Skip to content
View TharVid's full-sized avatar
🏆
Focusing
🏆
Focusing

Block or report TharVid

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
TharVid/README.md

Sunil Kumar

Senior Security Engineer | CISSP

+91-6376486690 | Jaipur, Rajasthan, India tharvid.in | LinkedIn | GitHub | stharvid@gmail.com


About Me

Senior Security Engineer with around 5 years of professional experience and CISSP certification, currently at Porch Group. I build and operate security systems across Cloud Security, DevSecOps, Incident Response, Security Automation, SOC Implementation, and Compliance. I specialize in securing multi-cloud environments (AWS, GCP, Azure), building scalable security automation workflows, and enabling faster threat detection and response through DevSecOps and SOAR practices.


Experience

Porch Group, Remote — Senior Security Engineer

Nov 2025 – Present (Security Engineer: Jun 2024 – Nov 2025)

  • Developed and maintained DevSecOps pipelines integrating SAST, IaC scanning, secret scanning, container scanning, DAST, API fuzzing, and dependency scanning. Automated vulnerability reporting to Jira for 500+ repositories and implemented ASPM for application security monitoring.
  • Implemented a SIEM solution integrating 100+ data sources, including custom integrations, parsers, correlation rules, and SOAR response workflows for automated incident response.
  • Onboarded 30+ AWS, GCP, and Azure accounts into CSPM, managing misconfigurations and indicators of attack.
  • Implemented Kubernetes runtime security across 15+ clusters via KSPM with real-time workload monitoring, behavioral threat detection, and automated policy enforcement.
  • Conducted CIS Critical Security Controls gap assessments across all 18 domains, ensuring PCI-DSS compliance.
  • Automated security workflows using Python, AWS Lambda, and Google Cloud Functions, embedding GenAI-driven alert enrichment and incident summarization.
  • Led enterprise GenAI security — deployed Lakera for real-time LLM protection (prompt injection, jailbreak, data leakage prevention) and secured LLM gateways via Portkey with policy enforcement, prompt filtering, and access controls.
  • Collaborated with global business units and leadership teams across subsidiaries to close vulnerabilities and enforce security policies enterprise-wide.

ACKO General Insurance, Bengaluru — Security Engineer

Aug 2021 – Jun 2024

  • Developed an advanced security system utilizing AWS CloudTrail, Config, Inspector, Detective, Macie, GuardDuty, and Security Hub for continuous monitoring and compliance.
  • Integrated DevSecOps stages into CI/CD pipelines — secret scanning, SAST, IaC security, container security, SCA, and DAST.
  • Managed triage of issues from bug bounty programs, DevSecOps, and cloud security tools.
  • Designed security policies for EDR, CASB, and MDM, enforced RBAC, SSO, and Conditional Access across Google Workspace, AWS, and GCP IAM.
  • Developed custom security tools — TPRM, phishing simulations, DNS security tool, and reporting solutions.
  • Led incident detection and response with deep log analysis and coordinated response.
  • Conducted risk assessments and penetration tests to identify and mitigate vulnerabilities.

Celebal Technologies, Jaipur — Associate, Cloud Infra and Security Intern

Feb 2021 – Jun 2021

  • Developed PoCs focused on M365 Security and cloud technologies.
  • Integrated Okta and Azure AD for centralized identity management.
  • Built Azure Monitor and Dynatrace dashboards for proactive threat monitoring.
  • Leveraged Microsoft Defender for Office 365 for real-time email threat protection.

Education

B.Tech, Computer Science & Engineering — Government Engineering College, Ajmer (2018–2022) | GPA: 7.94/10


Skills

Technologies: Cloud Security, DevSecOps, Security Automation, SOC, Incident Response, Threat Detection, SIEM, Penetration Testing, IAM, SAST, DAST, IaC Security, SCA, ASPM, CSPM, SOAR, DLP

Tools: AWS, GCP, Azure, Python, Docker, Jenkins, Git, Kubernetes, Burp Suite, Nmap, Wireshark, Metasploit, OWASP ZAP, CrowdStrike, NetSkope, Cloudflare, CheckPoint, Coralogix, Mimecast, Qualys, Rapid7, Google Chronicle, Okta, Azure AD

Frameworks: CIS Critical Security Controls, PCI-DSS, ISO/IEC 27001


Projects

GenAI-Based Security Alert Triage

Developed a GenAI-powered triage engine using Claude with MCP-based integrations to fetch context from SIEM, XDR, ticketing systems, historical incidents, and SOPs. Enables intelligent alert analysis across EDR, Cloud, and Application Security domains with automated TP/FP classification, enrichment, and actionable response recommendations. Reduced triage time from 30 minutes to under 60 seconds.

Enterprise SOAR Workflow Automation

Built an enterprise SOAR workflow integrating CheckPoint, Entra ID, Okta, Mimecast, Jira, PagerDuty, CrowdStrike XDR, Google Workspace, AWS, and GenAI-based enrichment to automate incident response from SIEM detections across multiple subsidiaries, significantly reducing MTTR.

DevSecOps Pipeline with Open-Source Tools

Implemented an open-source DevSecOps pipeline using Jenkins with Semgrep, Checkov, Trivy, Gitleaks, OWASP ZAP, and AWS ECR scanning. Automated parsing and reporting to Jira and DefectDojo.

Phishing Awareness Platform

Developed a phishing simulation platform using Gophish on AWS EC2 with Amazon SES for large-scale phishing campaigns and employee security awareness training.


Certifications

  • CISSP (Certified Information Systems Security Professional) — Verify
  • CompTIA Security+Verify
  • AWS Certified Security – SpecialtyVerify
  • Google Cloud Professional Cloud Security EngineerVerify
  • Docker Foundations Professional Certificate
  • AWS Certified Cloud Practitioner
  • Microsoft Certified: Azure Security Engineer Associate

Languages

English | Hindi


Blog

I write about security engineering, certifications, and career growth at tharvid.in/blog.

Recent posts:

Popular repositories Loading

  1. Open-Source-Badge-Generator Open-Source-Badge-Generator Public

    Open Source Badge Generator

    JavaScript 6 22

  2. TharVid.github.io TharVid.github.io Public

    Amazing portfolio website using HTML, CSS, JS.

    HTML 4 4

  3. portfolio portfolio Public

    Portfolio Website

    HTML 3 7

  4. android-root android-root Public

    Root Android Without PC

    2 1

  5. hacktoberfest-2020 hacktoberfest-2020 Public

    Forked from tasnimzotder/hacktoberfest-2020

    Let's change the world together with Open-Source & tackle Climate-Change

    HTML 1

  6. devfest-india-2020 devfest-india-2020 Public

    Forked from nikiyasimpson/devfest-india-2020

    Vue 1