I build security projects that connect attack simulation, cloud telemetry, identity analysis, and detection engineering into reviewable evidence. My strongest work is in AI Security, LLM red teaming, API abuse-path modeling, cloud IAM analysis, and SOC/detection engineering.
I am a BCA graduate pursuing an MCA in Cybersecurity and looking for entry-level cybersecurity roles, internships, and startup opportunities across India. I am open to onsite roles and relocation.
- AI Security and Red Team: prompt-injection testing, guardrail evaluation, adversarial test cases, tool/API abuse paths
- Cloud and IAM Security: GCP IAM, AWS IAM, least privilege, policy analysis, privilege-escalation paths
- Detection Engineering: Splunk SPL, Sigma/KQL concepts, MITRE ATT&CK mapping, alert context and false-positive reduction
- Security Automation: Python tooling, structured evidence, SARIF, CI checks, reproducible reports
- SOC and Incident Response: triage workflow, CloudTrail, WAF, VPC Flow Logs, Sysmon, Suricata, analyst handoff
| Project | Problem solved | Engineering evidence |
|---|---|---|
| AegisForge | Tests AI prompt defenses, modeled tool calls, API authorization, and correlated detections in one lab-safe attack chain | Python CLI/API, synthetic prompt-injection corpus, tenant-boundary checks, telemetry, benchmark gates, holdout analysis |
| GCP IAMGraph | Explains Google Cloud IAM access and privilege-escalation paths before confirming risk | ALLOW / DENY / UNKNOWN authorization decisions, inherited deny logic, SARIF, 74 tests, 91.33% coverage |
| Automated LLM Vulnerability Assessment | Compares baseline and guarded local LLM behavior under matched adversarial tests | NVIDIA garak, DAN jailbreak checks, encoding-injection tests, JSONL/CSV/Markdown evidence, residual-risk analysis |
| Enterprise Cloud Security Monitoring Platform | Builds an AWS/Splunk SOC lab for cloud, web, host, and network detection | Terraform, CloudTrail, AWS WAF, VPC Flow Logs, 10 SPL detections, validation reports, dashboards, runbooks |
| AI-Augmented SOC Triage Platform | Uses local AI to assist SOC triage while keeping response analyst-controlled | Splunk, Ollama, Sysmon, Suricata, YARA, SQLite audit records, approval-gated response workflow |
Languages and automation: Python, PowerShell, Bash, SQL, HCL
Cloud and infrastructure: GCP, AWS, Terraform, Linux, Windows, VMware
Security engineering: IAM, Splunk, Sysmon, Suricata, YARA, SARIF, MITRE ATT&CK
Testing and assessment: Burp Suite, Nmap, Nessus, Trivy, garak, Wireshark
Frameworks and concepts: OWASP Top 10, NIST CSF, NIST SP 800-61, ISO/IEC 27001 concepts
- I keep claims tied to evidence that a reviewer can inspect.
- I document limitations instead of hiding them.
- I design labs around isolated, authorized systems.
- I separate detection, AI enrichment, authorization, and response decisions.
- I build reports that answer: what happened, why it matters, ATT&CK mapping, evidence, and next steps.
I am expanding AegisForge as my hero AI Security project while continuing cloud IAM and detection-engineering work. My goal is to grow into a security engineering role where I can build practical tools, test attack paths safely, and improve security decision-making with strong evidence.
- Portfolio: parakh-shinde.github.io
- LinkedIn: linkedin.com/in/parakh-shinde
- GitHub: github.com/Parakh-Shinde
- Email: parakhshinde15@gmail.com
All offensive-security and red-team style work shown here is performed only in isolated, authorized lab environments.


