Harish Santhanalakshmi Ganesan

Security Engineer

San Francisco, California, United States2 yrs experience

Key Highlights

  • Top 50 security researchers globally in Q1 2022
  • Discovered critical vulnerabilities for major companies
  • Developed tools for AI model security and vulnerability detection
Stackforce AI infers this person is a Cybersecurity expert specializing in AI security and vulnerability assessment.

Contact

Skills

Core Skills

CybersecurityMachine Learning

Other Skills

Cisco Security CloudCybersecurity ResearchPythonDeep LearningVulnerability AssessmentBurpsuiteAWSOpenVASMaltegoNmapWiresharkGhidraIDA ProAny.runAndroid Development

About

I am working as AI security Engineer at Cisco Systems Inc, where I secure AI models and applications based on Large Language Models by researching on attack vectors and attack surfaces in AI models and I also develop tools to find vulnerabilities in LLM models I worked as student assistant at the Information Security Office at UT Dallas, where I devised and implement a comprehensive Systems Administration plan, encompassing software hardening, patching, and upgrading on 30 servers, resulting in a 90% decrease in system vulnerabilities. I also collaborated with stakeholders and developers to identify and address vulnerabilities within deadlines, implementing measures to contain, mitigate, and remediate them, leading to a 40% decrease in the average time taken to resolve vulnerabilities. I performed automated and manual vulnerability assessments, utilizing tools like Nessus, OpenVAS, and Burp Suite, to identify and mitigate 60% of critical and high-severity vulnerabilities, and conduct secure code reviews. In addition to my professional work experience, I am pursuing my MS in Cyber Security, Technology and Policy at UT Dallas, where I learn about the latest trends and technologies in the cyber security domain. I have a strong track record of discovering and responsibly disclosing critical vulnerabilities to companies such as Google, Microsoft, Apple, Forbes, Harvard, NASA, Uber, and Twitter, among others, earning me recognition as one of the MSRC Q1 2022 top 50 security researchers in the world. I have also been assigned CVE-2021-44086 and have found 0-day vulnerabilities in Windows 11, Windows RDP, and Windows FTP client. I am proficient in tools such as Maltego, Nmap, Wireshark, Ghidra, IDA Pro, and Any.run, and have contributed to open source projects of companies like Microsoft and Google. I have also developed various projects such as Oreoweb, OreoML, OreoCli, Anonbee Android App, Anonbee PWA, MockupGen, and AutoDocs. As a passionate and motivated individual, I believe in the moral responsibility of applying cyber security principles in a dynamic ecosystem. I possess excellent team building, customer empathy, accountability, and decision-making skills. I am interested in areas such as web application security, threat hunting, secure code reviews, cloud security, data privacy, and zero trust architectures. I am eager to join an energetic team and contribute my skills to creative and effective solutions for cyber security risks

Experience

2 yrs
Total Experience
2 yrs
Average Tenure
2 yrs
Current Experience

Cisco

3 roles

Security Research Engineer

Promoted

May 2024Present · 2 yrs

  • I worked on Cisco AI defense product from Day 0
  • built automated tools to monitor and collect information on threats on real time to build detection
  • worked on evaluation of LLMs against prompt injections and jailbreaks
  • Built tool to detect AI model supply chain attacks
  • Built patented technology to detect privacy issues in LLMs
  • Built and Opensourced Cisco MCP security scanner
  • Built hybrid algorithm which uses some principles of SAST and LLM to detect high impact bugs in MCP servers
  • Contributed to research
  • Contributed to 10 plus Patented technology
  • Found 0 days in Mac OS etc
Cisco Security CloudCybersecurity ResearchPythonMachine LearningDeep LearningVulnerability Assessment+1

Security Engineer

Jan 2024May 2024 · 4 mos

Security Engineer

Sep 2023Dec 2023 · 3 mos

  • Researched and Developed custom tool to find vulnerabilities in Large Language Models based applications
  • Conducted automated vulnerability assessments on LLM models utilizing custom tool resulting in mitigation of high severity prompt injection and prompt leaking vulnerabilities.
Deep LearningCybersecurity

The university of texas at dallas

Student Assistant at Information Security Office

Feb 2023Sep 2023 · 7 mos · Richardson, Texas, United States · On-site

  • Devised and implemented a comprehensive Systems Administration plan, encompassing software hardening, patching, and upgrading on 30 servers, resulting in a 90% decrease in system vulnerabilities.
  • Collaborated with stakeholders and developers to identify and address vulnerabilities within deadlines, implementing measures to contain, mitigate, and remediate them, leading to a 40% decrease in the average time taken to resolve vulnerabilities.
  • Performed automated and manual vulnerability assessments, utilizing tools like Nessus, OpenVAS, and Burp Suite, to identify and mitigate 60% of critical and high-severity vulnerabilities, and conducted secure code reviews.
BurpsuiteVulnerability AssessmentCybersecurity

Education

The University of Texas at Dallas

Master of Science - MS — cybsersecurity technology and policy

Aug 2022Jun 2024

Amrita Vishwa Vidyapeetham, Coimbatore

Bachelor's degree — Computer Science

Jun 2018May 2022

Stackforce found 100+ more professionals with Cybersecurity & Machine Learning

Explore similar profiles based on matching skills and experience