[Sharing my life experiences, learnings and takeaways from my professional career and academia in InfoSec!]
As a growing information security professional and a life-long learner, Gaurav led the penetration tests, cloud and offensive security engagements for major PwC accounts and customers in the private sector, before pursuing his Master’s of Cybersecurity Engineering at Duke University.
Gaurav's extensive experience includes roles as a Senior Security Analyst at McKesson Corporation and at TATA Consultancy Services Limited, where he honed his expertise in adversary emulation, penetration testing and vulnerability assessments. Adept as a technical lead and an individual contributor both, he has a proven track record of leading multiple projects, mentoring team members, and exceeding objectives.
He is proficient in conducting extensive penetration testing assessments across a range of technologies, such as Websites, Applications, Networks, APIs, Active Directory, and Cloud (AWS, Azure Infrastructure, Office365, and Azure AD). He's gained offensive and defensive security skills simulating sophisticated adversary TTPs, organized with the MITRE ATT&CK framework, while building pro-active defenses against them.
Gaurav holds multiple certifications, including the INE fka eLearnSecurity Junior Penetration Tester (eJPT), Certified AppSec Pentester (CAPen) and is working towards his Offensive Security Certified Professional (OSCP) certification, which underpin his technical competencies. Notably, he has played a pivotal role in identifying and remedying critical vulnerabilities, considerably improving organizational security postures. His strong communication skills have been key to conveying complex security challenges and plans effectively to stakeholders and partners. He is always curious to connect with industry peers and leaders as we all navigate the evolving information security landscape.
CGPA: 3.825/4
Relevant Coursework: Cyber Risk Management, Security Incident Detection, Response, and Resilience, Advanced Concepts in Cloud Security, Management of High-Tech Industries, Identity and Access Management, Business Fundamentals for Engineers, Cyber Law/Policy
Affiliations: Duke Office of Information Technology (Student Worker), Duke Cyber and CTF Club (Technical Track Member), Duke Gaming Club, Duke Aviators Club
Teaching Assistant: CYBERSEC 590 - Advanced Secure Enterprise Network Architecture (under Prof. Karen Schnell for Spring 2025)
CGPA: 3.92/4
Relevant Coursework: System Analysis and Design, Number Theory & Calculus, Correlation, Regression & Analysis, Advanced Digital Electronics, Data Structures & Algorithms, Object Oriented Programming (OOPs), Computer Architecture, Computer Organization, Data Communication & Networking, UNIX & Shell Scripting
Affiliations: MIT Cricket Club
October 2024 - Present
(Student on-campus employment, Part-time)
October 2024 - Present
(Student on-campus employment, Part-time)
October 2024 - Present
(Student on-campus employment, Part-time)
July 2023 - June 2024
(Professional employment, Full-time)
June 2021 - June 2023
(Professional employment, Full-time)
Expected by April, 2025
Represented Duke University's Master of Cybersecurity Engineering program as a graduate student ambassador at the annual Cyber Risk summit in Philadelphia, Pennsylvania.
Awarded a merit-based competitive scholarship towards pursuing a Master's in Cybersecurity Engineering at Pratt School of Engineering, Duke University, by faculty director Professor Arturo Ehuan.
Recipient of the prestigious scholarship established in 1892 by Jamsetji Nusserwanjee Tata, awarded annually to the top 50 brightest Indian students from STEM and Law disciplines for overseas higher education.
Runner-up of the CTF and gamified hiring events hosted by TESCO, VISA, HackerOne, BugCrowd, Stryker.
Led and mentored a team of senior security analysts from Tata Consultancy Services to achieve 2nd Place in the annual CyberCup held by McKesson Corporation in Irving, Texas.
Secured 7th rank among 22,000+ participants; subsequently hired by TATA Group’s Cybersecurity Center of Excellence for outstanding performance in this Capture the Flag competition.
Achieved a Top 100 position among 5,000+ participants in the cybersecurity hackathon and Capture the Flag event organized by HackerEarth.
An actual redacted pentest report prepared by me as a part of independent security consulting for a UAE based customer dated September 2023.
Published a comprehensive CTI report, as a part of my own interest and mid-term examination for CYBERSEC 510 coursework under Prof. Arturo Ehuan
Published an in-depth case study, as a part of my mid-term examination for CYBERSEC 590 coursework under Prof. David Faraone
Prepared a ransomware playbook, as a part of my final examination for CYBERSEC 510 coursework under Prof. Arturo Ehuan
Prepared an end-to-end IRP (Incident Response Plan), as a part of my final examination for CYBERSEC 510 coursework under Prof. Arturo Ehuan
Prepared a IR (Incident Response) Policy, as a part of my final examination for CYBERSEC 510 coursework under Prof. Arturo Ehuan