Purple Team Security Engineer at Gartner (2025-08 – Present)
- Led purple team operations focused on continuous detection validation and adversary emulation across enterprise environments, bridging offensive tactics with defensive capabilities.
- Deployed and operationalized MITRE Caldera and Atomic Red Team frameworks to simulate real-world attacker behaviors and continuously assess detection coverage against MITRE ATT&CK and Cyber Kill Chain.
- Utilized Mandiant Security Validation (MSV) to design and execute advanced attack scenarios and validate the effectiveness of existing security controls, SIEM detections, and XDR solutions.
- Collaborated with SOC, threat hunting, and detection engineering teams during purple team exercises to analyze telemetry from validation campaigns, identify detection gaps, and fine-tune correlation rules, playbooks, and response workflows, enhancing visibility, improving detection logic, and reducing mean time to detect (MTTD) across critical infrastructure and cloud environments.
- Developed and integrated new adversary simulation techniques and custom attack chains to test the resilience of security tools and improve detection fidelity.
Red Team Consultant at PwC India (2024-01 – 2025-08)
- Led comprehensive Red Team engagements simulating real-world adversaries, leveraging the MITRE ATT&CK and Cyber Kill Chain frameworks to structure operations and uncover critical vulnerabilities across clients' external and internal assets in the Banking, Power, and Petrochemical sectors.
- Collaborated with Blue Teams to enhance detection and response strategies. Utilized SIEM and SOAR solutions to create new rules and policies to proactively detect and stop attacks.
- Executed comprehensive social engineering assessments, including phishing, vishing, and physical intrusion simulations, to evaluate and improve clients' human-centric security defenses.
- Automated recon and attack processes to reduce mean time to report vulnerabilities by 25%
- Developed custom in-memory loaders, C2 beacons, and executables to deliver payloads and evade EDR/XDR detection, leveraging techniques such as Indirect Syscalls, Reflected DLL Loading, and Obfuscation to enhance the stealth and effectiveness of red team operations.
- Authored detailed technical reports and developed executive-level presentations for each red team engagement, including concise executive summaries and actionable security recommendations for leadership and technical stakeholders.
Software Engineer (Data Science) Trainee at HighRadius Corporation (2023-06 – 2023-12)
- Built AI-enabled B2B invoice management platform with predictive capabilities.
- Designed algorithms to validate financial deductions and automate business logic.
- Improved algorithm efficiency by 15% in terms of time and memory.
- Collaborated with cross-functional teams to align models with client requirements.