Skip to content
View Parakh-Shinde's full-sized avatar
:dependabot:
:dependabot:

Block or report Parakh-Shinde

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Parakh-Shinde/README.md

Parakh Shinde

Security Engineering · Cloud IAM · Detection Engineering · AI Security

I build security tools and laboratory platforms that turn cloud, identity, endpoint, and network telemetry into explainable security decisions.

My work focuses on Python security engineering, GCP and AWS security, identity and access analysis, detection-as-code, and analyst-controlled AI automation. I am currently pursuing an MCA in Cybersecurity and am open to entry-level Security Engineer, Cloud Security, Detection Engineering, Product Security, and SOC Engineering opportunities in India.

LinkedIn GitHub

Selected engineering work

Project Engineering focus Verifiable evidence
GCP IAMGraph Explainable GCP IAM authorization and attack-path analysis Three-state ALLOW/DENY/UNKNOWN decisions, inherited deny policies, SARIF, Python 3.10–3.12 CI, 74 tests, 91.33% coverage, versioned releases
Enterprise Cloud Security Monitoring Platform AWS cloud-security monitoring and detection engineering Terraform, CloudTrail, WAF, VPC Flow Logs, Splunk, MITRE ATT&CK detections, CI validation and incident-response evidence
Automated LLM Vulnerability Assessment Reproducible adversarial evaluation of local LLMs NVIDIA garak, matched baseline/guarded experiments, Python analysis, tests, CI and structured result artifacts
AI-Augmented SOC Triage Platform Evidence-driven SOC triage with local AI Splunk, Ollama, Sysmon, Suricata, YARA, MITRE ATT&CK, audit records and approval-gated response workflows

What I work on

  • Cloud and identity security: GCP IAM, AWS IAM, privilege escalation, policy inheritance and least privilege
  • Detection engineering: Splunk SPL, detection-as-code, Sysmon, Suricata, CloudTrail, WAF and VPC Flow Logs
  • Security automation: Python tooling, structured evidence, SARIF, CI quality gates and reproducible testing
  • AI security: LLM red teaming, prompt-injection testing, guardrail evaluation and analyst-controlled AI workflows
  • Incident response: alert triage, MITRE ATT&CK mapping, forensic evidence, investigation workflow and remediation documentation

Engineering principles

  • Evidence before conclusions
  • Explicit uncertainty instead of unsafe assumptions
  • Least-privilege and read-only defaults
  • Deterministic, reproducible output
  • Human approval before containment
  • Honest limitations and documented threat models

Technical toolkit

Python PowerShell Google Cloud AWS Terraform Splunk Linux GitHub Actions

Languages and automation: Python, PowerShell, Bash, SQL, HCL
Cloud and infrastructure: GCP, AWS, Terraform, Linux, Windows, VMware
Security engineering: IAM, Splunk, Sysmon, Suricata, YARA, SARIF, MITRE ATT&CK
Assessment and validation: Burp Suite, Nmap, Nessus, Trivy, garak, Wireshark
Frameworks: NIST CSF, NIST SP 800-61, OWASP Top 10, ISO/IEC 27001 concepts

Current direction

I am extending GCP IAMGraph with live, read-only cloud collection, differential validation against authoritative authorization decisions, performance benchmarks, and additional policy semantics.

I am also interested in contributing to open-source projects across cloud security, IAM, detection engineering, and AI security.

Credentials

  • Certified Ethical Hacker (CEH v13)
  • Computer Hacking Forensic Investigator (CHFI)
  • BCA graduate; pursuing MCA in Cybersecurity

Contact

All offensive-security activity documented in these repositories was performed in isolated, authorized laboratory environments.

Popular repositories Loading

  1. Network-Vulnerability-Project Network-Vulnerability-Project Public

    Network Vulnerability by Nessus tool

  2. Enterprise-Cybersecurity-Compliance-Hardening-Assessment-Project Enterprise-Cybersecurity-Compliance-Hardening-Assessment-Project Public

    Comprehensive cybersecurity hardening and compliance assessment for an enterprise environment modeled on Fed F1rst Control Systems. Showcases end-to-end skills in endpoint security, compliance audi…

  3. Enterprise-Security-Hardening-Compliance-Assessment-for-CryptoV4ult Enterprise-Security-Hardening-Compliance-Assessment-for-CryptoV4ult Public

    A full-scope cybersecurity hardening and compliance assessment for CryptoV4ult, a global cryptocurrency platform. This project demonstrates end-to-end capabilities in Secure SDLC integration, vulne…

  4. Ransomware-Detection-and-Incident-Response-Lab Ransomware-Detection-and-Incident-Response-Lab Public

    Controlled ransomware detection and incident-response lab using Sysmon, Wireshark, Volatility, MITRE ATT&CK, and NIST SP 800-61.

  5. Parakh-Shinde Parakh-Shinde Public

  6. Enterprise-Web-Application-VAPT Enterprise-Web-Application-VAPT Public

    Enterprise Web Application Penetration Testing | DVWA | OWASP Juice Shop | Burp Suite | SQLMap | Hydra | Kali Linux