./resume

> Security Engineering Leader · AI & Offensive Security Researcher · CTO at Pwned Labs

245 Pentests Delivered
1,592 Vulns Reported
28+ CVEs Credited
300+ HTB Labs Built
40k+ Platform Users

$ cat summary.txt

Offensive security leader with 7+ years across penetration testing, vulnerability research, and security engineering — specialized in AI/LLM penetration testing, equally deep across web, API, mobile, cloud, and internal network testing. Delivered 245 penetration tests and reported 1,592 vulnerabilities for Cobalt customers; credited with 28+ CVEs from original zero-day research; built 300+ hacking machines and labs for Hack The Box’s 2M+ user platform. Now CTO of Pwned Labs — architect and builder of the entire hands-on cloud, AI, and Kubernetes training platform used by 40,000+ practitioners. OSCP & CREST certified; Black Hat Arsenal tool author; speaker at Nullcon and c0c0n; BSides Bangalore “Cybersecurity Samurai of the Year 2023.”

$ ls ./experience

Aug 2025 — present

Chief Technology Officer @ Pwned Labs

Remote · hands-on cloud, AI & Kubernetes security training platform

  • Designed, built, and shipped the entire platform end-to-end — product, backend, lab-provisioning and orchestration engine, certification-exam infrastructure — serving 40,000+ users and a 10,000+ member community.
  • Own security engineering across the stack: appsec, multi-cloud hardening (AWS/Azure/GCP), IAM, and secure SDLC — for a user base of professional hackers.
  • Architect real-infrastructure cyber ranges across cloud, AI/LLM, Kubernetes, and CI/CD security — including PwnCloud OS, a purpose-built OS for cloud pentesting.
  • Lead a cross-functional team of 6 developers and 2 security engineers; own cloud budgeting and cost optimization across multi-cloud lab fleets.
Oct 2021 — present

Lead Pentester (part-time) @ Cobalt

Remote · promoted from Penetration Tester, Dec 2022

  • Delivered 245 pentest engagements end-to-end, reporting 1,592 vulnerabilities across AI/LLM systems, cloud environments, web apps, APIs, networks, mobile apps, and Chrome extensions.
  • Ran AI/LLM penetration tests against production chatbots, copilots, and agentic systems — prompt injection, jailbreaks, sensitive-data exfiltration, and tool-abuse attack chains.
  • Engagement lead for Fortune-500 and high-growth SaaS customers: scoping, methodology, triage, client communication, report quality.
  • Co-created and hosted “Hacker’s Corner,” Cobalt’s security podcast.
Sep 2024 — Aug 2025

Senior Security Engineer @ SolarWinds

Remote (US team)

  • Delivered 120+ internal penetration tests across the observability and IT-management portfolio (web, API, cloud, thick-client) under the Secure-by-Design program.
  • Built the pentest program from the ground up — scoping, methodology, reporting standards, and the remediation workflow adopted across product teams.
  • Set up and led the offensive security team — hired, managed, and mentored 3 junior security engineers, reviewing their engagements for quality.
  • Built triage automation that cut mean vulnerability resolution time from ~3 months to 40 days.
Dec 2020 — Sep 2023

Content Engineer → Content Engineer II @ Hack The Box

Remote (UK) · world’s largest hands-on hacking platform

  • Engineered, exploited, and shipped 300+ machines, CTF challenges, and labs for the platform’s 2M+ users — Active Directory, Kubernetes, AWS attacks, web exploitation, reversing, privilege escalation.
  • Authored flagship machines PikaTwoo (Insane, 5/5 rating), Pikaboo (Hard), and Love — each played by hundreds of thousands of users.
  • Ran pre-release pentesting and QA on all production content; built automated Python/Bash test harnesses.
  • Co-authored rapid-response research on Dirty Pipe (CVE-2022-0847) and Spring4Shell (CVE-2022-22965).
  • Cut lab infra cost via image optimization; delivered Kubernetes training at Cyber Apocalypse CTF (10,000+ players).
Jan 2021 — present

Security Researcher @ Code Vigilant

Volunteer coordinated-disclosure collective

  • Credited with 28+ CVEs, including 21 WordPress-plugin zero-days (SQLi, XSS, CSRF) found via source-code review at scale.
  • Built a Semgrep pipeline that scanned the entire 80,000-plugin WordPress repository, surfacing 4,200+ candidate issues — presented at Nullcon Goa 2022 and c0c0n XV.
  • Published exploits and advisories via ExploitDB, WPScan, and CodeVigilant.
Dec 2019 — Jul 2020

Information Security Analyst (internship) @ Enciphers

  • Co-developed Mobexler, the mobile-app pentesting VM later showcased at Black Hat Arsenal; web app pentests and internal vulnerable training labs.

$ cat skills.json

ai-securityAI/LLM & agent pentesting · prompt injection & jailbreaks · RAG and tool-abuse attack chains · OWASP LLM Top 10 · guardrail bypass · model/API abuse
offensiveWeb / API / network / mobile / cloud pentesting · red teaming · Active Directory attacks · vulnerability research · exploit development
cloud+platformAWS · Azure · Kubernetes · Docker · CI/CD security · AI/LLM security · Linux administration
sec-engineeringSecure code review · SAST at scale (Semgrep) · threat modeling · secure SDLC · vulnerability management
engineeringPython · JavaScript/Node.js · Bash · SQL · MongoDB · automation & tooling · IaC
standardsOWASP Top 10 / ASVS · MITRE ATT&CK · PTES · Burp Suite Pro · Metasploit · Nmap · BloodHound

$ ls ./talks --research

Black Hat Arsenal Mobexler — mobile-application pentesting VM (co-developer)
Nullcon Goa 2022 “Raining CVEs on WordPress Plugins with Semgrep” (speaker)
c0c0n XV 2022 Automated code review at scale · drone-hacking workshop trainer at Seasides 2022
Hacker’s Corner Podcast host (Cobalt) · HTB Cyber Apocalypse K8s talk · BSides Ahmedabad lock-picking village (Times of India)

$ ls ./certifications

OSCP Offensive Security Certified Professional · 2020
CRT CREST Registered Penetration Tester · 2022
CPSA CREST Practitioner Security Analyst · 2022
CRTP Certified Red Team Professional · 2021
CRTE Certified Red Team Expert · 2021
CBBH HTB Certified Bug Bounty Hunter · 2022
CKA Certified Kubernetes Administrator · 2021

HTB Pro Labs: Dante · Offshore · Hailstorm (AWS)

$ ls ./honors --achievements

1st
Nullcon CTF Cisco/Checkpoint · 2019
1st
Sector443 CTF Web, RE & firmware · 2019
3rd
c0c0n XI CTF Red Team Village · 2018
HTB Elite Hacker 109+ machines owned

$ cat education.txt

Bachelor of Computer Applications (Computer Science) — The Bhopal School of Social Sciences · 2017–2020