Appsec Engineer - Deputy Manager - North East Small Finance Bank - Guwahati
(2023-09 - 2024-04)
- Conducted penetration tests, uncovering critical flaws in applications.
- Developed threat models, proactively identifying risks before they escalate.
- Implemented secure coding practices, enhancing code quality and safety.
- Led security assessments, reducing vulnerabilities by 40% annually.
- Collaborated with dev teams to enhance security awareness and training initiatives.
- Managed multiple vendors and security engineers
- Streamlined incident response, reducing resolution time by 50%.
- Developed security policies to ensure compliance with industry standards and mitigate risks.
- Monitored security metrics, driving continuous improvement initiatives.
- Worked with regulatory bodies to conduct audits and resolve the findings within deadlines
Security Role - North East Small Finance Bank - Guwahati
(2022-11 - 2023-09)
Software Engineer - Security Research - Loginsoft - Hyderabad
(2024-04 - 2025-06)
- Conducted offensive research on OT devices, routers, and web apps, simulating real-world breach scenarios to enhance security protocols and inform defense strategies.
- Developed CodeQL queries for identifying vulnerabilities in large open-source codebases and integrated into CI/CD pipelines
- Built custom scripts in Python and Bash for reconnaissance, automation, and exploitation of vulnerabilities.
- Created advanced regex-based fingerprints and detection logic for ICS traffic, improving detection capabilities in threat intelligence systems.
- Developed new offensive tools, contributing to security research community efforts and enabling proactive measures against emerging threats.
Cybersecurity Engineer - Securze - Mumbai
(2025-07 - 2026-02)
- Automated deployment of Wazuh EDR infrastructure, installing and configuring agents on 400+ endpoints to enhance visibility and telemetry collection.
- Configured and optimized Wazuh Manager and dashboard while developing custom detection rules for high-fidelity security event correlation.
- Deployed Elastic Security SIEM across 200+ systems for centralized log aggregation, event correlation, and real-time threat detection.
- Engineered detection rules integrating Sysmon and Process Monitor telemetry with Elastic Security to improve endpoint behavioral detection coverage.
- Conducted Android application penetration testing, identifying and validating multiple vulnerabilities in authentication, data storage, and communication layers.
- Developed custom parsers for Fortinet firewall telemetry and automated security alert triage using LLM-driven analysis, improving SOC response efficiency.
- Constructed protocol-level parsers for automated packet capture analysis, streamlining forensic investigation workflows.
- Authored detection rules to extract malicious packets from PCAP datasets, enabling expedited threat hunting and network attack detection.