Security Research Engineer · NetSPI

I break it, then I teach systems to catch it.

Five years across offensive security tooling and threat detection — building the scanners, rules and automation that carry security work at scale. Python, Java and TypeScript, on both sides of the line.

[ PUNE · IN ]
● AVAILABLE
— portrait slot · drop your photo in assets/portrait.png —
0

Years in security

0

SIEM platforms

0

Microsoft certs

0

Published paper

Offence & defence

I've worked both sides
of the same line.

Most engineers pick one. I spent three years writing detections for what attackers do, and now I build the tooling that does it. Watch an attack chain run — and watch detection catch it.

◤ OFFENSIVE — ATTACK CHAIN ATT&CK PROGRESSION DETECTION SWEEP — DEFENSIVE ◢
Attack agent in transit Detection sweep · intercept INTERCEPTED 0
Red · Offensive

Building the things that find it.

At NetSPI — scanners, platform integrations and automated vulnerability verification for offensive security workflows.

0Tools shipped
0Languages
0Cloud & data
  • Scanner development — Nuclei templating, automated verification, template management.
  • Platform integrations — backend APIs, PostgreSQL, and React UI for consultant workflows.
  • Coverage & reliability — improving scanner accuracy and operational visibility.
Blue · Defensive

Teaching systems to see it.

SME for QRadar and Azure Sentinel at ReliaQuest — detection rules built through continuous R&D and shipped via CI/CD.

0SIEM platforms
0EDR suites
0Query languages
  • Detection engineering — rule development, tuning and CI/CD deployment.
  • Malware analysis — PE/non-PE, macros, code injection, hooking, process hollowing.
  • DFIR — Velociraptor, Redline, Mandiant IOC Editor, ransomware response.
Selected work

Tooling that ships into
live engagements.

Trajectory

SOC floor to
research engineering.

Jun 2025 — Present · 1 yr 4 mos

NetSPI · Pune

Security Research Engineer · Full-time · Hybrid
  • Design and develop security scanners and automation tools using Python, Java and TypeScript/React.
  • Build and maintain platform integrations across backend APIs, databases and UI for offensive security workflows.
  • Improve scanner reliability, detection coverage and operational visibility for security consultants.
  • Automate vulnerability verification and template management to reduce manual review effort.
  • Collaborate with engineering and security teams on tooling, research and platform enhancements.
Stack — Python · Java · TypeScript · React · PostgreSQL · AWS · Docker · Nuclei · API development · security automation
Sep 2023 — Jun 2025 · 1 yr 10 mos

ReliaQuest · Pune

Full-time · Hybrid · Two roles
Feb 2025 — Jun 2025 · 5 mos
Cyber Security Specialist
  • Conducted in-depth threat analysis and presented findings and security-posture recommendations directly to clients.
  • Recognised Subject Matter Expert for QRadar and Azure Sentinel.
Sep 2023 — Feb 2025 · 1 yr 6 mos
Threat Detection Developer
  • Develop and continuously improve threat detection rules to identify and respond to security incidents.
  • Collaborate with cross-functional teams to enhance incident response procedures and adapt to emerging threats.
  • Conduct threat analysis and provide recommendations for improving security posture.
  • Stay current with threat intelligence and security best practices to proactively defend against new threats.
SIEM — LogRhythm · QRadar · Google Chronicle · Splunk · Azure Sentinel · Sumo Logic · Exabeam · Devo
EDR — CrowdStrike Falcon · Microsoft Defender · Cortex XDR · SentinelOne
Email — O365 · SandBlast · Proofpoint
Nov 2021 — Sep 2023 · 1 yr 11 mos

SecurityHQ · Pune

Full-time · Three roles
Jun 2023 — Sep 2023 · 4 mos · On-site
Senior Analyst
  • Part of digital forensics and incident response engagements, including ransomware cases, through to remediation.
Apr 2022 — Jun 2023 · 1 yr 3 mos
Cyber Security Analyst
  • Analysing security events using QRadar and Azure Sentinel, and providing mitigation.
  • Monitor and manage endpoints with EDR tools — Carbon Black, Cortex XDR and CrowdStrike.
  • Malware analysis: PE, non-PE, PDF, Office macros and scripts — API calls used by malware, and common techniques such as code injection, hooking and process hollowing.
  • Email analysis: managing Mimecast and analysing phishing and spam mail across O365 AIR, Mimecast and Proofpoint.
  • Analysing logs from O365, ATP, DLP, proxy, firewall and IDS/IPS.
Nov 2021 — Apr 2022 · 6 mos
Security Engineer
  • Security monitoring and SIEM engineering on Azure Sentinel.
Tooling — QRadar · Azure Sentinel · SentinelOne · Carbon Black · Cortex XDR · CrowdStrike · Mimecast · Proofpoint
Credentials

Certified across the
Microsoft security stack.

SC-100

Cybersecurity Architect Expert

Microsoft · Jul 2024

SC-200

Security Operations Analyst Associate

Microsoft · Jan 2024

MS-500

Microsoft 365 Security Administration

Microsoft

Let's build something
that holds under attack.

Open to security engineering and research conversations.