Hardikkumar Patel
@hardikkumarpatel
Security Engineer with experience in VAPT, GRC, enterprise security engineering, and AI security. Building security programs from the ground up.
What I'm looking for
I am a Security Engineer with hands-on experience across offensive security, enterprise security engineering, Governance, Risk & Compliance (GRC), and AI security. My career has progressed from application security and VAPT into broader enterprise security, governance, and secure AI initiatives.
I began in VAPT, performing black-box and gray-box web application security assessments, API testing, reconnaissance, and vulnerability validation. I identified critical application security issues including IDORs, directory traversal, XSS, vulnerable third-party libraries, concurrent session vulnerabilities, and exposed sensitive resources, using Burp Suite and other security testing tools. I produced detailed findings with risk context, CVE/CWE references, and remediation recommendations.
At Sigmoid, I gained experience across GRC and enterprise security engineering, including ISO/IEC 27001 control assessments, asset and security hygiene, policy reviews, incident response, vulnerability assessment, and Third-Party Risk Management (TPRM). I contributed to 30+ client TPRM questionnaires under senior guidance and collaborated with cross-functional teams to establish IAM governance across 9+ SaaS and cloud platforms.
In my current role, I have been involved in building and formalizing security capabilities, giving me hands-on exposure to implementing security processes rather than only operating within an established program. My work spans security governance, security infrastructure, third-party risk, AI governance, incident investigation, and security automation.
A key focus has been applying AI to practical security problems. I designed and developed an internal RAG application using LangChain, LangGraph, and Ollama that indexed 50+ organizational security policies to streamline repetitive client TPRM questionnaire responses. I also incorporated security controls and evaluation using Promptfoo, NVIDIA NeMo Guardrails, and Garak to address risks such as prompt injection, hallucination, and unsafe LLM behavior.
I have also contributed to enterprise AI governance by evaluating Generative AI applications, identifying Shadow AI risks, defining approved AI usage, and developing secure AI usage guidelines and guardrails.
My technical interests include Product Security, Security Engineering, Application Security, AI/LLM Security, AI Safety, AI Red Teaming, Security Automation, GRC, Cloud Security, and secure AI systems.
I am particularly interested in product-focused organizations where I can solve meaningful security problems, work closely with engineering teams, build security capabilities from the ground up, and grow at the intersection of cybersecurity and AI.
Experience
Work history, roles, and key accomplishments
Information Security Engineer
Sigmoid Analytics
Oct 2025 - Present (10 months)
Helped establish enterprise security capabilities from the ground up across Google Workspace, endpoint security, SSE, firewall, and security infrastructure. Implemented security baselines aligned with CIS Benchmarks and supported ISO 27001/SOC 2 compliance readiness. Built security automation using LangChain/LangGraph and 50+ policies to streamline TPRM workflows.
InfoSec Intern
Sigmoid Analytics
Apr 2025 - Sep 2025 (5 months)
Supported enterprise security and GRC initiatives including ISO 27001 control assessments, security policy reviews, asset and patch management, endpoint protection, and physical security. Contributed to 30+ client TPRM questionnaires under senior guidance and supported incident response, RCA, and public-facing application security assessments.
Security Engineer Intern
Secure Loopholes
Jan 2025 - Mar 2025 (2 months)
Performed web application VAPT across client environments using Burp Suite and Kali Linux, identifying critical vulnerabilities including IDORs, directory traversal, XSS, exposed sensitive resources, and vulnerable components. Validated findings against OWASP Top 10 and delivered risk-based reports with CVE/CWE mapping and remediation guidance.
Education
Degrees, certifications, and relevant coursework
GSFC University
Bachelor of Technology, Computer Science Engineering (Cyber Security)
2021 - 2025
Grade: 7.51/10
Activities and societies: Data Structures & Algorithms, Python Programming, Application Security, Network Security, Web Security, Digital Forensics, Machine Learning Fundamentals.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Social media
Job categories
Skills
Interested in hiring Hardikkumar?
You can contact Hardikkumar and 90k+ other talented remote workers on Himalayas.
Message HardikkumarGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
