raghav ‎

DevOps Engineer

United States2 yrs 2 mos experience
Most Likely To Switch

Key Highlights

  • Filing CVEs from OSS research at Google.
  • Achieved top ranks in multiple CTF competitions.
  • Developed machine learning solutions with high accuracy.
Stackforce AI infers this person is a Cybersecurity and Machine Learning specialist with strong analytical and problem-solving skills.

Contact

Skills

Core Skills

Security EngineeringIncident ResponseWeb Application SecurityVulnerability AssessmentMachine LearningData EngineeringData AnalysisNetwork SecurityCybersecurityCybersecurity ResearchEthical Hacking

Other Skills

Red-teamingOffsecSecurity Vulnerability AssessmentCodeQLTarnishDoubleXPull RequestAuditingScriptingCTFTeam CollaborationData PipelineAPI DevelopmentClassification AlgorithmsRegression Algorithms

About

I am not a cybersecurity "professional". I don't know anything. I hack to defend against the unexpected. Opinions are my own and do not represent anyone but myself

Experience

2 yrs 2 mos
Total Experience
1 yr 1 mo
Average Tenure
1 yr 10 mos
Current Experience

Google

2 roles

Security Engineer II

Promoted

Jul 2024Present · 1 yr 10 mos · New York, New York, United States · Hybrid

  • Red-teaming/Offsec @ Google
  • Working on a cool product.
  • Worked on two cool exercises.
  • Working on cool exercises.
  • Did some dev work. Will do more TTP research and dev work.
  • Shadowed two cool exercises. Will shadow some more.
  • Filed 2 CVEs from OSS research
Red-teamingOffsecSecurity EngineeringIncident Response

Security Engineer

May 2023Aug 2023 · 3 mos · New York, United States · Hybrid

  • Assessed the effectiveness of various tools/methodologies for detecting security vulnerabilities within Chrome Extensions and designed a comprehensive methodology to identify them at scale.
  • Audited 1000+ internal Chrome Extensions using tools such as CodeQL, Tarnish, and DoubleX, identifying 8000+ potential security vulnerabilities.
  • Contributed a Pull Request that enhanced Tarnish’s capabilities, enabling it to parse Manifest Version 3, operate on localhost, and expand its permissions identification functionality.
  • Crafted helper scripts that reduced manual auditing time by over 30%.
  • Uncovered a critical exploitable bug within an internal Chrome Extension used by 20k+ Googlers and presented findings to diverse security teams.
Security Vulnerability AssessmentCodeQLTarnishDoubleXPull RequestAuditing+3

0x000

CTF Player

Oct 2022Oct 2022 · 0 mo

  • Huntress CTF 2024: Earned a rank of 80 amongst 3k+ teams.
  • UMDCTF 2024: Achieved 7 out of 13 team solves and earned a rank of 23 in the Student's Division and 51 in all divisions.
  • Fetch the Flag CTF 2023 by Snyk: Earned a rank of 39 out of 1287 teams as a member of Space.Cows.
  • National Cyber League Fall 2023 by Cyber Skyline: Earned a rank of 106 out of 585 participants in the Individual Game a rank of 63 out of 457 teams in the Team Game within the Experienced Student Division.
  • CSAW'23: Our team "UMDCSEC" earned a rank of 1 solving all challenges.
  • Cyber Apocalypse CTF 2023 by HackTheBox: Earned a rank of 502 solving 27 challenges across categories such as Pwn, Forensics, Misc, Rev, Hardware, Crypto, and ML as the Team Captain of 0d4yR007 (two members).
  • LA CTF 2023 by UCLA: Earned a rank of 186 out of 980 teams as a member of the she!!_exp!0it team solving 9 challenges.
  • Pragyan CTF 2023 by NIT Trichy: Earned a rank of 69 out of 400 participants solving one reversing and one forensics challenge.
  • IrisCTF 2023: Earned a rank of 40 as the sole member of the team "Space.Cows".
  • DownUnderCTF 2022: Earned a rank of 544 with 500 points as a sole competitor (nier0x00) in the team “UMDCSEC-B”.
  • Flare-On CTF 2022: Earned a rank of 2475 in the competition.
  • National Cyber League Fall 2022: Earned a rank of 397 out of 6675 participants in the Individual Game.
CTFTeam Collaboration

Jupiter ai labs

Machine Learning Engineer Intern

Nov 2021May 2022 · 6 mos · Delaware, United States

  • Successfully implemented a data pipeline and API interface for the Taxonomy Recommendation and Classification Engine, utilizing APA's Azure SQL database.
  • Developed a Ticket Priority Scheduler that utilizes a blend of classification and regression algorithms to accurately prioritize tickets with a fresh data accuracy rate of 94%.
  • Conducted a comprehensive analysis of MMYT and EMT stocks, incorporating historical data from Yahoo Finance and existing quarterly financial statements to predict future stock values.
  • Utilized the Sobel Edge and Harris Corner Detection techniques, in conjunction with a Gaussian mixture model, to match appliance images and group their edges and corners.
Data PipelineAPI DevelopmentClassification AlgorithmsRegression AlgorithmsImage ProcessingMachine Learning+1

Lido

Data Analyst Intern

Sep 2021Oct 2021 · 1 mo · Delhi, India

  • Constructed an SQL query that automatically assigns a manager to BDAs/BDMs that are without a manager at that moment.
  • Created multiple SQL queries reporting sales metrics achieved by BDA/BDM/SDBMs and created Sales Dashboards in Metabase visualizing the same.
SQLSales Metrics ReportingDashboard CreationData Analysis

Cisco networking academy

Network Security Intern

Apr 2021Jul 2021 · 3 mos

  • Completed three Netacad courses (Introduction to Cyber Security, Cybersecurity Essentials and Introduction to Packet Tracer) and achieved 100% in the final assessment.
  • Implemented a network simulation of Bennett University on Packet Tracer divided into several departments with DHCP, NAT, ARP, HTTP, FTP, SMTP and other such protocols employed.
Network SimulationPacket TracerNetwork Security

Neubrain solutions pvt ltd

Data Security Administrator

Apr 2021Jun 2021 · 2 mos

  • Performed a comprehensive Penetration Test on Neubrain's web server hosting WordPress websites and uncovered 4+ critical vulnerabilities including the use of unsafe WordPress plugins, weak passwords, and insecure PHP code.
  • Upon immediate employment, performed Incident Response on defacement of the web server and reported the method of infiltration and exfiltration.
  • Reduced the attack surface by 40% by fortifying the WordPress server via Web Application Firewalls (WAFs), necessary upgrades and code reviews.
Penetration TestingIncident ResponseWeb Application FirewallsCybersecurity

Cosgrid networks

Cybersecurity Researcher

Jan 2021Apr 2021 · 3 mos

  • Led a team that created an IoT Device Classification and AI-powered Anomaly Detection prototype, using tools such as Spark, XGBoost, Sklearn, Zeek, Argus, and TShark, achieving 91% accuracy on fresh data. The prototype was selected as a finalist in the 'Cyber Security Grand Challenge!' organized by DSCI.
  • Successfully deployed Apache Metron as a Big Data Network Intrusion Detection Solution on an AWS IoT Greengrass testbed, achieving an accuracy of 92.4% and a false positive rate of 0.24% in detecting malicious attacks automated by Guardicore's Infection Monkey.
IoT Device ClassificationAnomaly DetectionBig Data Network Intrusion DetectionCybersecurity Research

Some college you haven't heard of

Teaching Assistant

Aug 2020Dec 2020 · 4 mos

  • Contributed towards creating Machine Learning Labs for peers.
  • Held doubt sessions for peers regarding labs and miscellaneous ideas in Machine Learning.
  • Helped out peers in Machine Learning problems, concepts and labs.
Machine Learning LabsPeer Support

Cryptus cyber security private limited

Ethical Hacker

May 2020Oct 2020 · 5 mos

  • Compiled Penetration Testing Reports on 2 vulnerable client sites and reported several highly critical vulnerabilities such as SQL Injection and Remote Command Execution (RCE).
  • Investigated technical aspects of fileless malware, documenting Office macro attacks and in-memory injection of payloads using PowerShell and gained insight into Active Directory engagements.
  • Dissected the internal workings of tools such as TheFatRat and Veil Framework and acquired a deeper understanding of encryption mechanisms such as XOR/AES Encryption and basic code obfuscation techniques.
  • Examined manual SQL injection, memory-based exploitation, and local/remote file inclusion attacks on dummy websites and open services on servers and developed scripts to automate exploitation using Python.
Penetration TestingVulnerability ReportingMalware InvestigationEthical Hacking

Education

University of Maryland

Master of Engineering - MEng — Cybersecurity

Aug 2022May 2024

Some College You Haven't Heard Of

Bachelor of Technology - B.Tech — Computer Science and Engineering

Jan 2018Jan 2022

Stackforce found 100+ more professionals with Security Engineering & Incident Response

Explore similar profiles based on matching skills and experience