ravi@rajput:~$
ravi@rajput: ~/portfolio — 80×24

$ whoami --verbose

Ravi Rajput — security automation leader & offensive researcher. Hyderabad, India.

11+ years breaking systems, 3 shipping AI that defends them.

tagline: I build AI that runs security operations, break AI before

attackers do, and red-team everything in between — web, cloud,

hardware, and industrial.

$ cat pillars.txt

$

916K+
detections handled in production
78%
auto-resolved, no human touch
$1.2M
revenue anchored by SecAI
11
conference stages, 3 continents
6
open-source security projects
[01]

Work that shipped

Seven things built or broken — each one changed a real number for a real organisation.

Xalon — production agentic SOC

PROD2025—NOW

22 specialised agents on Microsoft AutoGen 0.4 with Anthropic Claude and Google Gemini in adversarial reasoning, on Azure Kubernetes. Every agent runs inside least-privilege IAM boundaries under a threat model I red-team myself with PyRIT and Garak. Five-lane severity-tiered model routing keeps daily LLM spend at $25–40 against a workload that would otherwise cost $375–500.

10–12Kalerts ingested / day
78%auto-resolution
$110K/yroperating savings
30×per-alert cost differential

SecAI — SaaS LLM vulnerability scanner

PROD2023—25

Proprietary scanner implementing the OWASP Top 10 for LLM Applications 2024 — prompt injection, insecure output handling, data-poisoning exposure — built and delivered at SourceHOV for Oracle, AIDO, and LLA client environments.

$1.2Mannual client revenue anchored
50%critical AI-app risk cut in 6 months

LLM-PT — autonomous LLM pentesting suite

OSS

A Python CLI that orchestrates promptfoo, Garak, and DeepTeam against LLM-backed web apps, APIs, and websockets — testing the OWASP Top 10 for LLM Applications (2025). Point it at a Burp Suite request export and an LLM works out which field carries the user prompt, so payloads land in the right place with no manual wiring. Findings normalise into one schema, an optional LLM judge re-scores hits, and results emit as SARIF for CI/CD.

MLSec-Analyzer — model-file security scanner

OSS

Static analysis for the ML supply chain: pickle RCE, Keras Lambda RCE (CVE-2024-3660), GGUF overflow, zip-slip, embedded secrets, and backdoored-weight anomalies across seven model formats. SARIF output for CI/CD.

LSTM Automotive Security — CAN-bus intrusion detection

OSSDEF CON 33

LSTM Autoencoder and Variational Autoencoder detecting replay attacks, fuzzing, timing deviations, and entropy anomalies on raw CAN telemetry — no proprietary DBC decoding needed. Presented on the DEF CON 33 Creator Stage.

AutoHackOS — vehicle pentesting operating system

OSSBLACKHAT ASIA

A bootable distro that puts CAN, BLE, telecom/SDR, firmware, and network tooling in one place — ending the multi-VM juggling act for vehicle security teams. Demonstrated at BlackHat Asia 2023 Arsenal.

The VinFast research — 0-day in a shipping vehicle

0-DAY2022

At AmynaSec Research Lab: a 0-day Chromium browser exploit, an Android companion-app vulnerability, and a cloud-side bug in a production vehicle platform — disclosed to VinFast with direct CEO acknowledgement. Part of pentesting across 20+ vehicle communication protocols, later extended to Modbus and ICS/SCADA assessments on live plant floors.

[02]

Leadership

The hacker builds and breaks. The manager makes it repeatable, billable, and survivable — through an acquisition, across 20+ enterprise clients.

ravi@rajput:~$ cat leadership-brief.txt
11–20
Cross-functional team of engineers, SOC analysts, and shift-roster managers — led through a post-acquisition transition without losing a client.
$1.2M
Revenue book owned. SecAI anchored directly-attributable annual client revenue across Oracle, AIDO, and LLA — partnerships retained to this day.
40%
Faster incident response across 20+ enterprise clients after redesigning the SOC and Red Team operating model at SourceHOV.
30×
Cost engineering as strategy. Severity-tiered model routing turned AI from a cost risk into a $110K/yr saving — with per-agent, per-incident cost observability.
1 practice
Built from zero. Founded and led the Automotive Security practice at BlueBinaries — ISO/SAE 21434 programmes for OEM and Tier-1 clients.
3 yrs
Mentorship at scale. NULL Ahmedabad chapter lead — free monthly security training; today mentoring engineers and analysts inside the team.
[03]

Speaking

Eleven stages across three continents. Every listing links to the conference's own record.

2025DEF CON 33, Las Vegas“Context Aware Anomaly Detection in Automotive CAN Without Decoding” — Creator Stage, plus a hands-on Creator Workshop. talk · schedule · workshop
2025c0c0n, KochiTelecom Village. village page
2025CSAxCONSpeaker — automotive security. profile
2024HITBSecConf, Bangkok“Exploiting the In-Vehicle Browser: A Novel Attack Vector in Autonomous Vehicles”. profile
2024BSides Mumbai“V2X Exploitation: Steering Through Auto Cyber Seas”.
2023BlackHat Asia, SingaporeArsenal — “Introducing the Operating System for Automotive Security Testing”. listing
2023HITCON, TaipeiSpeaker. agenda
2023NULLCON, Goa“ARM-ing for Android: Unraveling the Mysteries of Native Library Reverse Engineering”. talk page
2023BSides IndoreSpeaker.
2020BSides MaharashtraSpeaker. recording
2019Bounty Bash, NepalSpeaker.
[04]

Watch the talks

Recordings from conference stages and the AutoSec Pro webinar series.

defcon-33_can-anomaly-detection.mp4
DEF CON 33 — Context Aware Anomaly Detection in Automotive CAN Without Decoding (official DEF CON channel)
hitb-2024_in-vehicle-browser.mp4
HITB 2024 Bangkok — Exploiting the In-Vehicle Browser: A Novel Attack Vector in Autonomous Vehicles
bsides-mumbai_v2x-exploitation.mp4
BSides Mumbai 2024 — V2X Exploitation: Steering Through Auto Cyber Seas
blackhat-asia-23_autohackos.mp4
BlackHat Asia 2023 Arsenal — AutoHackOS release
autosec-pro_course-webinar.mp4
AutoSec Pro course webinar — vehicle cybersecurity with the creator
bsides-maharashtra_talk.mp4
BSides Maharashtra — talk recording (embedding disabled by the channel, opens on YouTube)
[05]

Expertise

Three fronts, one discipline — every module below is backed by an entry in ./work ./leadership.

building_ai_for_security

  • Agentic systems — AutoGen, MCP, multi-agent orchestration
  • Multi-LLM adversarial reasoning — Claude, Gemini, Azure OpenAI
  • AI cost engineering — severity-tiered routing, 30× per-alert differential
  • SOC modernisation — CrowdStrike Falcon, Sentinel, Splunk
  • Cloud security architecture — Azure AKS deep, AWS and GCP design-level

securing_ai

  • AI threat modeling — MITRE ATLAS, OWASP Top 10 for LLM Apps
  • AI red teaming — prompt injection, jailbreaks, tool abuse, RAG poisoning; PyRIT, Garak, and my own LLM-PT suite
  • ML supply-chain security — model-file scanning, backdoored weights
  • AI governance — NIST AI RMF, ISO 42001, data provenance
  • IAM for autonomous agents — least privilege, excessive-agency control

offensive_security

  • Automotive — CAN, ECU, infotainment, Android Automotive; ISO/SAE 21434, TARA
  • OT and ICS — Modbus, SCADA, plant-floor assessment; IEC 62443
  • Hardware and firmware — fuzzing, SDR/RF, BLE, reverse engineering
  • Red and purple team — web, cloud, Windows exploitation
  • 0-day research — browser, mobile, and cloud-side findings in production systems
[06]

git log --career

2025 — now · xbp-global
Manager, Cyber Security — XBP Global (formerly SourceHOV)
Xalon, AI red teaming, a cross-functional team of 11–20.
2025 · independent
Subject-Matter Expert (contract) — hardware security & applied AI
R&D lead for an AI-enabled automated hardware pentesting device; delivered the working MVP.
2023 — 2025 · sourcehov
Information Security Manager — SourceHOV
SecAI; SOC and Red Team redesign — 40% faster incident response across 20+ clients.
2022 — 2023 · bluebinaries
Lead Engineer, Automotive Security — BlueBinaries
Built the practice; ISO/SAE 21434 programmes for OEM and Tier-1 clients.
2022 · amynasec
Lead Security Researcher — AmynaSec Research Lab
The VinFast research; OT extension into Modbus and ICS/SCADA.
2019 — 2021 · 8bit-digital
Senior Security Researcher — 8 Bit Digital
Protocol and firmware fuzzing; AppSec automation — 40% faster cycles.
2015 — 2019 · innovador
Penetration Tester — Innovador Infotech
Web, Android, wireless/RF; 30+ critical findings; Windows user-mode exploits.
[07]

Teaching and community

AutoSec Pro — Vehicle Cybersecurity Mastery (W52), a full course on Pentest Magazine covering vehicle pentesting end to end. enroll on Pentest Magazine

Co-organiser of the DEF CON US Telecom Village since 2023, and of the Telecom Village at c0c0n 2025. Chapter lead of NULL Ahmedabad, 2017–2020 — three years of free monthly security training for the community.

[08]

Contact

$ ./hire --role security-leadership --mode remote-or-global
If your security operation needs someone who builds and breaks — talk to me.