About
About
Security Researcher by Profession, Philosopher by Mind.
I am Swarup Saha, a Security Engineer working in banking cybersecurity, where even a small weakness can carry serious operational and business consequences.
My work spans both sides. On the offensive side, I run assessments across web, API, mobile, network, and enterprise infrastructure — finding vulnerabilities, mapping attack paths, and validating that remediation actually holds. On the defensive side, I work across SOC operations, SIEM, threat hunting, incident investigation, detection engineering, and vulnerability management.
What interests me most is connecting the two — using what attackers do to sharpen how defenders detect and respond. Alongside this, I build automation in Python, publish open-source security tools, and research how LLMs and Agentic AI can augment both offensive and defensive workflows.
Areas of work
| Offensive SecurityFinding weaknesses before attackers do. | Web Application Penetration Testing, API Security Testing, Mobile Application Security, Network Penetration Testing, Vulnerability Assessment, Red Team Operations, Security Research |
|---|---|
| Defensive SecurityDetecting, hunting, and responding at SOC scale. | SOC Operations, SIEM, IBM QRadar, Threat Hunting, Incident Response, Threat Intelligence, Vulnerability Management |
| Programming & AutomationTurning repetitive security work into code. | Python, JavaScript, TypeScript, Bash, Security Automation, REST APIs |
| AI & Emerging SecurityApplying LLMs and agents to real security problems. | LLM Applications, Prompt Engineering, Retrieval-Augmented Generation (RAG), Agentic AI Workflows, AI Security, Security Copilots, AI-Powered SOC, AI-Powered Penetration Testing |
| Platforms & InfrastructureThe environments everything runs on. | Linux, Windows, Docker, GitHub, DigitalOcean, Cloudflare, Networking |
Certifications
| CEH | Certified Ethical Hacker | EC-Council | Active |
|---|---|---|---|
| CISA | Certified Information Systems Auditor | ISACA | Active |
| eCPPT | eLearnSecurity Certified Professional Penetration Tester | INE Security | Active |
Recognition
- Champion — National Cyber Drill 2026 (2026) — MTB CyberSavvy team.
- Third Place — FINCII 2024 (2024) — BGD e-GOV CIRT financial-sector cyber drill.
- Security research & vulnerability discoveries — Responsible disclosure of security weaknesses across web and API targets.
- Recognition for critical security findings — Professional recognition for high-impact vulnerabilities reported through proper channels.
- Cybersecurity community participation — Active in local security communities and security conferences.