I'm a final-year B.Tech Computer Science student at Bennett University, graduating in 2026 with a sustained focus on cybersecurity. My day-to-day blends offensive testing with defensive operations — the same system can be attacked and defended, and I'd rather understand both sides.
As a Cybersecurity Analyst at Cybrotech Digiventure in New Delhi, I run web and network penetration tests against the OWASP Top 10, tune SIEM pipelines in Wazuh and ThreatSpike, and work on DLP systems that actually get adopted. I write findings up against ISO/IEC 27001:2022 so engineering, leadership, and auditors read the same story.
How I think about security
Reports beat findings.
A CVE in a chat is noise. A reproducible, scored, prioritized report is a roadmap.
Attackers don't read your docs.
Architecture diagrams lie. Run the test, watch the packet, then update the diagram.
Automate the boring half.
Policies, scans, log triage — if it repeats, write the Python and move on.
Security is a team sport.
The best findings come from sitting next to backend, ops, and people who own the risk.
Currently exploring
Capability map
Offensive security
- Burp Suite
- Nmap / Nessus
- Metasploit
- BloodHound
- Wireshark
Detection & DLP
- Wazuh
- MISP
- ThreatSpike
- YARA / FIM
- DLP architecture
Development
- Python / FastAPI
- React / TypeScript
- Node.js
- PostgreSQL
- Docker
Frameworks
- OWASP Top 10
- ISO/IEC 27001:2022
- Cryptography
- Cloud (AWS / GCP / Azure)