Open to Opportunities · CPT/OPT Eligible

SAHIL
SHAILESH
ZUNJARRAO

MS Cybersecurity @ NYU · Secure Systems Lab Contributor · OpenSSF gittuf

MS Cybersecurity student at NYU Tandon with experience in security engineering, digital forensics, application security, and open source security. I contribute to the OpenSSF gittuf project through NYU's Secure Systems Lab and have been involved in ROS2/SROS2 security research at NYU's OSIRIS Lab. I am interested in Security Engineering, Application Security, Blue Team Security, Security GRC, and Vulnerability Management.

Security Engineering Application Security Blue Team Security Security GRC Vulnerability Management Open Source Security
Core Stack
Go Python Splunk AWS Burp Suite Git
Latest Contributions:
OpenSSF gittuf
2
Merged OpenSSF
Pull Requests
2
Cybersecurity
Internships
3.88
NYU GPA

01 · About

About Me

I'm a cybersecurity graduate student at NYU with experience spanning digital forensics, application security, and open source security. My interests include Security Engineering, Blue Team Security, Security GRC, and Vulnerability Management, with hands-on experience contributing to Software Supply Chain Security through OpenSSF.

Before NYU, I completed cybersecurity internships in Mumbai, including digital forensic investigations at Maharashtra Cyber's Government Cybercrime Unit and cybersecurity research at CyberFrat. At NYU, I contribute to OpenSSF gittuf through the Secure Systems Lab and have been involved in ROS2/SROS2 security research as part of NYU's OSIRIS Lab, while continuing to build expertise in secure software and defensive cybersecurity.

MS in Cybersecurity
New York University, Tandon School of Engineering · Brooklyn, NY
Sep 2025 – May 2027 · GPA: 3.88/4.0
Secure Systems Lab Contributor · OSIRIS Lab
F-1 (CPT/OPT Eligible)
Coursework: Vulnerability Assessment & Penetration Testing, Application Security, Network Security, Information Systems Security Engineering & Management
BTech in Cybersecurity
Shah and Anchor Kutchhi Engineering College · Mumbai
Graduated May 2025 · GPA: 3.7/4.0
Certifications
ISC2 Certified in Cybersecurity (CC) Google Cybersecurity Professional Certificate Fortinet NSE 1 Fortinet NSE 2
Achievements
🔧
OpenSSF gittuf ContributorContributed Go test coverage for DSSE envelope verification and Lua sandbox execution through NYU's Secure Systems Lab, resulting in two merged pull requests.
🏆
1st Place, Pan-India HackathonLed a four-member team to first place in a Pan-India cybersecurity hackathon through a controlled EternalBlue SMB exploitation demonstration.
🛡️
Government Cybercrime ExperienceSupported digital forensic investigations, phishing investigations, and cybercrime case analysis during an internship at Maharashtra Cyber.
🩺
Medical IoT Security AssessmentSTRIDE-based threat model of a networked infant incubator simulator, identifying nine vulnerabilities including SQL injection and AES nonce reuse.

02 · Experience

Work Experience

Open-Source Contributor, Secure Systems Lab
Feb 2026 – Present
New York University · OpenSSF gittuf · Brooklyn, NY
  • Contributing to OpenSSF gittuf, a software supply chain security project, through NYU's Secure Systems Lab.
  • Merged two pull requests expanding automated test coverage for security-critical components, including DSSE VerifyEnvelope error handling and Lua sandbox RunScript execution paths.
  • Collaborated with OpenSSF maintainers through multiple code review cycles to align implementations with project testing standards and Go best practices.
Cybersecurity Analyst Intern
Jun 2024 – Dec 2024
Maharashtra Cyber, Government Cybercrime Unit · Mumbai, India
  • Investigated 30+ digital evidence samples using Autopsy and FTK, identifying attacker techniques, indicators of compromise, and exploitation vectors supporting fraud and phishing investigations.
  • Triaged 15+ cybercrime complaints end-to-end, analyzed incident patterns, coordinated response actions, and maintained chain of custody, achieving approximately 50% resolution rate.
  • Produced forensic reports and threat intelligence documentation for phishing, synthetic fraud, and digital impersonation investigations.
Cybersecurity Research Intern
Apr 2023 – Dec 2023
CyberFrat · Mumbai, India
  • Led a 4-member team to 1st place in a Pan-India cybersecurity hackathon by demonstrating EternalBlue SMB exploitation in a controlled environment against 10+ finalist teams.
  • Performed controlled buffer overflow analysis and payload development during offensive security exercises.

03 · Projects

Projects

OpenSSF gittuf Contributions
Merged PRs ↗
Go · Software Supply Chain Security · DSSE · Testing · Open Source
  • Expanded automated test coverage for security-critical components of gittuf, a software supply chain security project under the Open Source Security Foundation (OpenSSF).
  • Added Go test coverage for DSSE VerifyEnvelope error handling and Lua sandbox RunScript, covering previously untested execution paths, merged as PR #1457 and PR #1490.
  • Collaborated with OpenSSF maintainers through multiple review iterations as part of NYU's Secure Systems Lab.
Open Source · Merged
Medical IoT Security Assessment
STRIDE Threat Modeling · Infant Incubator Simulator · ISSEM, NYU Tandon
  • Conducted a vulnerability assessment of a networked medical device simulator using STRIDE threat modeling.
  • Identified nine vulnerabilities, including SQL injection, AES nonce reuse, and race conditions, with remediation recommendations.
Academic Research
Autonomous Security Intelligence Agent
GitHub ↗
Python · Google Gemini API · CVE · CVSS Scoring · Automation
  • Built a Gemini-powered security agent using the Google Gemini 2.5 Flash API to identify vulnerabilities, map CVEs, and generate CVSS-based remediation reports.
  • Developed automated vulnerability analysis and reporting workflows using CVE and CVSS data.
AI-Assisted Security
Web Vulnerability Scanner
GitHub ↗
Python · OWASP Top 10 · SQL Injection · XSS · CORS · SSL/TLS
  • Developed a Python-based OWASP Top 10 vulnerability scanner covering SQL injection, XSS, CORS misconfiguration, and SSL/TLS analysis.
  • Generated HTML and JSON reports with severity ratings and prioritized remediation recommendations.
Application Security

04 · Skills

Technical Skills

Security
Vulnerability Management · Vulnerability Assessment · Threat Detection · Threat Hunting · Incident Response · IOC Analysis · Threat Intelligence
Programming
Python · Go · Bash
Tools
Splunk · Nessus · Nmap · Burp Suite · Metasploit · Autopsy · FTK · Git
Networking
TCP/IP · DNS · Routing · Firewalls · Network Troubleshooting · Wireshark
Operating Systems
Windows · Ubuntu Linux · Kali Linux · WSL
Frameworks
MITRE ATT&CK · NIST CSF · OWASP Top 10 · ISO 27001
Cloud
AWS (IAM · EC2 · S3) · Cloud Security Fundamentals
Focus Areas
Security Engineering · Application Security · Blue Team Security · Security GRC · Vulnerability Management · Open Source Security · Software Supply Chain Security

05 · Contact

Get In Touch

Looking for opportunities during the 2026–2027 academic year and full-time roles from May 2027 in Security Engineering, Application Security, Blue Team Security, Security GRC, or Vulnerability Management. Feel free to reach out directly.

Quick Facts
LocationNew York, NY
StatusOpen to Opportunities
VisaF-1 · CPT/OPT Eligible
SeekingSecurity Internships & Research
Full-TimeMay 2027
RolesSecEng · AppSec · Blue Team · GRC