Swarup Saha

About

About

Security Researcher by Profession, Philosopher by Mind.


I am Swarup Saha, a Security Engineer working in banking cybersecurity, where even a small weakness can carry serious operational and business consequences.

My work spans both sides. On the offensive side, I run assessments across web, API, mobile, network, and enterprise infrastructure — finding vulnerabilities, mapping attack paths, and validating that remediation actually holds. On the defensive side, I work across SOC operations, SIEM, threat hunting, incident investigation, detection engineering, and vulnerability management.

What interests me most is connecting the two — using what attackers do to sharpen how defenders detect and respond. Alongside this, I build automation in Python, publish open-source security tools, and research how LLMs and Agentic AI can augment both offensive and defensive workflows.

Areas of work

Areas of work grouped by discipline
Offensive SecurityFinding weaknesses before attackers do.Web Application Penetration Testing, API Security Testing, Mobile Application Security, Network Penetration Testing, Vulnerability Assessment, Red Team Operations, Security Research
Defensive SecurityDetecting, hunting, and responding at SOC scale.SOC Operations, SIEM, IBM QRadar, Threat Hunting, Incident Response, Threat Intelligence, Vulnerability Management
Programming & AutomationTurning repetitive security work into code.Python, JavaScript, TypeScript, Bash, Security Automation, REST APIs
AI & Emerging SecurityApplying LLMs and agents to real security problems.LLM Applications, Prompt Engineering, Retrieval-Augmented Generation (RAG), Agentic AI Workflows, AI Security, Security Copilots, AI-Powered SOC, AI-Powered Penetration Testing
Platforms & InfrastructureThe environments everything runs on.Linux, Windows, Docker, GitHub, DigitalOcean, Cloudflare, Networking

Certifications

Professional certifications
CEHCertified Ethical HackerEC-CouncilActive
CISACertified Information Systems AuditorISACAActive
eCPPTeLearnSecurity Certified Professional Penetration TesterINE SecurityActive

Recognition

  • Champion — National Cyber Drill 2026 (2026)MTB CyberSavvy team.
  • Third Place — FINCII 2024 (2024)BGD e-GOV CIRT financial-sector cyber drill.
  • Security research & vulnerability discoveriesResponsible disclosure of security weaknesses across web and API targets.
  • Recognition for critical security findingsProfessional recognition for high-impact vulnerabilities reported through proper channels.
  • Cybersecurity community participationActive in local security communities and security conferences.