Skip to main content
Hardikkumar PatelHP
Looking for a job

Hardikkumar Patel

@hardikkumarpatel

Security Engineer with experience in VAPT, GRC, enterprise security engineering, and AI security. Building security programs from the ground up.

India
Message

What I'm looking for

I'm looking to build secure, scalable AI systems through security engineering, automation, offensive security, and AI safety.

I am a Security Engineer with hands-on experience across offensive security, enterprise security engineering, Governance, Risk & Compliance (GRC), and AI security. My career has progressed from application security and VAPT into broader enterprise security, governance, and secure AI initiatives.

I began in VAPT, performing black-box and gray-box web application security assessments, API testing, reconnaissance, and vulnerability validation. I identified critical application security issues including IDORs, directory traversal, XSS, vulnerable third-party libraries, concurrent session vulnerabilities, and exposed sensitive resources, using Burp Suite and other security testing tools. I produced detailed findings with risk context, CVE/CWE references, and remediation recommendations.

At Sigmoid, I gained experience across GRC and enterprise security engineering, including ISO/IEC 27001 control assessments, asset and security hygiene, policy reviews, incident response, vulnerability assessment, and Third-Party Risk Management (TPRM). I contributed to 30+ client TPRM questionnaires under senior guidance and collaborated with cross-functional teams to establish IAM governance across 9+ SaaS and cloud platforms.

In my current role, I have been involved in building and formalizing security capabilities, giving me hands-on exposure to implementing security processes rather than only operating within an established program. My work spans security governance, security infrastructure, third-party risk, AI governance, incident investigation, and security automation.

A key focus has been applying AI to practical security problems. I designed and developed an internal RAG application using LangChain, LangGraph, and Ollama that indexed 50+ organizational security policies to streamline repetitive client TPRM questionnaire responses. I also incorporated security controls and evaluation using Promptfoo, NVIDIA NeMo Guardrails, and Garak to address risks such as prompt injection, hallucination, and unsafe LLM behavior.

I have also contributed to enterprise AI governance by evaluating Generative AI applications, identifying Shadow AI risks, defining approved AI usage, and developing secure AI usage guidelines and guardrails.

My technical interests include Product Security, Security Engineering, Application Security, AI/LLM Security, AI Safety, AI Red Teaming, Security Automation, GRC, Cloud Security, and secure AI systems.

I am particularly interested in product-focused organizations where I can solve meaningful security problems, work closely with engineering teams, build security capabilities from the ground up, and grow at the intersection of cybersecurity and AI.

Experience

Work history, roles, and key accomplishments

SA
Current

Information Security Engineer

Sigmoid Analytics

Oct 2025 - Present (10 months)

Helped establish enterprise security capabilities from the ground up across Google Workspace, endpoint security, SSE, firewall, and security infrastructure. Implemented security baselines aligned with CIS Benchmarks and supported ISO 27001/SOC 2 compliance readiness. Built security automation using LangChain/LangGraph and 50+ policies to streamline TPRM workflows.

Sigmoid Analytics logoSA

InfoSec Intern

Sigmoid Analytics

Apr 2025 - Sep 2025 (5 months)

Supported enterprise security and GRC initiatives including ISO 27001 control assessments, security policy reviews, asset and patch management, endpoint protection, and physical security. Contributed to 30+ client TPRM questionnaires under senior guidance and supported incident response, RCA, and public-facing application security assessments.

Secure Loopholes logoSL

Security Engineer Intern

Secure Loopholes

Jan 2025 - Mar 2025 (2 months)

Performed web application VAPT across client environments using Burp Suite and Kali Linux, identifying critical vulnerabilities including IDORs, directory traversal, XSS, exposed sensitive resources, and vulnerable components. Validated findings against OWASP Top 10 and delivered risk-based reports with CVE/CWE mapping and remediation guidance.

Education

Degrees, certifications, and relevant coursework

GSFC University logoGU

GSFC University

Bachelor of Technology, Computer Science Engineering (Cyber Security)

2021 - 2025

Grade: 7.51/10

Activities and societies: Data Structures & Algorithms, Python Programming, Application Security, Network Security, Web Security, Digital Forensics, Machine Learning Fundamentals.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan