Sagar Kishore
Kumar
Cybersecurity engineer with 3 years across threat intelligence, detection engineering, and security automation at production scale — building AI-assisted pipelines that have processed environments handling up to 4 billion emails a week.
Threat intel meets detection engineering.
Cybersecurity engineer with 3 years of experience across threat intelligence, detection engineering, and security automation at production scale.
Skilled in OSINT and MITRE ATT&CK-driven CTI, SIEM-based threat hunting and incident triage (Elasticsearch/OpenSearch), and cloud security risk assessment (STRIDE, NIST SP 800-30, ISO 27005).
Builds automated, AI-assisted security pipelines in Python across environments handling up to 4 billion emails/week.
Tools of the trade.
Six modules covering the full lifecycle — from cloud risk modeling to AI-assisted detection.
Cloud Security & GRC
GCP security architecture, IAM, Workload Identity Federation, IAP, secrets management, STRIDE threat modeling, NIST SP 800-30 / ISO 27005 risk assessment, CI/CD & supply-chain security, SLSA provenance.
SIEM & Detection Engineering
Elasticsearch / OpenSearch / Kibana dashboards, alerting & rule tuning, threat hunting, incident triage, log & telemetry analysis, detections-as-code, playbook authoring, Prometheus, Grafana.
Threat Intelligence & CTI
OSINT collection & enrichment, MITRE ATT&CK mapping (TTPs, tactic heatmaps), IOC analysis (IP, domain, hash, CVE), threat actor attribution, ransomware tracking, Cyber Kill Chain.
AI & LLM Security
LLM-driven classification & clustering, prompt injection testing (OWASP LLM Top 10), RAG pipelines, NER (BERT, GLiNER), grammar-constrained extraction (GBNF), AI-assisted triage.
Automation & Development
Python (FastAPI, Flask, pandas, asyncio, TensorFlow), API integrations, event-driven automation, Bash, SQLite, Postgres, Docker, Git, CI/CD (GitHub Actions, SARIF).
Tooling & Networking
Burp Suite, Nmap, OWASP ZAP, Wireshark, nuclei, subfinder, httpx; TCP/IP, DNS, TLS, Firewalls, IDS/IPS, Linux.
Professional experience.
Cyber Threat Intelligence Researcher (Master's Thesis)
- Built a fully automated 16-source OSINT ingestion pipeline (Ransomware.live, CISA, international CERTs) accumulating 4,231 incidents across 53 countries, with fuzzy deduplication and incremental source-state tracking.
- Automated MITRE ATT&CK mapping via semantic RAG (697 techniques embedded, top-5 candidates per article), yielding 512 technique observations across 14 tactics with no manual tagging.
- Designed a 105-field grammar-constrained LLM extraction schema (GBNF) with GLiNER NER pre-pass and Pydantic-validated self-correction; 67% enrichment coverage across 2,847 incidents.
- Built a 14-table intelligence database with an 8-type IOC schema and ~50 FastAPI endpoints powering an interactive dashboard with tactic heatmaps and sector-targeting matrices.
Email Security Analyst, NGSF Team
- Built and maintained LLM-driven classification pipelines for spam and phishing detection processing ~350K emails/day on infrastructure handling ~4 billion emails/week.
- Performed large-scale threat hunting and telemetry analysis in Elasticsearch/OpenSearch; built Python automation for threat enrichment, incident triage, and operational response.
- Engineered a brand-impersonation detection system combining ML models, embeddings (RETVec), and BERT-based NER via OpenSearch pipelines across IONOS, GMX, and WEB.DE user bases.
- Contributed to detections-as-code: automated rule deployment, version-controlled alerting logic, and structured telemetry pipelines across email security infrastructure.
Test Development Engineer
- Built automated test and data-validation frameworks for enterprise cloud applications (.NET/MSSQL), cutting manual QA cycles by 25% and surfacing data-integrity anomalies for triage.
- Documented technical findings and reproduced edge-case failures for cross-functional teams, reducing defect investigation turnaround.
Selected work.
Case studies and open-source tools spanning cloud risk, threat intelligence, and AI security testing.
EduThreat-CTI
End-to-end automated OSINT threat-intelligence platform for the education sector.
- 15-source ingestion distilling 124,676 raw observations into 2,967 verified incidents across 91 countries (2000–2026).
- 132-field CTI schema via Qwen3-Coder (480B) + GLiNER NER; 91% accuracy on ransomware-vs-rest classification.
- Identified ransomware as the dominant threat (~40% of incidents, peaking at 52% in 2025); MOVEit breach cascaded to 93 institutions.
- Threat knowledge graph linking 213 threat actors, CVEs, and vendors to surface coordinated campaigns.
LLMMap
Prompt injection testing framework — dual-LLM attack-and-judge architecture.
- Covers 227 prompt injection techniques across 18 attack families.
- SARIF v2.1.0 export for CI/CD security integration.
- Ships with PromptLab — an OWASP LLM Top 10 classification lab with vulnerable/defended simulation across Ollama, OpenAI, Anthropic, and Google backends.
WRX — Web Recon eXecutive
Security automation orchestrator unifying the recon & scanning stack.
- Unifies subfinder, httpx, katana, ffuf, nuclei, and OWASP ZAP into one pipeline.
- Async job monitoring, run diffing, and export connectors for SARIF, GitHub, and Jira.
- Aligned with detections-as-code workflows for continuous recon.
Cloud Migration Security Assessment
Self-directed case study — securing a GitLab-to-GCP migration.
- STRIDE threat modeling and NIST SP 800-30 / ISO 27005 rating across 18 risk scenarios on a 5×5 likelihood-impact matrix.
- Identified critical risks (access-token & long-lived service-account key exposure); remediated via Workload Identity Federation.
- Produced a five-layer reference architecture with IAP, FIDO2 MFA, SLSA provenance, and ATT&CK-mapped detections.
Outside of security work.
Products in progress at Matrix Social Labs — a startup studio I run alongside the security work above.
Blendn
Where events meet serendipity — discover events in your city and connect with people around you, live and anonymously. No catfish, no cringey bios, just vibes.
Safera
A place-based women safety map for Indian cities — anonymous reporting, safer routes, and city watch pages. Map-first, not form-first, no accounts required.
Prism
Role-aware AI news intelligence — the same story read through your professional lens, every side of the narrative, and a grounded agent you can ask.
Pulled straight from the source.
This grid calls the GitHub API in your browser right now — no cached screenshots.
Let's secure something together.
Open to conversations on threat intelligence, detection engineering, and cloud security. Based in Saarbrücken, Germany — reachable anywhere.