Nimal Kurien Thomas
security & engineering

I work across the stack — securing infrastructure, hunting threats, breaking applications, and building intelligent systems.

Based in College Park, MD. Open to relocation and remote.

OffSec Certified Professional+ (OSCP+) OSCP+ OffSec Certified Professional (OSCP) OSCP HTB Certified Offensive AI Expert (HTB COAE) HTB COAE AWS Certified Solutions Architect – Associate AWS SAA CompTIA Security+ ce Certification Security+

Experience

Role title Organisation

A line or two on scope and what you were responsible for.

Role title Organisation

A line or two on scope and what you were responsible for.

Education

Degree University

Focus area, thesis, or relevant coursework.

Degree University

Focus area, thesis, or relevant coursework.

Work

Cloud & Cloud Security

Securing cloud-native environments — IAM, posture management, and runtime defence.

Projects for this area are on the way.
  • AWS (primary)
  • GCP
  • Kubernetes / EKS
  • Terraform / Pulumi
  • Cloudflare
  • IAM & least-privilege
  • CSPM & posture management
  • Cloud workload protection
  • Serverless security
  • CIS benchmarks / SOC2

DevOps / DevSecOps

Shifting security left — baking it into pipelines, containers, and delivery workflows.

Projects for this area are on the way.
  • Semgrep / SonarQube
  • Trivy / Grype
  • Checkov / Terrascan
  • Falco
  • Vault (HashiCorp)
  • Threat modeling
  • Supply chain security (SLSA)
  • Policy-as-code (OPA)
  • SBOM generation
  • Secure IaC (Terraform)

Pentesting

Offensive security — finding the holes before the adversary does.

Projects for this area are on the way.
  • Burp Suite
  • Metasploit
  • Nmap / Masscan
  • BloodHound / SharpHound
  • Impacket
  • Web app pentesting
  • Active Directory attacks
  • Network enumeration
  • Privilege escalation
  • Report writing

ML / AI

Applying machine learning to security problems and building intelligent systems.

Projects for this area are on the way.
  • Python / PyTorch / scikit-learn
  • HuggingFace Transformers
  • LangChain / LlamaIndex
  • FastAPI
  • MLflow
  • Security-focused ML
  • LLM red-teaming
  • Anomaly & intrusion detection
  • NLP for threat intel
  • Adversarial ML

API Security

Designing, securing, and stress-testing APIs — from spec to production.

Projects for this area are on the way.
  • Burp Suite (API testing)
  • Postman / Insomnia
  • OpenAPI / Swagger
  • GraphQL
  • gRPC / Protobuf
  • OWASP API Top 10
  • Auth patterns (OAuth2, JWT)
  • Rate limiting & abuse prevention
  • API fuzzing & testing
  • REST & async API design

Binary Exploitation

Memory corruption, reverse engineering, and turning crashes into control.

Projects for this area are on the way.
  • GDB / pwndbg
  • pwntools
  • Ghidra / IDA
  • radare2
  • AFL++ / libFuzzer
  • Stack & heap overflows
  • Return-oriented programming
  • Format string bugs
  • ASLR / NX / canary bypass
  • Shellcode development

DFIR

Digital forensics and incident response — finding what happened, how, and when.

Projects for this area are on the way.
  • Autopsy / FTK
  • Volatility 3
  • Velociraptor
  • Elastic / Splunk
  • Wireshark / Zeek
  • Windows forensics (MFT, registry)
  • Memory analysis
  • Malware triage
  • Network traffic analysis
  • Chain of custody