Hello, I'm

KUSHAGRAVARSHNEY

A Security Professional

SECURITYENGINEER

01 / About

Summary

Security engineer with 2 years of hands-on experience across application security, AI/LLM security, and security automation, most of it in Python. Currently testing enterprise financial platforms on Azure at The World Bank Group, where AI security research surfaced a prompt injection flaw. Built a production SOC pipeline that ran live in a data center, and RedV01, an agentic AI penetration testing system. Vulnerability disclosures acknowledged by NASA, Zoho, and India's NCIIPC.

0.00%

noise reduction — 0+ daily events → ~150 alerts

0+

validated findings, Medium to Critical severity

GHSA-gjm7-g266-w3wj

SSRF advisory · CVE pending

02 / Experience

Work History

Apr 2026 – Present · Chennai

The World Bank Group

Application Security Testing Intern

  • Reported a prompt injection flaw (Unicode filter bypass) found while testing AI-integrated financial tools; ongoing research covers LLM prompt injection, model inversion, and adversarial inputs.
  • Test Azure-hosted enterprise systems and work with development teams to land fixes through Azure DevOps pipelines.
  • Run static and dynamic analysis with Veracode, Semgrep, and SonarQube on multi-tenant financial platforms serving government and institutional clients worldwide, targeting OWASP Top 10 vulnerability classes.

Jun 2025 – Apr 2026 · Gurugram

Fluidech IT Services Pvt Ltd

Junior Security Analyst

  • Designed, deployed, and ran a production SOC pipeline (Wazuh, ELK, Shuffle SOAR, MISP, DFIR IRIS) in a live data center, cutting 2,000,000+ daily log events to ~150 enriched alerts — a 99.99% noise reduction with no added headcount.
  • Automated incident response end to end: detection scripts correlated IOCs and blocked malicious IPs on enterprise firewalls in real time, removing manual triage for known threat categories.
  • Designed and executed threat simulations against OT/ICS environments, modelling attacker TTPs from MITRE ATT&CK for ICS to find exploitable gaps in industrial control system configurations.

Jul 2024 – Jan 2025 · Remote

CyberSapiens LLP

Security Analyst, VAPT

  • Reported 100+ validated findings, Medium to Critical severity, across client infrastructures worldwide; disclosures acknowledged by NASA, Zoho, and 2× by India's NCIIPC (National Critical Information Infrastructure Protection Centre).
  • Validated findings technically and wrote remediation guidance delivered directly to client stakeholders.

03 / Projects

Selected Work

Dec 2024 – Present

RedV01 — Agentic AI Penetration Testing System

AWS AI for Bharat 2026 – Semifinalist (Prototype Phase)
  • Built an agentic AI system that runs the full VAPT workflow, from attack surface discovery through active exploitation to report generation, cutting manual overhead by ~60%.
  • Designed the multi-agent architecture on LangFlow and LLMs, with real-time vulnerability correlation and CVSS-based risk scoring wired into the generated reports.
kushagra.social

Jun 2024 – Aug 2024

Phishing URL Detection using AI/ML

IBM Hackathon — 3rd Prize
  • Trained a Random Forest classifier to 98.97% accuracy on a multi-feature extraction pipeline, classifying URLs as phishing or benign from signals derived during training.
  • Built a generative-AI agent on top of it that captures the suspect page in real time, processes the screenshot server-side, and reports the specific red flags and green flags behind each verdict — turning a bare classification into an explanation a user can act on.

04 / Skills

Toolkit

AppSec

  • OWASP Top 10
  • Burp Suite Pro
  • API Security
  • Static Analysis (Veracode, Semgrep, SonarQube)
  • DAST
  • Secure Code Review
  • Threat Modeling
  • Web Pentesting

AI Security

  • LLM Threat Modeling
  • Prompt Injection
  • Adversarial ML
  • Agentic AI Security
  • AI Integrated App Testing

Dev Tooling

  • Git
  • Linux
  • CI/CD Pipelines (Azure DevOps)
  • Azure Cloud
  • REST APIs

SOC / SIEM

  • Splunk
  • Wazuh
  • Alert Triage
  • IOC Analysis
  • MISP
  • OpenCTI
  • Detection Engineering

OT / ICS

  • ICS Threat Simulation
  • Industrial Network Defense
  • Critical Infrastructure Security

Frameworks

  • MITRE ATT&CK
  • NIST
  • OWASP
  • Responsible Disclosure
  • CVE Research

Languages

  • Python
  • Bash
  • Rust

05 / Certifications

Credentials

Certified Red Team Professional (CRTP)

Altered Security

Certified Application Security Practitioner (CASP)

SecOps Group

Certified Cybersecurity Technician (CCT)

EC-Council

Certified in Cybersecurity (CC)

ISC2

CyberOps Associate

Cisco

06 / Achievements

Recognition

Security acknowledgements from NASA, Zoho, and 2× NCIIPC (Govt. of India) for responsible vulnerability disclosures

Discovered and reported an SSRF vulnerability (CWE-918) in Basecamp's open-source once-campfire — published as GHSA-gjm7-g266-w3wj; CVE pending assignment.

view advisory

AWS AI for Bharat 2026 – Semifinalist (Prototype Phase), AWS AI for Bharat 2026 (AWS × Hack2skill), with RedV01

Chapter Lead – OWASP Student Chapter, GLA University; Technical Lead – Club Cyberonites; built CTF challenges for university events

Ranked 19th nationally in Defcon Delhi CTF; top 5% globally on TryHackMe