cyber_security_professional//all-rounder

Devangshu
Mazumder_

MSc Cyber Security and independent security researcher on the leading bug-bounty platforms. I secure systems end to end, hardware, malware, web, cloud and compliance, and move fast by putting AI, LLMs and cloud tooling to work.

bug bounty · freelanceopen to collabescar Europe 2025 · publishedMSc · Univ. of BirminghamNorthrop Grumman ScholarCEH v13 · Security+AWS Security
about

cat about.md

about.md · bash
dev@mazumder:~$ cat about.md

I'm a cyber security engineer who likes building things as much as breaking them. My core is programming, problem solving and security. I write code that actually ships, I pull hard problems apart until they make sense, and I think about how a system breaks before someone else does. That spans offensive work, blue team, cloud and software engineering, and these days I run my own independent security research on HackerOne, Bugcrowd and Intigriti, turning findings into validated, high impact reports.

On the job I've covered a lot of ground. At Oracle I was a software engineer on the Foreign System Interfaces team, leading code reviews and security assessments across clinical products like Millennium, PharmNet, RadNet and PowerChart. I was the L3 escalation point and subject matter expert for high priority clients, closing out 80+ complex code and interface failures, and I led a team of seven system engineers and two solution analysts, running knowledge transfer sessions and writing the incident playbooks we leaned on. Before that I was a cloud engineer at GE, rotating through DevOps, cloud and shift left security, and a security analyst at mDrift Technologies, where I ran OWASP Top 10 assessments and hardened endpoints for a startup.

A few things I'm proud of: an MSc in Cyber Security from the University of Birmingham on a Northrop Grumman merit scholarship, one of seven awarded; a research paper I presented at escar Europe 2025 in Frankfurt to CISOs and CTOs from global automotive OEMs; and recognition at Oracle from managers, executives and clients under their Commit, Deliver, Engage and Collaborate values.

On paper I hold CEH v13, CompTIA Security+, AWS Security, Blue Team Junior Analyst, Qualys VMDR and ISO 21434 automotive cyber security, with a handful of OSINT, network analysis and cloud foundations certs behind them.

However I get there, I lean on AI and LLMs to move fast: LLM assisted triage, cloud scale scanning, automation first tooling. Less time on the repetitive parts, more on the calls that genuinely need a human who understands the threat.

Focus
Research · Offensive · Cloud
Based
United Kingdom
Certs
CEH v13 · Security+ · AWS
Status
Bug bounty · Freelance
skills

htop --skills

htop, capability monitor
// hover or drag the reactor

Offensive Security

Web App Pentestingadvanced
Network Recon · Nmapadvanced
Protocol / CAN Fuzzingproficient
OWASP ZAP · Burpproficient

Reverse Eng · Hardware

CAN Bus · Automotiveadvanced
ARM Firmware REproficient
Unicorn Rehostingproficient
UART · SPI · JTAGfamiliar

Cloud · Automation

Linux · Bashadvanced
Docker · Containersproficient
CI/CD Pipelinesproficient
Cloud-Scale Scanningproficient

AI-Augmented Workflow

LLM-Assisted Triageadvanced
Prompt Engineeringadvanced
Automation Scriptingadvanced
Pythonadvanced
// certifications:CEH v13CompTIA Security+AWS SecurityBlue Team Junior (BTJA)Qualys VMDRISO 21434 AutomotiveOCI Foundationsnasscom NSQF L7Intro to OSINTNetwork Analysis// languages: Python · C · Bash · JavaScript
dev@mazumder:~/soc$ tail -f events.log
    featured_work

    ls -la ./projects

    [ hardware ][ automotive ]01

    Real-Time Video Detection for CAN Bus Fuzzing

    hardware · Pairs a live video-detection model with CAN-bus fuzzing to catch automotive faults traditional fuzzers miss, a cyber-physical technique that generalises to any sensor-driven system.

    [ malware ][ crypto ]02

    Ransomware Decryptor, Rescuing Hank's Files

    malware · Reverses an AES-CBC ransomware payload in Python and rebuilds the locked files into a clean directory, malware analysis turned into a working recovery utility.

    [ firmware ][ reverse-eng ]03

    ARM Firmware Rehosting on a Raspberry Pi Pico

    firmware · Reverse-engineers UART and SPI on a Pico-based security token, then rehosts a key firmware routine with the Unicorn engine to run and analyse it entirely off-device.

    [ web ][ iot ]04

    XTU-J9 Smart Doorbell, Penetration Test

    web · iot · Full pentest of a consumer smart doorbell, mapping the web and network attack surface and documenting data-exposure and encryption weaknesses in a formal report.

    [ compliance ][ cloud ]05

    GDPR Compliance Scanner, ZAP + Nmap

    compliance · cloud · Orchestrates OWASP ZAP and Nmap into one automated audit, cookie analysis, third-party script detection and scanning that scales across a whole estate, not one page at a time.

    [ ai-security ][ offensive ]06

    MCP-Sentinel

    ai-security · Building a static + dynamic scanner that audits Model Context Protocol servers, the fastest-growing AI attack surface of 2026, with 40+ CVEs disclosed in four months. It fuzzes live MCP servers for tool-poisoning, prompt-injection, auth-bypass, and path-traversal flaws, then grades each finding with reproducible proof-of-concept requests.

    [ details ][ building ]
    [ blue-team ][ detection-as-code ]07

    DetectForge

    blue-team · Building an LLM-assisted detection-as-code pipeline that turns a raw threat-intel report into a validated, ATT&CK-mapped Sigma rule with an automated test, compressing intel-to-deployment from days to minutes. Every rule is generated, converted to SIEM queries, sandbox-validated against an Atomic Red Team test, and opened as a pull request, so it's proven to fire before it merges.

    [ details ][ building ]
    [ cloud ][ deception ]08

    DecoyNet

    cloud · Building a one-command mesh of cloud honeypots and AWS canary tokens that lures attackers and fires a CloudTrail alert the instant a planted credential is used. An LLM classifies each attacker session into TTPs and streams a near-zero-false-positive threat-intel feed to a live attack map.

    [ details ][ building ]
    career

    git log --oneline career

    e2c9d7a(HEAD -> main)bug bounty · freelancefeat: Security Researcher, bug-bounty platforms
    Independent research across HackerOne, Bugcrowd and Intigriti, turning findings into validated, high-impact reports and tracking the latest tooling and TTPs.
    Dec 2025 to present
    a1f9c02(tag: msc)edu: MSc Cyber Security @ University of Birmingham
    Northrop Grumman merit scholarship, one of seven. CAN-bus fuzzing, ARM rehosting, IoT pentesting and compliance tooling.
    2023 to 2024
    7d3b8e1feat: Software Engineer @ Oracle
    Foreign System Interfaces team. Code reviews and security assessments across Millennium, PharmNet, RadNet and PowerChart. L3 escalation point and SME on 80+ complex failures. Led 7 system engineers and 2 solution analysts.
    Sept 2022 to May 2023
    3c07af5feat: Cloud Engineer @ GE
    System Integrations team, rotating through DevOps, cloud and shift-left security. Delivered 3 developments alongside Accenture, Deloitte and Genpact.
    Jan 2022 to Jul 2022
    b52e6d4feat: Security Analyst @ mDrift Technologies
    OWASP Top 10 vulnerability assessments and endpoint hardening across distributed environments. Migrated the company site and databases from Django to Wagtail.
    May 2021 to Jul 2021
    0e4d1a9(tag: btech)edu: BTech Computer Science @ VIT
    Foundations in systems, software, and the security mindset.
    2018 to 2022
    contact

    ./open --channel

    send_message.sh
    whoami, contact
    dev@mazumder:~$ whoami --contact
    status● open to work
    // integrity demo, type anything, it's hashed locally (SHA-256, never sent):
    sha256: -