Skip to main content
HA
Open to opportunities

Himanshu Alghare

@himanshualghare

OSCP-certified offensive security consultant specializing in VAPT and red team operations.

India
Message

What I'm looking for

I want to work on offensive security engagements—VAPT and red teaming—where I can emulate real adversary TTPs, test Active Directory and web/API systems, and deliver risk-tiered remediation guidance mapped to MITRE ATT&CK.

I’m an OSCP-certified offensive security consultant with 3.6+ years of experience delivering VAPT, penetration testing, and red team engagements for enterprise environments. I focus on finding exploitable real-world misconfigurations across networks, web, APIs, mobile (Android), wireless, and Active Directory.

In my work at EY and Redfox Cyber Security, I’ve executed end-to-end offensive testing, from reconnaissance and exploitation to reporting with clear, actionable remediation guidance. I’ve specifically targeted Active Directory weaknesses such as Kerberoasting, AS-REP Roasting, pass-the-hash/ticket, DCSync, and ACL/GPO abuse, and I’ve supported phishing simulation exercises as part of social engineering assessments.

I bring a practical, adversary-focused mindset—covering TTP-based attack emulation, C2 operations, purple-team validation, and post-exploitation outcomes like lateral movement, persistence, credential harvesting, pivoting, and data exfiltration. I also develop automation and use tools like Burp Suite, Metasploit, Cobalt Strike, BloodHound/SharpHound, and Impacket to streamline workflows while mapping findings to frameworks like MITRE ATT&CK and OWASP.

Experience

Work history, roles, and key accomplishments

Ernst & Young logoEY
Current

Offensive Security Consultant

May 2023 - Present (3 years 2 months)

Conducted VAPT engagements across internal/external networks, web applications, APIs, and SAP for enterprise clients. Exploited Active Directory misconfigurations (e.g., Kerberoasting and GenericWrite abuse) for privilege escalation and supported red team activities and phishing simulations, delivering client-facing remediation guidance.

RS

Associate Security Consultant

Redfox Cyber Security

Feb 2023 - May 2023 (3 months)

Executed penetration tests across network infrastructure and web application layers, documenting exploitation chains and risk ratings. Performed Active Directory enumeration and exploitation to achieve privilege escalation, validated controls during red team simulations, and delivered remediation recommendations mapped to MITRE ATT&CK and security standards.

Education

Degrees, certifications, and relevant coursework

SU

SAGE University

Bachelor of Technology, Cyber Security & Forensic Engineering

2018 - 2022

Grade: 8.3/10

Earned a B.Tech in Cyber Security & Forensic Engineering from SAGE University (Indore), graduating in 2022 with a CGPA of 8.3/10.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan