Anubhav Gain
Security Software Engineer | Rust & Go Developer | DevSecOps
Raipur, Chhattisgarh, India
SUMMARY
Security Software Engineer with 2+ years building production security platforms in Rust, Go, and .NET — EDR/XDR, SIEM, WDAC application control, ASPM, and AI-driven security automation (LLM orchestration over MCP). Deliver security engineering for finance-sector and fintech clients. Certified across OPSWAT, AWS, Anthropic, Google, IBM, and Linux Foundation.
EDUCATION
Parul University, Vadodara
2021 – 2025 | B.Tech, Cyber/Computer Forensics & Counterterrorism | GPA 3.9
Charles Sturt University
2023 | Licentiate — Cybersecurity Management (High Distinction, 93/100) & Ransomware Techniques
SKILLS
Languages: Rust, Go, C/C++, C#/.NET, Python, TypeScript, Swift, Bash
Security: EDR/XDR, SIEM, Malware Analysis, Reverse Engineering (IDA Pro, Ghidra, Binary Ninja), PE/ELF/Mach-O parsing, WDAC application control, VAPT, threat detection, eBPF, Zero Trust
Cloud & DevOps: AWS, Azure, Docker, Kubernetes, Terraform, Helm, CI/CD (Jenkins, GitHub Actions)
Data & Infra: PostgreSQL, Redis, ClickHouse, NATS, RabbitMQ, OpenSearch/Wazuh/Kibana/ELK, pgvector, OpenTelemetry
Frameworks & AI: Next.js, React, Axum, Tokio, SignalR, LLM orchestration (MCP), AWS Bedrock
Compliance: ISO 27001, NIST, PCI-DSS
OPEN SOURCE
github.com/mranv · github.com/anubhavg-icpl
Security & EDR: ebpf-file-monitor (Rust · 14★), ETWConsoleApp (EDR telemetry, .NET 10), yara-edr (Linux), slm-l (SLM code auditor), file-parse (PE/ELF parser), active-response (Windows hardening)
Kernel & Drivers: app-control (WDM allow/deny driver, C++/Rust), leviathan (Windows driver samples · 2★)
Platforms & Infra: krustron (open-source Devtron alternative, Go), osdls (Wazuh + OpenSearch stack · 4★), rust-cert-authority (auto CA)
AI & Tooling: vibe (AI agent collection, Python · 5★), agni (Firecracker microVM UI, Go)
EXPERIENCE
Security Software Engineer & Security Consultant
Jul 2024 – Present | Infopercept Consulting
- › Architect Invinsense XDR/OXDR deployment (single- & multi-tenant): custom OpenSearch dashboard plugins, cross-platform monitoring agents in Rust, Docker-based Wazuh/OpenSearch/Kibana environments, Fluent Bit pipelines, and CI/CD security testing
- › UEC Consultant · Fintech Client (May 2026 – Present): build Invinsense 7.0 Unified Endpoint Control — application whitelisting, policy create/review/approve/deploy workflows, and endpoint telemetry across Windows, macOS, and Linux
- › Application Security Consultant · Finance Sector (Mar – May 2026): led AppSec assessments and VAPT across the software ecosystem, advising teams on remediation and secure coding aligned to financial-industry standards
DevSecOps Engineer
Nov 2023 – Jul 2024 | Atcults
- › Built Python/PowerShell automation for vulnerability scanning and remediation across 8 CI/CD pipelines
- › Provisioned AWS with Terraform (12+ Kubernetes clusters) and set up ELK-stack monitoring with automated response playbooks
Founder & Security Researcher
Dec 2022 – Present | TechAnv Consulting (R&D)
- › Founded an independent R&D firm; reverse-engineered 50+ malware samples (IDA Pro, Ghidra, Binary Ninja) and shipped open-source Rust/Python security tools — PE/ELF parsers, scanners, EDR prototypes, and the honeypot.rs framework
IT Security Specialist
Nov 2022 – Oct 2023 | Parul University
- › Managed 8+ Palo Alto firewalls for 5,000+ users with zero-trust policies; administered Red Hat Linux, Windows, and AWS under ISO 27001 and NIST compliance
PROJECTS
- › Talon — AI-driven penetration-testing platform: 5-binary Go system automating recon → exploit → post-exploit with an LLM codegen fallback and second-model verifier; Metasploit and nmap/nuclei over MCP; Next.js 16 console. (Go, Next.js, MCP, Bedrock)
- › Patra Sanchalak (Invinsense) — Multi-tenant email-dispatch microservice in Rust on NATS JetStream: multi-provider delivery (SMTP/SES/SendGrid) with failover, a 27-endpoint Axum API, and OpenTelemetry. (Rust, Tokio, Axum, NATS)
- › Techanv Warden — Self-hosted ASPM platform (~63k LOC) unifying 27 scanners (Semgrep, CodeQL, Trivy) into deduplicated findings with SLA/RBAC, pgvector semantic search, an MCP server, and Helm/K8s deployment. (.NET 10, Next.js, pgvector)
CERTIFICATIONS
80+ verified badges · credly.com/users/anubhavgain
- › OPSWAT (13): Ethical Hacking (OEHE), WebApp Exploitation (OWEE), Password Cracking (OPCE), OSINT (OCOE); Network / Endpoint / File Security; Schneider & Siemens PLC (ICS/OT)
- › CISM (Cybrary) · AWS Solutions Architect · Google Cybersecurity · IBM Cybersecurity Analyst · Cisco (Threat Mgmt, Endpoint, Network Defense) · Linux Foundation 15+ (Rust, GitOps, OpenSSF, SBOM)
- › Anthropic / Claude: Claude API, MCP (Intro + Advanced), Claude Code, Agent Skills & Subagents, AI Fluency · AI/GenAI: Agentic AI (LangGraph, CrewAI, AutoGen), RAG · API Security (OWASP API Top 10, PCI)