[OK] establishing secure channel...
[OK] loading threat intelligence modules...
[OK] mounting portfolio://sagar-kishore-kumar
ACCESS 0%
SYSTEM ONLINE // SAARBRÜCKEN, GERMANY

Sagar Kishore
Kumar

Cybersecurity engineer with 3 years across threat intelligence, detection engineering, and security automation at production scale — building AI-assisted pipelines that have processed environments handling up to 4 billion emails a week.

SCROLL
01 // whoami

Threat intel meets detection engineering.

about.sh

Cybersecurity engineer with 3 years of experience across threat intelligence, detection engineering, and security automation at production scale.

Skilled in OSINT and MITRE ATT&CK-driven CTI, SIEM-based threat hunting and incident triage (Elasticsearch/OpenSearch), and cloud security risk assessment (STRIDE, NIST SP 800-30, ISO 27005).

Builds automated, AI-assisted security pipelines in Python across environments handling up to 4 billion emails/week.

English (C1) German (A2) M.Sc. Cybersecurity — Universität des Saarlandes
0+
YEARS EXPERIENCE
0B/wk
EMAILS SECURED
0
OSINT SOURCES AUTOMATED
0
INCIDENTS INGESTED
0
COUNTRIES COVERED
0
PROMPT-INJECTION TTPS
02 // technical arsenal

Tools of the trade.

Six modules covering the full lifecycle — from cloud risk modeling to AI-assisted detection.

MODULE_01

Cloud Security & GRC

GCP security architecture, IAM, Workload Identity Federation, IAP, secrets management, STRIDE threat modeling, NIST SP 800-30 / ISO 27005 risk assessment, CI/CD & supply-chain security, SLSA provenance.

MODULE_02

SIEM & Detection Engineering

Elasticsearch / OpenSearch / Kibana dashboards, alerting & rule tuning, threat hunting, incident triage, log & telemetry analysis, detections-as-code, playbook authoring, Prometheus, Grafana.

MODULE_03

Threat Intelligence & CTI

OSINT collection & enrichment, MITRE ATT&CK mapping (TTPs, tactic heatmaps), IOC analysis (IP, domain, hash, CVE), threat actor attribution, ransomware tracking, Cyber Kill Chain.

MODULE_04

AI & LLM Security

LLM-driven classification & clustering, prompt injection testing (OWASP LLM Top 10), RAG pipelines, NER (BERT, GLiNER), grammar-constrained extraction (GBNF), AI-assisted triage.

MODULE_05

Automation & Development

Python (FastAPI, Flask, pandas, asyncio, TensorFlow), API integrations, event-driven automation, Bash, SQLite, Postgres, Docker, Git, CI/CD (GitHub Actions, SARIF).

MODULE_06

Tooling & Networking

Burp Suite, Nmap, OWASP ZAP, Wireshark, nuclei, subfinder, httpx; TCP/IP, DNS, TLS, Firewalls, IDS/IPS, Linux.

03 // field log

Professional experience.

OCT 2024 — OCT 2025

Cyber Threat Intelligence Researcher (Master's Thesis)

CISPA Helmholtz Center for Information Security, Saarbrücken
  • Built a fully automated 16-source OSINT ingestion pipeline (Ransomware.live, CISA, international CERTs) accumulating 4,231 incidents across 53 countries, with fuzzy deduplication and incremental source-state tracking.
  • Automated MITRE ATT&CK mapping via semantic RAG (697 techniques embedded, top-5 candidates per article), yielding 512 technique observations across 14 tactics with no manual tagging.
  • Designed a 105-field grammar-constrained LLM extraction schema (GBNF) with GLiNER NER pre-pass and Pydantic-validated self-correction; 67% enrichment coverage across 2,847 incidents.
  • Built a 14-table intelligence database with an 8-type IOC schema and ~50 FastAPI endpoints powering an interactive dashboard with tactic heatmaps and sector-targeting matrices.
JAN 2023 — AUG 2025

Email Security Analyst, NGSF Team

1&1 Mail & Media SE, Karlsruhe
  • Built and maintained LLM-driven classification pipelines for spam and phishing detection processing ~350K emails/day on infrastructure handling ~4 billion emails/week.
  • Performed large-scale threat hunting and telemetry analysis in Elasticsearch/OpenSearch; built Python automation for threat enrichment, incident triage, and operational response.
  • Engineered a brand-impersonation detection system combining ML models, embeddings (RETVec), and BERT-based NER via OpenSearch pipelines across IONOS, GMX, and WEB.DE user bases.
  • Contributed to detections-as-code: automated rule deployment, version-controlled alerting logic, and structured telemetry pipelines across email security infrastructure.
NOV 2020 — SEP 2021

Test Development Engineer

Wipro Limited, Bangalore
  • Built automated test and data-validation frameworks for enterprise cloud applications (.NET/MSSQL), cutting manual QA cycles by 25% and surfacing data-integrity anomalies for triage.
  • Documented technical findings and reproduced edge-case failures for cross-functional teams, reducing defect investigation turnaround.
04 // deployed projects

Selected work.

Case studies and open-source tools spanning cloud risk, threat intelligence, and AI security testing.

EduThreat-CTI

01
PythonLLMsFastAPINext.js

End-to-end automated OSINT threat-intelligence platform for the education sector.

  • 15-source ingestion distilling 124,676 raw observations into 2,967 verified incidents across 91 countries (2000–2026).
  • 132-field CTI schema via Qwen3-Coder (480B) + GLiNER NER; 91% accuracy on ransomware-vs-rest classification.
  • Identified ransomware as the dominant threat (~40% of incidents, peaking at 52% in 2025); MOVEit breach cascaded to 93 institutions.
  • Threat knowledge graph linking 213 threat actors, CVEs, and vendors to surface coordinated campaigns.

LLMMap

02
PythonFastAPILLMs

Prompt injection testing framework — dual-LLM attack-and-judge architecture.

  • Covers 227 prompt injection techniques across 18 attack families.
  • SARIF v2.1.0 export for CI/CD security integration.
  • Ships with PromptLab — an OWASP LLM Top 10 classification lab with vulnerable/defended simulation across Ollama, OpenAI, Anthropic, and Google backends.

WRX — Web Recon eXecutive

03
PythonAutomation

Security automation orchestrator unifying the recon & scanning stack.

  • Unifies subfinder, httpx, katana, ffuf, nuclei, and OWASP ZAP into one pipeline.
  • Async job monitoring, run diffing, and export connectors for SARIF, GitHub, and Jira.
  • Aligned with detections-as-code workflows for continuous recon.

Cloud Migration Security Assessment

04
GCPSTRIDENIST

Self-directed case study — securing a GitLab-to-GCP migration.

  • STRIDE threat modeling and NIST SP 800-30 / ISO 27005 rating across 18 risk scenarios on a 5×5 likelihood-impact matrix.
  • Identified critical risks (access-token & long-lived service-account key exposure); remediated via Workload Identity Federation.
  • Produced a five-layer reference architecture with IAP, FIDO2 MFA, SLSA provenance, and ATT&CK-mapped detections.
05 // currently building

Outside of security work.

Products in progress at Matrix Social Labs — a startup studio I run alongside the security work above.

Blendn

B
EventsSocialReal-time

Where events meet serendipity — discover events in your city and connect with people around you, live and anonymously. No catfish, no cringey bios, just vibes.

Safera

S
SafetyCivicMaps

A place-based women safety map for Indian cities — anonymous reporting, safer routes, and city watch pages. Map-first, not form-first, no accounts required.

Prism

P
AINewsLLMs

Role-aware AI news intelligence — the same story read through your professional lens, every side of the narrative, and a grounded agent you can ask.

06 // live from github

Pulled straight from the source.

This grid calls the GitHub API in your browser right now — no cached screenshots.

connecting to api.github.com...
View full profile →
07 // get in touch

Let's secure something together.

Open to conversations on threat intelligence, detection engineering, and cloud security. Based in Saarbrücken, Germany — reachable anywhere.