Executive Summary
Cybersecurity professional with hands-on experience across offensive security, threat analysis, vulnerability assessment, and GRC. Experienced in web and network security testing, reconnaissance, security automation, and risk assessment using industry frameworks.
Proficient in Kali Linux, Burp Suite, Metasploit, Nmap, Wireshark, Python, and Bash, with practical experience in OWASP Top 10, DAST, malware analysis, threat intelligence, and security risk management.
TECHNICAL_STRENGTHS
- Web Exploitation & Vulnerability Assessment
- Network Recon & Enumeration
- Threat Intel & Log Analysis
- Python & Bash for Automation
- AI-Assisted Security Analytics
Methodology
Blue Team — SOC & Detection
15Detection, log analysis, and incident response.
- 01Threat Detection
- 02Log Analysis
- 03Incident Response
- 04Incident Triage
- 05Network Traffic Analysis
- 06IOC Analysis
- 07MITRE ATT&CK
- 08CVE Prioritization
- 09Malware Analysis
- 10Wireshark
- 11Tshark
- 12OpenVAS
- 13Nessus
- 14OWASP ZAP
- 15Splunk
Red Team — Offensive Security
19Web and network exploitation, tooling, and recon.
- 01Web & Network Pentesting
- 02OWASP Top 10
- 03SQL Injection
- 04XSS & CSRF
- 05API Security
- 06Kali Linux
- 07Metasploit
- 08Burp Suite
- 09Nmap
- 10Recon-ng
- 11Maltego
- 12Hydra
- 13Nikto
- 14Gobuster
- 15SQLMap
- 16John the Ripper
- 17Hashcat
- 18Frida
- 19APKTool
Languages, Systems & AI
13Automation, scripting, and AI-assisted analytics.
- 01Python
- 02Bash
- 03C++
- 04Java
- 05SQL
- 06TCP/IP
- 07Linux
- 08Windows
- 09TF-IDF Analysis
- 10Behavior Correlation
- 11CVE Severity Prediction
- 12Threat Intelligence Mapping
- 13Security Automation
GRC & Compliance
09Risk assessment, control mapping, and compliance frameworks.
- 01Risk Assessment
- 02Security Policies & Procedures
- 03Control Mapping
- 04Audit Evidence Collection
- 05NIST SP 800-30
- 06NIST CSF 2.0
- 07ISO 27001:2022 Annex A
- 08PCI DSS
- 09DPDP Act
Experience
- June 2026 – August 2026

Research Intern
— DRDO Headquarters (DRDO Bhawan), Ministry of Defence- Contributed to cybersecurity research through literature surveys and comparative analysis of contemporary cybersecurity approaches relevant to the DRDO Directorate of Planning & Coordination.
- Researched the recovery of legacy glyph-encoded Devanagari text into standard Unicode for cross-lingual access to bilingual defence archives, formulating the problem as a context-aware sequence normalization task.
- Developed a regression-tested rule-based normalizer and an automatic reverse-rendering pipeline to generate aligned training data without manual annotation.
- Fine-tuned a compact byte-level neural model and conducted dataset preparation, model development, and experimental evaluation, with particular focus on improving recovery of code-mixed content.
- Demonstrated the effectiveness of the recovered Unicode text for cross-lingual semantic retrieval over defence archives and documented the findings in a research paper prepared for peer-reviewed publication.

- June 2025 – August 2025

Cybersecurity Analyst Intern
— CRIS — ISG Department- Worked on securing large-scale Indian Railways digital platforms, including IRCTC and e-DRISTI, which handle millions of daily transactions and manage sensitive passenger data.
- Reviewed application, server, and network logs to detect suspicious activity, anomalies, and potential cyber threats across railway IT infrastructure.
- Assisted in vulnerability assessments and penetration testing of internal and public-facing railway applications such as e-DRISTI, identifying SQL injection, Cross-Site Scripting (XSS), weak authentication, and application misconfigurations.
- Conducted security reviews of IRCTC services to identify vulnerabilities that could lead to data breaches or disruption of ticketing and payment transactions, including session duplication issues exploited by travel agents.
- Documented and tracked security incidents, Indicators of Compromise (IOCs), and remediation actions as part of incident response activities.
- Collaborated with IT and security teams to strengthen firewalls, access controls, and server hardening for critical railway IT systems.

Achievements
OffSec Gauntlet
7 October 2025 – 2 December 2025Rank achieved
Solved hands-on challenges in web application security, reconnaissance, and vulnerability analysis under time constraints, finishing 45th out of roughly 9,000 participants.
Case Files
Certifications
Certified Ethical Hacker (CEH v13)
Validates expertise in ethical hacking methodologies, penetration testing, and security assessment techniques — proficiency in identifying vulnerabilities and securing systems against cyber threats.
Cyber Security 101 (SEC1)
Covers core cyber security concepts across networking, offensive and defensive security, and web fundamentals — validated through TryHackMe's hands-on, exam-based assessment.
Pre Security (SEC0)
Validates foundational security knowledge spanning networking basics, web fundamentals, and core Linux/Windows security concepts — completed through TryHackMe's hands-on, exam-based assessment.



