Offensive
Recon, exploitation, and post-exploitation across web, network, and Active Directory.
Detection engineer and cloud-security builder. I catch what others miss, secure the infrastructure underneath, then write it down so you can trust it.
Tooling in regular use

I got into security to understand how systems actually fail, not the sanitized textbook version, but the real vulnerabilities that surface when defenses meet a determined attacker. At NYU Tandon I work across detection engineering, cloud security, and application security: writing KQL that fires in production, architecting AWS where security is structural rather than bolted on, and finding the bug before someone else does. I’m looking for work where the problems are hard, documentation is valued, and the team takes the craft seriously.
Two things pointed me toward security. The work has real consequences for real people, and the field never stays still long enough to get comfortable. For someone wired the way I am, that is not a downside.
Production detection engineering and academic security builds across offensive, defensive, cloud, AppSec, and GRC. Open any project for the full case study: the problem, what I built, and the measured outcome. Every number is a real result, not an estimate.
The work tags against six canonical security domains: offensive, defensive, cloud, AppSec, GRC, and the foundations underneath. Each card lists the tools and methods I actually use, marked by depth: unlabelled means proficient, otherwise working knowledge or lab. Nothing here is aspirational.
Recon, exploitation, and post-exploitation across web, network, and Active Directory.
Detection engineering, log analysis, incident response, and digital forensics.
Securing AWS, Azure, and GCP: IAM, workload, container, and Kubernetes posture.
Finding and fixing flaws in code and APIs: SAST/DAST and secure code review.
Risk, audit, and compliance against frameworks such as NIST and ISO 27001.
Networking, operating-system internals, scripting, and applied cryptography.
Security only works when the person doing it is accountable to someone real. This is mine, in my words.
Security works when the person doing it has principles, and principles start with understanding who you are actually accountable to.
Strong security builds trust. Trust attracts stakeholders. Stakeholders grow the business. A growing business demands stronger security. The cycle only holds if the person in the middle of it never loses sight of who they actually serve.
Authorized scope. Coordinated disclosure. Access only what the role requires. Not rules someone imposed on me. Just how this should work.
Teaching cybersecurity at NYU Tandon and shipping production detections at Embee, on top of a master's at NYU and a bachelor's at Manipal.
Course Instructor, CS4CS
Teach 60+ rising-senior high schoolers (16–17) hands-on cybersecurity: configuring lab environments, designing CTF challenges, and mentoring 20+ student projects split evenly between AI builds and case-study security problems.
Detection Engineering & Compliance
Production detection engineering and ISO 27001 compliance work in Microsoft Sentinel: KQL analytics, enrichment pipelines, and incident-response runbooks.
NYU Tandon School of Engineering · New York, NY · GPA 3.6 / 4.0
Manipal University Jaipur · Jaipur, India · GPA 3.2 / 4.0 · Minor in Cloud Infrastructure
Long-form security writing: how generative AI is reshaping both sides of the fight, Zero Trust for financial services, hardening LLM applications against prompt injection, machine-learning defense for industrial control systems, and how everyday browsing quietly maps your digital life.
I’m starting a small practice: risk assessments, security reviews, and practical hardening for teams that can’t yet staff a full security function. Less buzzword, more rolled-up sleeves: find what’s exposed, explain it plainly, and leave you with something documented you can act on. Deeper offensive work is on the roadmap as I build it out.
Open to security roles and project work in detection engineering, cloud security, and AppSec. Graduating December 2026. The fastest way to reach me is email.
Prefer a form?