./resume
> Security Engineering Leader · AI & Offensive Security Researcher · CTO at Pwned Labs
$ cat summary.txt
Offensive security leader with 7+ years across penetration testing, vulnerability research, and security engineering — specialized in AI/LLM penetration testing, equally deep across web, API, mobile, cloud, and internal network testing. Delivered 245 penetration tests and reported 1,592 vulnerabilities for Cobalt customers; credited with 28+ CVEs from original zero-day research; built 300+ hacking machines and labs for Hack The Box’s 2M+ user platform. Now CTO of Pwned Labs — architect and builder of the entire hands-on cloud, AI, and Kubernetes training platform used by 40,000+ practitioners. OSCP & CREST certified; Black Hat Arsenal tool author; speaker at Nullcon and c0c0n; BSides Bangalore “Cybersecurity Samurai of the Year 2023.”
$ ls ./experience
Chief Technology Officer @ Pwned Labs
Remote · hands-on cloud, AI & Kubernetes security training platform
- Designed, built, and shipped the entire platform end-to-end — product, backend, lab-provisioning and orchestration engine, certification-exam infrastructure — serving 40,000+ users and a 10,000+ member community.
- Own security engineering across the stack: appsec, multi-cloud hardening (AWS/Azure/GCP), IAM, and secure SDLC — for a user base of professional hackers.
- Architect real-infrastructure cyber ranges across cloud, AI/LLM, Kubernetes, and CI/CD security — including PwnCloud OS, a purpose-built OS for cloud pentesting.
- Lead a cross-functional team of 6 developers and 2 security engineers; own cloud budgeting and cost optimization across multi-cloud lab fleets.
Lead Pentester (part-time) @ Cobalt
Remote · promoted from Penetration Tester, Dec 2022
- Delivered 245 pentest engagements end-to-end, reporting 1,592 vulnerabilities across AI/LLM systems, cloud environments, web apps, APIs, networks, mobile apps, and Chrome extensions.
- Ran AI/LLM penetration tests against production chatbots, copilots, and agentic systems — prompt injection, jailbreaks, sensitive-data exfiltration, and tool-abuse attack chains.
- Engagement lead for Fortune-500 and high-growth SaaS customers: scoping, methodology, triage, client communication, report quality.
- Co-created and hosted “Hacker’s Corner,” Cobalt’s security podcast.
Senior Security Engineer @ SolarWinds
Remote (US team)
- Delivered 120+ internal penetration tests across the observability and IT-management portfolio (web, API, cloud, thick-client) under the Secure-by-Design program.
- Built the pentest program from the ground up — scoping, methodology, reporting standards, and the remediation workflow adopted across product teams.
- Set up and led the offensive security team — hired, managed, and mentored 3 junior security engineers, reviewing their engagements for quality.
- Built triage automation that cut mean vulnerability resolution time from ~3 months to 40 days.
Content Engineer → Content Engineer II @ Hack The Box
Remote (UK) · world’s largest hands-on hacking platform
- Engineered, exploited, and shipped 300+ machines, CTF challenges, and labs for the platform’s 2M+ users — Active Directory, Kubernetes, AWS attacks, web exploitation, reversing, privilege escalation.
- Authored flagship machines PikaTwoo (Insane, 5/5 rating), Pikaboo (Hard), and Love — each played by hundreds of thousands of users.
- Ran pre-release pentesting and QA on all production content; built automated Python/Bash test harnesses.
- Co-authored rapid-response research on Dirty Pipe (CVE-2022-0847) and Spring4Shell (CVE-2022-22965).
- Cut lab infra cost via image optimization; delivered Kubernetes training at Cyber Apocalypse CTF (10,000+ players).
Security Researcher @ Code Vigilant
Volunteer coordinated-disclosure collective
- Credited with 28+ CVEs, including 21 WordPress-plugin zero-days (SQLi, XSS, CSRF) found via source-code review at scale.
- Built a Semgrep pipeline that scanned the entire 80,000-plugin WordPress repository, surfacing 4,200+ candidate issues — presented at Nullcon Goa 2022 and c0c0n XV.
- Published exploits and advisories via ExploitDB, WPScan, and CodeVigilant.
Information Security Analyst (internship) @ Enciphers
- Co-developed Mobexler, the mobile-app pentesting VM later showcased at Black Hat Arsenal; web app pentests and internal vulnerable training labs.
$ cat skills.json
$ ls ./talks --research
$ ls ./certifications
HTB Pro Labs: Dante · Offshore · Hailstorm (AWS)
$ ls ./honors --achievements
$ cat education.txt
Bachelor of Computer Applications (Computer Science) — The Bhopal School of Social Sciences · 2017–2020