$ whoami_

Security research & offensive craft.

I build tools and break systems for a living - threat intelligence, vulnerability research, and automation that turns noise into signal. A recent Cyber Operations graduate from the University of Arizona, now a cybersecurity engineer focused on SOC, penetration testing, and OSINT.

scroll
// 01 - operations_log

Tools I've built, bugs I've found.

A short list of things that made it past my usual delete-it filter - shipped, tested, and still running somewhere.

// 02 - operator_profile

The short version.

I'm a recent Cyber Operations graduate from the University of Arizona (BAS, CS minor). I spend most of my time inside other people's systems - legally - and the rest writing Python to make that work less tedious.

Past lives include a Junior SOC Analyst role at CyberEyeAW and a Cyber Intelligence internship at CogMac in New Delhi. I'm currently a Cybersecurity Fellow with Handshake AI, evaluating LLM outputs on offensive-security prompts, and most recently I designed an AI-driven security evaluation framework that critiques LLM-generated code against the OWASP Top 10.

This September I start an MSE in Information and Cyber Security at OST (Ostschweizer Fachhochschule) in Rapperswil, Switzerland.

  • nowOpen to SOC, Pentest & Security Engineer roles
  • builtAI security eval framework vs OWASP Top 10
  • stackPython · Semgrep · Bandit · YARA · Ghidra · Volatility
  • certsCompTIA Security+ · eJPT · ICCA
  • nextMSE Info & Cyber Security, OST Switzerland · Sep 2026
// mission_log - experience

A timeline of paid curiosity.

  1. 2025 - NOW

    Cybersecurity Fellow

    Handshake AI · San Francisco, CA

    Auditing prompt-response pairs and evaluating LLM outputs on cybersecurity-focused projects. Designing domain-specific prompts to improve correctness and alignment.

  2. JAN - MAY 2026

    UG Cybersecurity Research Assistant

    University of Arizona · Tucson, AZ

    Designed a critique-based evaluation framework for LLM-generated code against OWASP Top 10. Built a Python pipeline that combined static analysis, rule-based scanning (Semgrep/Bandit), and LLM reasoning.

  3. MAY - AUG 2025

    Jr. Security Operations Analyst

    CyberEyeAW · Sierra Vista, AZ

    Triaged 100+ weekly security incidents with a 99% resolution rate. Ran vulnerability assessments that reduced exposure by 70%. Collaborated with SOC teams on ThreatLocker tuning - cutting response time 30%.

  4. MAY - AUG 2024

    Cyber Intelligence Intern

    CogMac · New Delhi, India

    Investigated 50+ risks in hardware and financial systems, helping cut response time by 30%. Documented 25+ adversary TTPs via OSINT - playbooks adopted by 7 teams. Automated data pipelines that saved ~40 hrs/month.

// training_record - education

Where I trained.

  1. SEP 2026 - 2028

    MSE in Information and Cyber Security

    OST - Ostschweizer Fachhochschule · Rapperswil, Switzerland

    Starting September 2026. An 18-month, 3-semester master's focused on information and cyber security.

  2. AUG 2022 - MAY 2026

    BAS in Cyber Operations, Minor in Computer Science

    University of Arizona · Tucson, AZ

    Completed May 2026. GPA 3.5/4.0, Dean's List. Coursework across active cyber defense, threat intelligence, forensics, and cyber warfare.

// 03 - capability_matrix

Working toolbox.

[01]

Offensive

Penetration testing, red teaming, vulnerability research, exploit development, reverse engineering.

  • Burp Suite
  • Metasploit
  • Nmap
  • Nessus
  • Ghidra
  • John
  • Hashcat
[02]

Defensive

SOC operations, incident response, threat hunting, SIEM tuning, forensic triage.

  • Splunk
  • Wireshark
  • Snort
  • ThreatLocker
  • YARA
  • Volatility
[03]

Languages

Python-first. Comfortable low-level when required, plus the web languages for building tools around findings.

  • Python
  • Java
  • C
  • JavaScript
  • Bash
  • PowerShell
  • SQL
[04]

Frameworks

Mapping work to standards the rest of the org actually cares about.

  • MITRE ATT&CK
  • NIST CSF
  • OWASP Top 10
  • ISO 27001
  • CIS Controls
[05]

Infra & Cloud

Lab and prod environments across hypervisors and cloud providers.

  • AWS
  • Azure
  • Docker
  • Linux
  • Active Directory
  • VMware
[06]

Analysis

Turning raw telemetry and malware into actionable intel.

  • Static & dynamic analysis
  • Packet inspection
  • OSINT
  • Threat modeling
// 04 - establish_connection

Let's build something worth breaking.

ashishdevchoudhary@gmail.com