HI, I'M ROHIT PRANAV D
MCA Information Security Student
Specializing in Cloud Security Architecture, OWASP AppSec Auditing, Threat Detection, and Full-Stack Engineering. Building resilient enterprise software designed to withstand modern cyber vectors.
ABOUT THE ENGINEER
CAREER OBJECTIVE
To leverage deep technical expertise in threat detection, secure code auditing, cloud infrastructure hardening, and full-stack development to build enterprise-grade software that withstands modern cyber threats.
CURRENT RESEARCH & LEARNING FOCUS
- >Advanced AWS Cloud Security Architectures (S3, IAM, GuardDuty, AWS WAF)
- >Kubernetes Security Posture Management & Container Hardening
- >Zero Trust Architecture & Microsegmentation Protocols
- >Automated Static & Dynamic Application Security Testing (SAST/DAST in CI/CD)
CORE SECURITY PHILOSOPHY
Engineered for resilience, zero compromise, and bulletproof security controls.
Defense in Depth
Implementing layered security controls at network, application, identity, and data tiers to eliminate single points of compromise.
Zero Trust Mindset
Never trust, always verify. Enforcing strict identity verification and least-privilege authorization for every request.
Automated Security (DevSecOps)
Shifting security left by embedding vulnerability scanners, dependency auditing, and compliance checks into automated CI/CD workflows.
Performance & Craftsmanship
Combining bulletproof cybersecurity with lightning-fast user experiences, clean component architecture, and modern UX design.
EDUCATION & QUALIFICATIONS
MCA Information Security
Postgraduate master's degree focusing on advanced cyber threat intelligence, cloud security infrastructure, cryptography, ethical hacking, application security, and enterprise security management.
B.Sc Computer Science and Applications
Foundational undergraduate degree in computer science principles, database systems, object-oriented programming, data structures & algorithms, web technology, and computer network protocols.
SKILLS & CAPABILITIES
Python
ProgrammingSecurity scripting, automation, exploit POCs, data processing
Java
ProgrammingObject-oriented software development, enterprise applications
JavaScript
ProgrammingES6+, async programming, DOM manipulation, full-stack
TypeScript
ProgrammingStrict type safety, generic interfaces, scalable web apps
PHP
ProgrammingBackend web development, legacy app security auditing
C
ProgrammingLow-level memory structure, buffer overflow analysis
C++
ProgrammingData structures, memory management, systems security
React
FrontendComponent-driven architecture, state management, hooks
Next.js
FrontendApp Router, SSR, Server Components, API routes, performance
HTML5
FrontendSemantic markup, accessibility (a11y), SEO optimization
CSS3
FrontendFlexbox, Grid, keyframe animations, responsive design
Tailwind CSS
FrontendUtility-first design system, dark mode, glassmorphism UI
Node.js
BackendAsynchronous runtime, microservices, secure web servers
Express
BackendREST API routing, security headers (Helmet), middleware
REST API
BackendAPI security, OAuth 2.0, JWT, rate limiting, OpenAPI
Authentication
BackendJWT, Session tokens, MFA, RBAC, OAuth2, SAML
AWS
CloudEC2, S3 bucket policies, IAM roles, GuardDuty, AWS WAF, VPC
Azure
CloudEntra ID (Azure AD), Azure Key Vault, Security Center
Google Cloud
CloudGCP IAM, Security Command Center, Cloud Storage controls
OWASP Top 10
Cyber SecuritySQLi, XSS, CSRF, SSRF, Broken Access Control mitigation
IAM (Identity Access)
Cyber SecurityLeast privilege access, RBAC, ABAC, Single Sign-On
Threat Detection
Cyber SecuritySIEM log analysis, intrusion detection, threat modeling
Network Security
Cyber SecurityFirewalls, IDS/IPS, TLS/SSL inspection, VPN, Wireshark analysis
Application Security
Cyber SecurityStatic & Dynamic analysis, secure code auditing, input sanitization
Cloud Security
Cyber SecurityPosture management (CSPM), bucket hardening, container security
Git
DevOpsVersion control, branching strategies, commit auditing
GitHub
DevOpsActions CI/CD pipelines, Dependabot security alerts, PR reviews
Docker
DevOpsContainerization, distroless base images, rootless security
Linux
DevOpsBash scripting, SSH security, file permissions, system hardening
Burp Suite
ToolsWeb proxy, active scanning, intruder, repeater, extension scripts
Wireshark
ToolsPacket inspection, PCAP analysis, protocol decoding, malware traffic
Nmap
ToolsPort scanning, NSE scripting, OS fingerprinting, vulnerability discovery
Kali Linux
ToolsPenetration testing OS, Metasploit, Aircrack-ng, John the Ripper
VS Code
ToolsIDE configuration, debugging extensions, ESLint, security linters
SECURITY & SOFTWARE PROJECTS
Distributed Job Portal System with ML Matching
Scalable distributed architecture leveraging machine learning algorithms for candidate-job matching
An enterprise-grade distributed job portal platform featuring an intelligent Machine Learning recommendation engine that matches candidate resumes with job postings using TF-IDF and Cosine Similarity.
SECURITY LABS & PENTESTING PLATFORMS
OWASP Top 10 Security Audit & Remediation
Hands-on audit and code defense implementation against SQL Injection, XSS, CSRF, SSRF, Broken Authentication, IDOR, and Security Misconfigurations.
PortSwigger Burp Suite Certified Audit
Advanced intercepting proxy labs, custom intruder payload generation, web socket analysis, authentication bypass, and automated security extensions.
TryHackMe Security Paths & Offensive Labs
Completed Web Fundamentals, DevSecOps, SOC Analyst Level 1, Cyber Defense, and Junior Penetration Tester learning paths on TryHackMe platform.
Hack The Box Machine Exploitation & Privilege Escalation
Systematic enumeration, initial foothold exploitation, Linux/Windows local privilege escalation, and active directory penetration labs.
DVWA (Damn Vulnerable Web App) Pentesting
Tested and exploited web vulnerabilities across Low, Medium, and High security levels in DVWA environment, documenting remediation code patches.
Nmap Network Reconnaissance & Service Auditing
Advanced TCP/UDP port scanning, OS fingerprinting, vulnerability script engine (NSE) execution, stealth SYN scans, and firewall evasion.
Wireshark Packet Analysis & PCAP Forensics
Deep inspection of network protocols (TCP, HTTP/2, TLS handshake, DNS, ARP), identifying malware C2 beaconing and unencrypted credential leaks.
Kali Linux OffSec Tools Ecosystem
Proficient utilization of Kali Linux toolkit including Metasploit Framework, Hydra, John the Ripper, Gobuster, SQLmap, and Hashcat.
INDUSTRY CERTIFICATIONS
Introduction to CISSP
Introduction to Cybersecurity
Introduction to Cyber Attacks
GITHUB DEVELOPMENT METRICS
ENGINEER RESUME
ROHIT PRANAV D
MCA Information Security Student • MCA Information Security (2026-2028)
EDUCATION
MCA Information Security
Jain University (2026-2028)
B.Sc Computer Science
(2023-2026)
CORE DOMAINS
- • Cloud Security (AWS/Azure)
- • DevSecOps & CI/CD SAST
- • OWASP AppSec Auditing
- • Full-Stack Next.js/React
TOP TOOLS
- • Burp Suite & Wireshark
- • Nmap & Kali Linux
- • Docker & Git / Actions
- • Python & TypeScript
GET IN TOUCH
DIRECT CHANNELS
Whether you have a security role opportunity, a project proposal, or want to discuss cloud security architectures, feel free to drop a message.