LLM Security Audit Framework
An automated framework for identifying prompt injection and data exfiltration vulnerabilities in Large Language Models.
Senior Manager — Cybersecurity & AI Security
7+ years bridging offensive security, enterprise risk governance, and the frontier of AI security research — protecting the organisations and systems that matter.
I am a Senior Cybersecurity Manager with over 7 years of experience spanning offensive security, enterprise risk governance, and cutting-edge AI security research.
My career began hunting threats in the SOC, advanced through complex penetration testing engagements, and evolved into executive leadership — orchestrating comprehensive security postures across enterprise environments and regulated industries.
Today, my core research focus is AI Security — identifying prompt injection vectors in production LLMs, quantifying risks in AI supply chains, and building secure integration frameworks for the next generation of enterprise AI systems.
Level 3 BOS
Leading cyber security operations, GRC implementation, and AI security research initiatives.
Risk Associates
Conducted advanced penetration testing for web, mobile, API, and network environments.
Independent / Stealth
Researched LLM vulnerabilities, prompt injection attacks, and AI integration security.
The Horizon Tech
Implemented DevSecOps pipelines and automated security testing.
Intellectsols
Monitored SIEM alerts, incident response, and threat hunting.
Offensive security tooling, GRC automation, and AI vulnerability research — built to solve real enterprise challenges.
An automated framework for identifying prompt injection and data exfiltration vulnerabilities in Large Language Models.
A centralized dashboard for tracking ISO 27001, SOC2, and PCI DSS compliance across multi-cloud environments.
A CI/CD pipeline template that integrates SAST, DAST, and SCA scanning natively into GitHub Actions.
Contributing to the global cybersecurity community through research, vulnerability disclosures, and published insights.
ISC2
APIsec University
ISC2
Red Hat
AWS
ISC2
BSI
LogRhythm
Hamdard University
Aptech
Years Experience
Reported Vulnerabilities
Security Assessments
Penetration Tests
Security Trainings
The portfolio runs its own deception stack — every probe below is a live mechanism answering hostile traffic right now.
Fake admin, CMS and config paths answer with indistinguishable 404s. Each attacker gets a deterministic fingerprint, defeating scanner diffing.
Known offensive tooling (sqlmap, Nikto, Burp, Nmap…) is served silent soft-404s on sensitive routes — it never reaches real application surface.
Sliding-window rules score connection floods, sequential probing and auth abuse; findings are risk-ranked LOW → HIGH in real time.
Deception replies are CSPRNG-selected and budget-capped per attacker. Once spent, the engine goes dark — log-only, zero signal leakage.
Two-step admin login, scrypt password hashing, DB-backed revocable sessions, CSRF tokens, origin checks and constant-time comparisons.
The edge proxy rotates a fresh nonce into the Content-Security-Policy of every response; inline scripts are stamped, violations are reported.
Events recorded
Last 24 hours
Last 7 days
Last contact
/admin/skills61/admin/progress-skills52/admin/certifications50/admin/publications50/admin/achievements45Anonymized aggregates only — source addresses are never published.
Open to strategic security leadership, AI security consulting, and meaningful research collaborations.
Prefer email for initial outreach — typically responded within 48 hours.
Phone
Location
Global · Remote