Dhrupad J.

Security Engineer | Penetration Testing, Detection Engineering & Incident Response | Ex-KPMG | 4 CVEs | MS Cybersecurity @ Penn State

United States

About

Cybersecurity professional with 3 years of experience in penetration testing, incident response, and vulnerability management. At KPMG, led 10+ breach and attack simulations and identified 150+ vulnerabilities. At CableLabs and Penn State, built detection and lab systems that improved threat visibility and training outcomes. I am now targeting Cybersecurity Engineer opportunities where I can apply offensive security, secure coding, and detection engineering expertise

Experience

  • Research And Teaching Assistant at Penn State University
    Aug 2024 - May 2026 · 1 yr 10 mos

    • Built a browser-based Intrusion Detection lab with v86, WebAssembly, and Buildroot to deliver attacker/defender incident-response labs without local virtualization or cloud-hosted lab infrastructure. Project: https://polylab.ist.psu.edu/snort/ • Implemented a JavaScript Layer 2 bridge so browser-based VMs could communicate without external relays or server. • Built randomized lab scenarios with Snort detections, and flag validation workflows to train 50+ students in IDS. • Presented the browser-based intrusion detection lab at the CAE Symposium in "Retention and engagement measurement in cyber labs with lower overhead and unique parameters" (p. 51). • Architected GenAI learning assistant for secure coding guidance by prompt-driven hints and contextual feedback while preserving student problem-solving. Link : http://104.131.52.52 • Administered DigitalOcean hosted lab infrastructure with hardened Linux access controls, SSH key-based administration, PAM/sudo privilege controls, firewall configuration, and least-privilege operational practices.

  • Network Security Specialist at CableLabs
    May 2025 - Aug 2025 · 4 mos

    DDoS Mitigation, DDoS and +10 skills

  • KPMG India (1 yr 5 mos)
    • Cyber Defense & IR Associate Consultant
      Apr 2024 - Aug 2024 · 5 mos

      • Led 10+ enterprise breach and attack simulations across ransomware, phishing, data leakage, lateral movement, and control-evasion scenarios, identifying 150+ vulnerabilities and earning KPMG Rising Star recognition. • Conducted Vulnerability Assessment and Penetration Testing (VAPT) across networks, servers, endpoints, and AWS/Azure environments using Tenable.sc, Nessus, Qualys, Nmap, Python, Bash, and PowerShell. • Performed web, API, Android, and thick-client security assessments, identifying authentication, authorization, and business logic flaws aligned with OWASP Top 10. • Executed endpoint reviews, phishing campaigns, ransomware/DLP simulations, and red team assessments to evaluate detection coverage and incident response effectiveness. • Implemented Checkmarx and HCL AppScan workflows to support SAST/DAST testing, secure SDLC initiatives, and developer remediation training. • Reviewed bug bounty findings, prioritized exploitability, documented business impact, and coordinated remediation with engineering and security stakeholders.

    • Cyber Defense and IR Analyst
      Apr 2023 - Apr 2024 · 1 yr 1 mo

      • Deployed 15+ SIEM-integrated honeypots using deception, landmine, and intrusion-detection techniques, improving threat intelligence coverage by 40% and enabling proactive detection of 250+ security events. • Developed PowerShell tooling to automate endpoint assessments, emulate adversary behavior, and identify attack paths across Windows environments. • Deployed Tenable.sc on client environments, configuring scan policies, asset groups, dashboards, and reporting workflows for enterprise vulnerability management. • Built automated reporting and rescan workflows, trained stakeholders on remediation processes, and increased patching efficiency by 37%. • Reviewed firewall configurations, IT controls, and incident management reports to identify security gaps, improve threat detection, and strengthen network defense. • Supported incident response investigations, remediation validation, and security control testing across enterprise environments.

  • Software Engineer at Capgemini
    Jul 2021 - Mar 2023 · 1 yr 9 mos

  • IT Engineer and Security Researcher at Freelance
    Dec 2019 - Jul 2021 · 1 yr 8 mos