • Compliance Management
  • Policy Development
  • Control Assurance
  • Third-Party Risk Management
Risk & Privacy
  • Risk Registers
  • Risk Treatment Planning
  • Vendor & Third-Party Risk
  • Australian Privacy Act (APP)
  • Audit Support
  • Evidence Collection
  • Insider Threat Awareness
Security Operations
  • Security Monitoring
  • Incident Response
  • Vulnerability Management
  • Access & Identity Management
  • SIEM Concepts
  • Security Event Handling
  • CI/CD Security Awareness
Tools & Platforms
  • ServiceNow GRC
  • Ghidra (Reverse Engineering)
  • Wireshark (Network Analysis)
  • CANalyzer / CANoe
  • Trace32
  • DOORS
  • Microsoft Office Suite

Certifications
& specialised training.

ISO/IEC 27001 Lead Auditor
Information Security Management
Verify on Credly
GRC Mastery
Governance, Risk & Compliance
Verify on Credly
Third-Party Risk Management 2025
SecurityScorecard Academy
Verify Certificate
Cyber Security Risk Management
Risk Frameworks & Practices · Udemy
Verify Certificate
CAN Protocol
In-Vehicle Communication · Udemy
Verify Certificate
AUTOSAR Architecture
Automotive Software Standards · Udemy
Verify Certificate
Master of Cyber Security
RMIT University · In Progress
Expected Dec 2026
Secure Boot & SecOC Implementation
Bosch Internal Training · Honda Japan Programme
Internal · Bosch Programme

A few things that
round me out.

Professional Cricket
A long-time cricketer, the discipline, captaincy and game-reading translate well into the way I think about risk.
Trekking Enthusiast
The mountains are my reset button. Trekking has taught me patience, planning, and how to keep moving when conditions change.
Hodophile
A traveller at heart, cultures, conversations and unfamiliar places are how I learn to think about systems differently.

Volunteering &
industry engagement.

Showing up for the cybersecurity community in Melbourne, volunteering, attending and learning from the people shaping the field locally.

Beyond conferences, I make it a point to attend talks, meetups and industry events around the city. The Australian cybersecurity community is genuinely welcoming, and the conversations you have at these events shape how you think about the work.

CyberCon 2025, Melbourne
Volunteer · AISA · Melbourne Convention Centre
Volunteered at Australia's largest annual cybersecurity conference, supporting attendee experience and engaging with practitioners across GRC, security operations and consulting.
Bosch Internal Cybersecurity Events
Presenter · Bengaluru
Presented the ADAS Security ESD-XC portfolio at multiple internal Bosch showcases, walking cross-functional stakeholders through Secure Boot, SecOC and vulnerability monitoring practices.
Melbourne Cybersecurity Meetups & Talks
Active participant · Ongoing
Regular attendee of cybersecurity talks and industry events around Melbourne, keeping a finger on the pulse of the local practitioner community.

Let's start a conversation.

I'm actively seeking GRC Analyst, Cybersecurity Analyst, Compliance Analyst and related roles across Australia. Open to a chat about full-time opportunities, contracts, or just to talk frameworks.

LinkedIn
Location
Melbourne, Victoria, Australia
Resume

Form submissions are delivered straight to my inbox.