I build security tools and laboratory platforms that turn cloud, identity, endpoint, and network telemetry into explainable security decisions.
My work focuses on Python security engineering, GCP and AWS security, identity and access analysis, detection-as-code, and analyst-controlled AI automation. I am currently pursuing an MCA in Cybersecurity and am open to entry-level Security Engineer, Cloud Security, Detection Engineering, Product Security, and SOC Engineering opportunities in India.
| Project | Engineering focus | Verifiable evidence |
|---|---|---|
| GCP IAMGraph | Explainable GCP IAM authorization and attack-path analysis | Three-state ALLOW/DENY/UNKNOWN decisions, inherited deny policies, SARIF, Python 3.10–3.12 CI, 74 tests, 91.33% coverage, versioned releases |
| Enterprise Cloud Security Monitoring Platform | AWS cloud-security monitoring and detection engineering | Terraform, CloudTrail, WAF, VPC Flow Logs, Splunk, MITRE ATT&CK detections, CI validation and incident-response evidence |
| Automated LLM Vulnerability Assessment | Reproducible adversarial evaluation of local LLMs | NVIDIA garak, matched baseline/guarded experiments, Python analysis, tests, CI and structured result artifacts |
| AI-Augmented SOC Triage Platform | Evidence-driven SOC triage with local AI | Splunk, Ollama, Sysmon, Suricata, YARA, MITRE ATT&CK, audit records and approval-gated response workflows |
- Cloud and identity security: GCP IAM, AWS IAM, privilege escalation, policy inheritance and least privilege
- Detection engineering: Splunk SPL, detection-as-code, Sysmon, Suricata, CloudTrail, WAF and VPC Flow Logs
- Security automation: Python tooling, structured evidence, SARIF, CI quality gates and reproducible testing
- AI security: LLM red teaming, prompt-injection testing, guardrail evaluation and analyst-controlled AI workflows
- Incident response: alert triage, MITRE ATT&CK mapping, forensic evidence, investigation workflow and remediation documentation
- Evidence before conclusions
- Explicit uncertainty instead of unsafe assumptions
- Least-privilege and read-only defaults
- Deterministic, reproducible output
- Human approval before containment
- Honest limitations and documented threat models
Languages and automation: Python, PowerShell, Bash, SQL, HCL
Cloud and infrastructure: GCP, AWS, Terraform, Linux, Windows, VMware
Security engineering: IAM, Splunk, Sysmon, Suricata, YARA, SARIF, MITRE ATT&CK
Assessment and validation: Burp Suite, Nmap, Nessus, Trivy, garak, Wireshark
Frameworks: NIST CSF, NIST SP 800-61, OWASP Top 10, ISO/IEC 27001 concepts
I am extending GCP IAMGraph with live, read-only cloud collection, differential validation against authoritative authorization decisions, performance benchmarks, and additional policy semantics.
I am also interested in contributing to open-source projects across cloud security, IAM, detection engineering, and AI security.
- Certified Ethical Hacker (CEH v13)
- Computer Hacking Forensic Investigator (CHFI)
- BCA graduate; pursuing MCA in Cybersecurity
All offensive-security activity documented in these repositories was performed in isolated, authorized laboratory environments.


