🏠 Go to Home
πŸ‘€ Go to About
πŸ’Ό Go to Experience
πŸ“ Go to Projects
πŸ› οΈ Go to Skills
πŸ“œ Go to Certifications
πŸ“§ Go to Contact
πŸŒ“ Toggle Theme
🎨 Accent: Blue
🎨 Accent: Cyan
🎨 Accent: Purple
🎨 Accent: Green
🎨 Accent: Red
πŸ” Live Threat Assessment

I find what's broken
before someone else does.

B.Tech in Cybersecurity. Hands-on VAPT across web apps, Linux, and enterprise networks. I build full-stack apps β€” so I know where the vulnerabilities hide.

20+SYSTEMS TESTED
5+THREAT MODELS
9.7CGPA Β· B.TECH IT
3YEARS HANDS-ON
root@nandalal:~ $
➜Initializing security scan…
➜Target: Nandalal Patil (Cybersecurity Analyst)
➜
Burp SuiteNessusOWASP ZAPNmapWireshark MetasploitKali LinuxAzureIriusRiskMS Threat Modeling Tool ReactNode.jsPythonMongoDBDocker Burp SuiteNessusOWASP ZAPNmapWireshark MetasploitKali LinuxAzureIriusRiskMS Threat Modeling Tool ReactNode.jsPythonMongoDBDocker
About

From fixing computers to breaking them on purpose.

I didn't start out chasing cybersecurity β€” I started out fixing other people's computers. Two years in IT support taught me how systems actually break in practice: bad configurations, weak passwords, forgotten patches, a user who clicks the wrong link. That ground-level view stuck with me.

From there I moved into full-stack development, building applications with the MERN stack, and started noticing how much of what I was learning in security classes showed up in the code I was writing β€” and in code I wasn't writing carefully enough.

That's what pulled me fully into security. I've since tested real web applications and networks for vulnerabilities, built STRIDE threat models for healthcare and IoT systems, and built WAFGuard, a web application firewall that pairs rule-based detection with a machine learning model β€” because I wanted to understand both sides of the fight.

I completed my internship at eInfochips (An Arrow Company) in August 2026, working across VAPT, threat modeling, and secure SDLC. I've since joined Knights Eye LLP as a Junior System Engineer, where I support systems administration and infrastructure security while continuing to build toward a full-time role in offensive security.

Experience

Seven roles, one direction.

Each step added a layer β€” infrastructure, then code, then how to break both on purpose.

Junior System Engineer β€” Knights Eye LLP
SEP 2026 β€” PRESENT Β· REMOTE
  • Administering and hardening Windows/Linux systems and network infrastructure, applying secure-configuration and least-privilege principles learned through VAPT work.
  • Monitoring systems for vulnerabilities and anomalies, and supporting patch management and access-control reviews.
  • Bridging systems engineering with a security-first mindset β€” documenting configurations and flagging risks before they become incidents.
Systems AdministrationLinuxWindowsSecurity Hardening
Cybersecurity Intern β€” eInfochips (An Arrow Company)
JAN 2026 β€” AUG 2026 Β· AHMEDABAD
  • Tested 20+ web applications, Linux systems, and enterprise networks with Burp Suite, Nessus, Nmap, Wireshark, and Metasploit.
  • Built STRIDE-based threat models for 5+ healthcare and IoT systems using Microsoft Threat Modeling Tool and IriusRisk.
  • Folded threat modeling and security testing into Secure SDLC instead of bolting it on at the end.
VAPTSTRIDESecure SDLCAzure
Software Engineer Intern β€” Bluestock
MAY β€” JUN 2025 Β· REMOTE
  • Built and shipped React.js features backed by Node.js and MongoDB.
  • Worked across the stack β€” REST APIs, database logic, reusable components β€” which sharpened how I think about where application vulnerabilities actually originate.
ReactNode.jsMongoDB
Cybersecurity Intern β€” Hacktify
FEB β€” MAR 2025 Β· REMOTE
  • Manually tested web applications for SQL injection, XSS, and authentication weaknesses.
  • Ran network reconnaissance with Nmap to map attack surfaces ahead of deeper testing.
SQLiXSSNmap
Technical Team Member β€” CyberSecurity Club, SCET
JUL 2024 β€” PRESENT Β· SURAT
  • Ran workshops and hands-on sessions on ethical hacking and networking for other students.
  • Organized security-awareness events for the college community.
CommunityTeaching
Full-Stack Developer β€” Webstack Academy
JUL β€” AUG 2024 Β· BENGALURU
  • Built end-to-end MERN applications, from database schema to UI.
MERN
IT Support Specialist β€” Proskill Engineering
JAN 2023 β€” MAY 2024 Β· VADODARA
  • Configured and secured 20+ Windows/Linux workstations and resolved day-to-day infrastructure issues β€” the practical starting point for everything that came after.
LinuxWindowsNetworking
Projects

Built to be attacked. On purpose.

Each one exists to answer a specific security question, not to fill a portfolio slot.

WAFGuard

Problem
Signature-based firewalls only catch known attacks.
Approach
Reverse-proxy with rule-based filtering + LightGBM model to catch novel SQLi, XSS, and OWASP Top 10 attacks.
PythonLightGBMReverse ProxyOWASP

Convomate

Problem
Real-time chat apps are prime targets for broken auth and injections.
Approach
JWT, MFA, encrypted communication, RBAC enforcing least privilege β€” hardened against OWASP Top 10.
MERNJWTRBACMFA

Healthcare & IoT Threat Models

Problem
Connected medical devices expand the attack surface beyond IT security.
Approach
STRIDE-based models for 5+ systems using MS Threat Modeling Tool and IriusRisk.
Note
Internal engagement β€” details available on request.
STRIDEIriusRiskIoT Security
Skills

Grouped by what they're for, not alphabetized.

Security

VAPTThreat Modeling (STRIDE)Secure SDLCRisk AssessmentOWASP Top 10Application Security

Networking

TCP/IPNetwork ReconFirewallsSegmentationWireshark

Cloud & Systems

Microsoft AzureLinux (RHEL SA1/SA2)Kali LinuxWindows

Tools

Burp SuiteNessusOWASP ZAPNmapMetasploitIriusRisk

Development

React.jsNode.jsExpress.jsMongoDBPythonJavaScriptSQL

Working Style

Analytical ThinkingClear DocumentationTime ManagementContinuous Learning
Certifications

Formal training behind the hands-on work.

Google Cybersecurity Professional Certificate

Completed

CompTIA Security+

Training completed

CompTIA Network+

Training completed

Certified Ethical Hacker (CEH)

In progress

RHEL Administration β€” SA1 & SA2

Completed
Contact

Let's talk about your team.

I'm currently a Junior System Engineer at Knights Eye LLP, and open to Cybersecurity Analyst, Security Engineer, Application Security Engineer, or VAPT Analyst roles. If your team is hiring, I'd like to hear about it.