Vishal Tharu

Open to work Security Engineer Carson, California

Vishal Tharu

Build. Break. Repeat.

I build detection — the rules, the pipeline that feeds them, and the lab I attack to find out where they fail.

Open to IAM, SOC, security analyst and security engineering roles

By the numbers

62
Participants Competitors on the CTF platform I built and ran
167
Challenges shipped Authored and deployed for a single three-and-a-half hour event
24/25
False alarms removed Scoring code rewritten after real traffic proved it wrong
2
Attack chains caught Two-step attacks spotted by connecting separate events

Case studies

Two things I built, and what each one taught me by breaking.

Lab / personal 2025 – present

SOC 2.0

I built a security monitoring system, then attacked it to find out what it missed

Pointing real machines at it exposed roughly 82% false alarms in my own scoring code. Fixing it took four separate corrections and re-checking every address the system had ever flagged.

  • FastAPI
  • OpenSearch
  • Vector
  • Sigma
  • Wazuh
  • Sysmon

Other work

Not public

Campus occupancy heatmap

CSUDH Office of the Vice Provost

Turns the university class schedule into an hour-by-hour picture of how busy each building will be. Built first as a standalone Python application, then rebuilt as a script running inside the office’s own spreadsheet once it was clear that a new application handling student data would need a security review outlasting my appointment. Still in use. The data is confidential, so nothing from it is shown.

  • Office Scripts
  • Python
  • pandas

Also public

  • CTFd Workshop Hands-on hacking workshop I ran for a national computing conference, October 2025.
  • Header security project Checks a website for the protective settings it should be sending to browsers, and explains what each missing one exposes.
  • SYN flood lab A controlled denial-of-service experiment, with the defence that stops it.
  • Web application pentest A structured test of a deliberately vulnerable web application, written up finding by finding.
  • AWS secure banking A cloud architecture for financial data built to payment-card and banking regulations.

Coursework and training

Cryptographic algorithms implemented from scratch, a LAMP server build, a Docker and Jenkins build pipeline, an AWS deployment project, and Red Hat administration practice — from the graduate programme and the year of technical training before it.

All repositories on GitHub

Blog

Fifteen challenges, each one ending with how you catch it.

Most writeups stop at the answer. Stopping there has always felt like doing half the job — the interesting question is not how the attack worked, it is what would have noticed it.

  • Forensics

    Malware that never touched the disk

    Someone left a backdoor on a Windows machine without saving a single file. It hid inside a database Windows keeps for its own housekeeping — and ran itself once an hour, as the most privileged account on the system.

  • Network forensics

    Every keystroke, smuggled out one letter at a time

    A guest laptop was quietly sending everything typed on it to an attacker — one character per web request, hidden in the part of a request nobody inspects.

  • AI security

    I did not hack the AI. I just told it who I was.

    An AI assistant guarded an internal code. It decided whether you were allowed to have it by asking your name — and then believing the answer.

All writeups On GitHub

Experience

  1. Aug 2025 – May 2026 Carson, CA

    President CSUDH Cybersecurity Club

    Elected vice president in January 2025, then president that August.

    A 120-member student community running four flagship events a year, including the university’s annual hacking competition.

    • Led a 120-member community and recruited a six-person officer team, setting the technical roadmap each semester.
    • Designed and built the platform for ToroHack 10.0 — 167 challenges across three difficulty tracks, played by 30 teams in a single afternoon. Owned the requirements, the challenge design, the infrastructure and the live operations.
    • Ran the event end to end: lined up the speakers, secured sponsorship from Adobe and the university’s Computer Science department, and built the public event site.
    • Rehearsed the whole system before the day — a simulated run with 150 players, a check of all 64 challenge servers, and three rounds of independent testing with tracked fixes.
    • Restored the entire platform from backup onto a clean machine afterwards to prove the recovery process actually worked. It found six real faults that a written plan would have missed.
    • Taught web exploitation and cloud security sessions to members across the year.
    • Docker
    • Linux
    • nginx
    • Python
    • Flask
    • Redis
    • MariaDB
    • TLS
    • Event operations
  2. May – Aug 2025 Carson, CA

    Student Assistant — Academic Affairs CSUDH Office of the Vice Provost

    The office was losing the analytics tool it used to see how busy each campus building would be, and was evaluating a paid replacement.

    • Built the replacement in-house: a tool that turns the class schedule into an hour-by-hour heatmap of expected student numbers, covering every classroom on campus.
    • Rebuilt it once, deliberately. The first version was a standalone Python application — then I understood that any new application handling student data would need an IT security review that would outlast my appointment. A correct tool nobody is allowed to run is not a tool.
    • Shipped it as an Office Script instead, running inside the office’s own spreadsheet on the data already there. Nothing new to approve, no data leaving the university, no new access to grant. It is still in use.
    • Handled budget tracking, records and scheduling for the office alongside the build.
    • Office Scripts
    • Python
    • pandas
    • Data analysis
    • Automation
  3. Jun 2023 – May 2024 Ahmedabad, India

    Cybersecurity & Cloud Infrastructure Intern Grras Solutions

    Three consecutive full-time technical programmes over eleven months, moving from systems administration into offensive security.

    • Red Hat Linux, Ansible and AWS — server administration, shell scripting, configuration automation and cloud fundamentals. Sat and passed the Red Hat Certified System Administrator exam during this period.
    • Python — scripting and automation.
    • Ethical hacking curriculum — networking, reconnaissance, scanning, vulnerability assessment, cryptography and web application security, with hands-on labs throughout.
    • Red Hat Linux
    • Ansible
    • AWS
    • Bash
    • Python
    • Web application security
  4. Sep 2021 – Aug 2022 Ahmedabad, India

    Assistant System Engineer Tata Consultancy Services

    Front-line support for an enterprise SAP system during a platform migration. Deciding who is allowed to do what, and fixing it when the answer is wrong.

    • Handled access requests and permission changes for enterprise SAP users across development and test systems, granting and removing permissions against defined role requirements.
    • Investigated and resolved access failures reported by users — working out whether someone had been given the wrong permissions, or the right ones in the wrong place.
    • Held a same-day turnaround on requests, tracked through the organisation’s ticketing system.
    • Joined client calls to troubleshoot access problems directly, walking users through fixes over screen share.
    • Diagnosed certificate errors blocking access to a legacy internal site and restored access with a temporary certificate while the permanent fix was arranged.
    • Completed the graduate systems engineering programme alongside daily support work.
    • SAP ECC
    • Identity & access management
    • User provisioning
    • ServiceNow
    • Incident support

Also at CSU Dominguez Hills, 2024 – 2026

Supplemental instruction leader and then mentor, supporting statistics and Java students in lecture and running structured revision sessions. Teaching assistant across large mathematics courses, where I delivered a faculty session comparing AI assistants on real teaching tasks. Technical assistant at the University Theatre. President of the Indian Student Organization, running cultural festivals across the academic year.

Skills

Interview me for an hour I have built with these, broken them, and fixed them under time pressure.
  • Detection rule writing (Sigma)
  • Docker & Docker Compose
  • Linux administration
  • MITRE ATT&CK mapping
I use these regularly Productive without reaching for the documentation.
  • Python
  • Bash
  • FastAPI
  • nginx
  • Caddy
  • PostgreSQL
  • Redis
  • Sysmon
  • Git
  • CTF challenge design
  • Identity & access administration (SAP)
Used in a lab or one project I have shipped something real with these, once. I would need a ramp-up.
  • OpenSearch
  • Vector
  • Wazuh
  • auditd
  • Atomic Red Team
  • AWS
  • Ansible
  • React
  • Flask
  • MariaDB
  • Prometheus & Grafana
  • scikit-learn
  • Office Scripts
  • pandas
  • Java
Learning right now Actively working through these, not yet claiming them.
  • AI & LLM security
  • Prompt injection defence
  • Proxmox

Education

  1. Aug 2024 – May 2026

    M.S. Cybersecurity

    California State University, Dominguez Hills Carson, CA

    3.9 GPA Nine courses, 254 graded pieces of work, 94.2% average.

    • Graduate Project 100%

      My capstone was SOC 2.0 — the security monitoring system on this site. It has kept growing since.

    • Advanced Hacking Prevention 97.2%

      Every attack lab shipped with a matching defence lab. Wrote scanners and packet tools from scratch rather than running someone else’s.

    • CyberOps and Cloud DevSecOps 94.7%

      Build pipelines, log analysis, intrusion detection and secure cloud architecture. Final project was a banking system on AWS aligned to payment-card and financial regulations.

  2. Aug 2017 – May 2021

    B.E. Information & Communication Technology

    L.J. Institute of Engineering & Technology, Gujarat Technological University Ahmedabad, India

Certifications

  • CompTIA Security+ ce

    CompTIA

    Earned June 2025 Valid to June 2028

    ISO 17024 accredited · DoD 8140 approved

    Verify
  • Red Hat Certified System Administrator

    Red Hat

    Earned January 2024 Valid to January 2027

    Performance-based exam — no multiple choice

    Verify
  • Google Cybersecurity Professional Certificate

    Coursera

    Earned July 2023 No expiry

    Foundations — completed before starting the master’s

    Verify

In progress TryHackMe AI Security — learning path, not a certification, expected August 2026.

Also: ethical hacking and cryptography coursework (Grras Solutions), and the Tata Group cybersecurity analyst job simulation.

TryHackMe Top 4% · 119 rooms · 18 badges as of 8 August 2026

About

I started in access administration at Tata Consultancy Services, setting up SAP users and chasing down the reasons people could not get into the systems they needed. It was unglamorous work and it turned out to be the right foundation — deciding who is allowed to do what is where a great deal of security actually lives. I finished an M.S. in Cybersecurity at CSU Dominguez Hills in May 2026 and spent that time building the things I wanted to be able to point at.

What I am best at is detection: writing the rules that recognise an attack, and building the plumbing that gets the evidence to them. I built a security monitoring system, wrote 32 rules for it, and then pointed real machines at it — an Ubuntu machine, a Windows machine, and a Kali machine actually attacking them both. Two multi-step attacks were caught. Most of what I learned came from what broke afterwards.

I trust measurements over assumptions, which is mostly a habit of distrusting my own work. My scoring code looked fine until real traffic showed it was calling Cloudflare an attacker — around 82% false alarms. I fixed it, declared victory off one clean run, watched the false alarms come back, and only then went through all 25 addresses it had ever flagged and scored them again. That is the version I trust. The same habit turned up a limit that could be bypassed by asking a different server, and an application that could not see who any of its visitors actually were.

I led the CSUDH Cybersecurity Club as vice president and then president, recruited a six-person officer team, and ran a 120-member community. For our annual competition I designed and built the entire platform — 167 challenges, over a hundred servers, three difficulty tracks and a five-act story, on one rented machine, in 17 days. Sixty-two people competed on it for three and a half hours. Before that I spent two years as a supplemental instruction leader and teaching assistant, which is where I learned that explaining something clearly is a separate skill from knowing it.

My lab runs often enough to keep breaking in interesting ways. I am in the top 4% on TryHackMe with 119 rooms completed, and I write up the ones worth writing up — including the defensive rule, because stopping at the answer has always felt like doing half the job. Right now I am working through AI security, partly out of self-interest: I built five escalating prompt-injection challenges for the competition and I would like to be better at both sides of that.

I have unreasonably strong opinions about cooking. Every recipe gets my own edit, and you have not had a proper sandwich until you have had one of mine. I like people, which turns out to matter more in this work than it sounds like it should.

Contact

Email is the fastest way to reach me.

I am looking for IAM, SOC, security analyst or security engineering roles — the kind where I own something end to end rather than watch a queue. I want to work somewhere the goal is bigger than the quarter, on a product that leaves people better off. I bring production access-administration experience, a detection setup I built and tuned against real attacks, and a habit of finding my own mistakes before someone else does.