Available for senior roles Β· Vancouver, BC

<GP Singh />

I build security tools that close the gap between detection and action.
5 tools shipped Β· autonomous HTB pipeline Β· 2.4M domains blocked Β· zero cloud APIs.

terminal β€” gp@kali: ~

Cyber Security
Engineer

Cyber Security Engineer at lululemon, Vancouver BC β€” building automation that closes the gap between vulnerability discovery and remediation.

When I joined, vulnerability management was entirely manual β€” check Wiz, MDE, Qualys, and Recorded Future by hand, find asset owners, cut tickets one by one. Days of work per CVE cycle. I built an AWS Lambda pipeline that automated ownership mapping, correlated findings across all four tools, and routed tickets automatically to the right teams. Mean time from CVE identification to ticket dropped from days to under 30 minutes. After integrating AI-driven contextualization against the CISA KEV catalog, that became seconds β€” with severity normalized to our actual environment, not raw CVSS.

Outside of work: 5 shipped security tools in Python, a self-hosted homelab running Wazuh, Greenbone, and a full vulnerability management pipeline β€” and an autonomous HTB pentest agent that handles recon through exploitation without human input.

TryHackMe top 1%. 10+ TCM Security certifications. Target: OSCP 2028, Staff Security Engineer shortly after.

βœ…
Practical Ethical Hacking β€” TCM Security 2024
βœ…
Practical Web Hacking β€” TCM Security 2024
βœ…
Practical API Hacking β€” TCM Security 2024
🎯
OSCP β€” Offensive Security 2028
5 tools shipped
10+ certs earned
top 1% TryHackMe
2.4M domains blocked

Things I've Built

Each one solves a real security problem. Built in Python, runs on-prem, open source.

πŸ”
β–  Shipped
P1 β€” SAST+DAST Triage Tool
↓ 60%+ alert volume Β· deduplicated across 3 scanners Β· CI-ready SARIF export

Deduplicates Semgrep/Bandit/ZAP findings by CWE+location, scores risk 0–10, LLM false-positive filter, SARIF 2.1.0 export for GitHub Code Scanning.

PythonSemgrepOWASP ZAPSARIFOllama
πŸ—ΊοΈ
β–  Shipped
P2 β€” Threat Model Generator
Full STRIDE report in <30s Β· compliance flags auto-detected Β· exec-ready HTML output

STRIDE analysis across all components. MITRE ATT&CK + OWASP + NIST mapping. Auto-flags GDPR/PCI-DSS violations. On-prem LLM narratives. Executive HTML report with Chart.js visuals.

PythonSTRIDEMITRE ATT&CKOllama
πŸ“‘
β–  Shipped
P3 β€” AI Log Anomaly Detector
7 MITRE ATT&CK patterns Β· AbuseIPDB enrichment Β· real-time alerts on live homelab traffic

Parses auth.log + journalctl JSON, detects 7 attack patterns mapped to MITRE ATT&CK with confidence scoring. AbuseIPDB enrichment, email alerts, local LLM assessment.

PythonMITRE ATT&CKAbuseIPDBOllama
πŸ€–
β–  Shipped
P4 β€” Mini-CRS
100% automated fix rate Β· fuzz β†’ triage β†’ patch β†’ validate, zero human input

Autonomous vulnerability discovery inspired by DARPA AIxCC. AFL++ fuzzing β†’ ASan/GDB triage β†’ LLM root cause (CWE) β†’ patch generation β†’ recompile + validate. Pluggable LLM: Ollama, Claude, OpenAI.

PythonAFL++AddressSanitizerCWEClaude
πŸ€–
β–  Shipped
P5 β€” ATLAS (Autonomous Pentest Pipeline)
Rooted HTB machines autonomously Β· recon β†’ exploit β†’ report without human input

Autonomous HTB/CTF pentest agent: recon β†’ enum β†’ web β†’ exploit β†’ report. Parallel tool execution β€” nikto+gobuster, enum4linux+ldap+snmp run simultaneously. Human-in-the-loop checkpoints. LLM-guided at every stage.

PythonnmapgobusterThreadPoolExecutorOllama
🚩
β—‹ Active
CTF Lab

HackTheBox and TryHackMe machine writeups with custom exploit scripts. Commit-on-root discipline: every rooted machine β†’ writeup β†’ push.

HTBTHMOffensiveWriteups
βš™οΈ
β—‹ Active
Memory Safety Lab

Hands-on C exploitation β€” stack overflows, heap corruption, UAF. GDB + pwndbg analysis. Foundation for OSCP exploit development track.

CGDBpwndbgOSCP prep
View all projects β†’

Tech Stack

Vulnerability Management
WizMicrosoft Defender for Endpoint QualysRecorded Future AWS LambdaCISA KEV DefectDojoGreenbone
SIEM / Detection
SplunkIBM QRadar ELK StackAzure Sentinel AWS GuardDutyFortisiem MISPSTIX/TAXII
Offensive / AppSec
Burp SuiteOWASP ZAP NmapMetasploit WiresharkNessus HashcatGDB/pwndbg
Cloud / IAM
Azure DefenderAzure WAF AWS IAMOkta Active DirectoryIDS/IPS SOARPAM
Dev / Automation
Python 3.11+Bash Ollama (local LLM)MITRE ATT&CK SARIF 2.1.0Docker GitHub ActionsSemgrep

Production Security Lab live

A real self-hosted infra stack β€” not a tutorial VM. Used daily for security practice, tool development, monitoring, and offensive lab work.

πŸ–₯️ Proxmox VE
Bare-metal hypervisor. 10+ VMs & LXCs, ZFS RAID mirror, 64GB RAM.
HypervisorZFS
πŸ”₯ OPNsense
Firewall VM with IDS/IPS, VLANs, traffic rules, and WAN edge protection.
FirewallIDS/IPS
πŸ›‘οΈ Wazuh SIEM
8 agents across the homelab. Real-time threat detection, file integrity monitoring, compliance checks.
SIEM8 agents
πŸ” Greenbone + DefectDojo
Automated vuln scanning pipeline β€” Greenbone discovers, DefectDojo tracks and triages findings.
Vuln MgmtCVE
🌐 Pi-hole + DoH
Network-wide DNS filtering β€” 2.4M blocked domains. Cloudflare DoH upstream via cloudflared. DNSSEC enabled.
DNSDoHDNSSEC
πŸ“Š Grafana + Prometheus
Live metrics across all hosts β€” CPU, RAM, network, disk. Node exporters on every container.
MonitoringMetrics
πŸ€– Ollama (Local LLM)
Hermes 3 70B, Qwen, Llama running on-prem. Powers all security tools β€” no data leaves the network.
LLMOn-premAI
🎯 Kali + ATLAS Lab
Dedicated offensive security VM. Runs ATLAS autonomous pentest pipeline for HTB/CTF targets.
KaliPentestHTB
πŸ•ΈοΈ Traefik + Cloudflare
Reverse proxy with zero-trust tunnel. All services exposed via subdomain with TLS β€” no open ports.
Reverse ProxyZero Trust
🍯 Cowrie Honeypot
SSH/Telnet honeypot capturing attacker TTPs. Logs credential attempts and lateral movement patterns.
HoneypotDeception

Security Lab Notes

Technical writeups on tools I build, machines I root, and concepts I'm learning. Published on dev.to.

AI Log Anomaly Detector: auth.log to MITRE ATT&CK in 30 Seconds

Why I Built This

/var/log/auth.log is full of signal. Brute forces, privilege escalations, new user accounts β€” all there. But finding them …

Building a SAST+DAST Triage Tool with AI False-Positive Filtering

The Problem with Raw Scanner Output

Run Semgrep and Bandit on the same Python repo and you’ll get the same SQLi finding at app.py:42 …

HackTheBox: Archetype Walkthrough

Target

Archetype β€” HTB Starting Point, Windows machine.

IP: 10.10.10.27

Enumeration

nmap -sV -sC -p- 10.10.10.27

Interesting ports:

  • 445/tcp …

All posts on dev.to β†—

Let's Talk

Open to Senior / Staff Security Engineer roles β€” Vancouver or remote. I bring production tooling, a working offensive lab, and real detection engineering experience. Not looking for recruiters, looking for engineers.