Available for Opportunities

Hello, I'm

Mahesh Syangtan

Cybersecurity

Securing Architecture. Defending Data.

Passionate about Penetration Testing, Application Security, and Governance, Risk & Compliance (GRC) — building resilient defenses from the ground up.

bash — 80×24 SSH Secure
visitor@portfolio:~$

About Me

I'm a passionate cybersecurity professional with a relentless drive to stay ahead of evolving threats. My expertise spans the full security lifecycle — from proactive red-team engagements and vulnerability research to building resilient blue-team detection pipelines and governance frameworks.

I believe the best defenders think like attackers. My work is grounded in the principle that security is not a product — it's a mindset. Whether hunting advanced persistent threats, hardening cloud infrastructure, or aligning teams with compliance frameworks, I bring structured thinking and technical depth to every engagement.

🎯 Threat Hunter 🔴 Red Teamer 🔵 Blue Teamer ☁️ Cloud Security 📋 GRC Specialist 🐛 Bug Hunter
0
CTF Challenges Solved
0
Vulnerabilities Found
0
Years of Learning
Active
Continuous Learning

Skills Matrix

Offensive Security

Red Team & Penetration Testing

Kali Linux Metasploit Burp Suite Wireshark Nmap / Nessus SQLMap John the Ripper Cobalt Strike OWASP Top 10

Defensive Security

Blue Team & Incident Response

Splunk SIEM Elastic Stack CrowdStrike Snort / Suricata Incident Response Digital Forensics Threat Intelligence MITRE ATT&CK Vulnerability Mgmt

Cloud & DevSecOps

Infrastructure & Pipeline Security

AWS Security Azure Sentinel Docker / Kubernetes Terraform CI/CD Security IAM / Zero Trust CSPM Tools Secrets Management SBOM Analysis

Programming & Scripting

Automation & Tool Development

Web Designing Python Bash / Zsh PowerShell Go JavaScript Regex YARA Rules Sigma Rules SQL

Featured Projects

Active

Automated Threat Hunting Script

Developed a Python-based threat hunting automation framework that ingests IOCs from OSINT feeds, correlates events in Splunk via REST API, and auto-generates structured IR reports — reducing manual analysis time by 70%.

Python Splunk API STIX/TAXII REST APIs Threat Intel
Complete

Network Vulnerability Assessment

Conducted a full-scope internal network penetration test for a mid-size enterprise. Identified 14 critical misconfigurations including Kerberoasting, Pass-the-Hash paths, and unpatched CVEs, with actionable remediation guidance.

Nmap Nessus Metasploit BloodHound Active Directory
Research

Cloud Security Posture Dashboard

Built a real-time AWS security posture dashboard that evaluates S3 ACLs, IAM privilege escalation paths, CloudTrail gaps, and Security Group misconfigurations using Boto3 and outputs risk-scored findings to a web UI.

Python AWS Boto3 IAM CloudTrail Terraform

Education & Certifications

Certifications

eJPT
eLearnSecurity Junior Penetration Tester (eJPT)
INE / eLearnSecurity
In Progress ● Pursuing
SEC+
CompTIA Security+
CompTIA
In Progress ● Pursuing
THM
TryHackMe — Top 10% Ranking
TryHackMe
2022 – Present ● Active
HTB
Hack The Box — Active Practitioner
Hack The Box
2022 – Present ● Active

Education

BCS.CS.NT (Bachelor of Computer Science in Computer Science & Network Technology)
Lincoln International College
2024 – Present Kathmandu, Nepal

Currently studying Computer Science and Network Technology. Focused on systems security, network architecture, web technologies, and security practices.

Professional Training & Labs
TCM Security / Hack The Box / TryHackMe
2022 – Present

Actively engaging in hands-on laboratories, learning about ethical hacking, threat hunting, secure software architecture, and vulnerability research.

Higher Secondary Education (+2 Science)
Sanothimi Campus
2022 – 2024 Bhaktapur, Nepal

Completed higher secondary education with focus on science stream before transitioning to a computer science pathway.

Get In Touch

Have a security challenge, a collaboration idea, or just want to talk shop? My inbox is always open.