MS Cybersecurity · Northeastern · Boston, MA

Hrishikesh Jadhav.

Detection Engineering · Cloud Security · AppSec · Pentesting

Hrishikesh Jadhav

About.

A cybersecurity engineer who likes to build, break, and defend systems end to end.

I work across detection engineering, cloud security, and application security. That covers standing up a SIEM and writing custom detection rules mapped to MITRE ATT&CK, deploying and hardening Linux servers and AWS infrastructure, and manual web app pentesting with Burp Suite. I like the full loop: simulating an attack, watching what fires (and what doesn't), and closing the gap honestly.

I'm pursuing an MS in Cybersecurity at Northeastern's Khoury College, and previously spent two years as a Software Engineer building encrypted government APIs, deploying self-hosted infrastructure, and hardening systems with Python and Bash automation. Lately I've been exploring the security of LLM deployments: prompt injection, data leakage, and the OWASP LLM Top 10. I write up what I learn on my blog and stay sharp through CTFs, Hack The Box, and bug bounty.

Experience & Education.

Sept 2023 — Sept 2025

Divvya CPP Private Limited

Software Engineer

Configured a Wazuh SIEM end to end: dashboards, detection rules, alert thresholds, and log analysis. Built a digital-envelope API for Indian Customs using hybrid encryption (AES + RSA) with certificate validation to exchange government shipment data. Deployed and configured AWS infrastructure (VPCs, security groups, RDS, site-to-site VPN, IoT Core), hardened Linux servers with Python/Bash automation for firewall rules and access controls, and stood up self-hosted CI/CD, version control, and password-management platforms. Also handled on-site physical security installs: IP cameras, network switches, and IoT readers.

Apr 2022 — May 2022

Alancesec Private Limited

Cybersecurity Intern

Manual web application penetration testing with Burp Suite, Metasploit, and SQLmap. Discovered authentication bypass, IDOR, XSS, and injection flaws, wrote vulnerability reports with remediation recommendations, and retested patched systems to confirm fixes.

2025 — Dec 2027

Northeastern University

MS Cybersecurity · Khoury College of Computer Sciences · GPA 3.9/4.0
Computer System Security Cybersecurity Threats & Defenses Decision Making in Critical Infrastructure Kubernetes
2019 — May 2023

Zeal College of Engineering & Research, Pune

BE Computer Science · GPA 9.02/10
Operating Systems Computer Networks Cryptography Data Structures & Algorithms

Projects.

AcquiGraph M&A Attack Surface Visualizer

Maps how mergers and acquisitions expand attack surface (parent → subsidiaries → domains → cloud assets → vendors) with automated risk scoring. Pulls subsidiary lists from SEC EDGAR (Exhibit 21), propagates risk upward via Cypher traversals, detects attack paths, and renders it all in interactive D3.js dashboards. One-command Docker deploy.

FastAPI React D3.js Neo4j Docker

Detection Engineering & SIEM Lab

A 3-VM isolated lab (Kali attacker, Windows + Sysmon victim, Ubuntu Wazuh manager). Simulated SMB brute force, scheduled-task persistence, Mimikatz credential dumping, and LLMNR poisoning, and wrote custom detection rules mapped to MITRE ATT&CK. Documented a real host-level detection gap for LLMNR poisoning rather than hiding it.

Wazuh Sysmon MITRE ATT&CK Kali Linux

AI-Powered Security Learning & Automation Tool

Self-hosted LLM agent on personal infrastructure, reached over zero-trust remote access with no port forwarding. Automates bug bounty report curation into a daily Discord digest, turns synced notes into spaced-repetition quizzes, and runs a CTF practice pipeline into a local CTFd instance. Researched prompt injection and data leakage risks along the way.

LLM Agent Zero Trust Automation Prompt Injection

Recon Automation Framework

A Python framework for external attack surface reconnaissance (subdomain enumeration, port scanning, screenshotting, and Nuclei vulnerability scanning) with automated alerting when newly exposed assets appear.

Python Nuclei Recon Automation

Cyber-Physical Vulnerability Assessment of Boston's Electric Grid

DHS final research paper analyzing SCADA/OT vulnerabilities and IT/OT convergence risk across critical infrastructure. Modeled cascading-failure scenarios against threat vectors and prioritized mitigations, aligned to NIST CSF and NIST SP 800-82.

OT Security SCADA / ICS NIST CSF NIST 800-82
Scroll horizontally →

Blog & Practice.

Skills.

Languages
Python Bash JavaScript C++ x86 Assembly SQL
Security
SIEM (Wazuh) Penetration Testing Vulnerability Assessment Detection Engineering Incident Response Log Analysis Threat Detection
Cloud & Infra
AWS Linux Windows Server Docker Kubernetes CI/CD
Tools
Burp Suite Caido Nuclei Metasploit SQLmap Wireshark Nmap Volatility
Frameworks
NIST CSF NIST SP 800-82 ISO/IEC 27001 CIS Controls v8 OWASP Top 10 MITRE ATT&CK
AI / LLM Security
LLM Deployment Prompt Injection OWASP LLM Top 10

Connect.

Got a role, a challenge, or a question? Let's talk.