About Skills Experience Projects Education Certifications Badges Learning Reviews Resume Contact
atharva@portfolio:~
atharva@portfolio:~$
Available for hire 📍 London, UK

Atharva
Kulkarni

CEH V12 · GCHQ-Accredited MSc Cyber Security · Targeting Penetration Testing & Red Team
Turning 4 years of enterprise infrastructure knowledge into offensive security expertise — finding the gaps before adversaries do.

CEH
Certified
MSc
Cyber Security
4+
Yrs IT & Security Ops
85%
CSAT Uplift
01 //

About Me

I am a CEH-certified ethical hacker with a GCHQ-accredited MSc in Applied Cyber Security, making a deliberate move into offensive security from a foundation in enterprise IT — Active Directory, endpoint hardening, network operations, and incident investigation. That background gives me an attacker's instinct for where real systems break: misconfigurations, weak identity boundaries, and overlooked integrations.

My career began in enterprise IT and network operations — configuring and hardening 250+ devices, managing Active Directory and endpoint compliance, and running incident investigations across complex Windows environments. At Eurostop I now own data integrity and conduct security assessments across enterprise EPOS platforms, middleware, a cloud POS, and internal integrations, applying root-cause analysis and operational-security thinking at scale. The thread through all of it is the same instinct that drives good penetration testing: trace the data, find the anomaly, secure the boundary.

Academically, my research is offensive in nature — my MSc dissertation weaponised Generative Adversarial Networks against hardware Physical Unclonable Functions. Outside work I am continuously hands-on: completing TryHackMe pentest paths, working live HackTheBox machines, and building toward the eJPT and OSCP, with red team operations and the CRTO as the long-term target. I am based in London and open to junior penetration testing and security analyst roles across the UK.

🔍 Offensive Mindset from Enterprise Ops

Years managing LAN/WAN, Active Directory, and middleware gave me direct insight into the misconfigurations attackers exploit first.

🎓 Research-Led Security Thinking

MSc dissertation on Machine Learning Attacks on Physical Unclonable Functions — demonstrating threat research capability at hardware and cryptographic levels.

⚡ Hands-On Lab Practice

Actively practising manual exploit identification, network reconnaissance, and vulnerability assessment through TryHackMe Junior Pentest Path and HackTheBox.

02 //

Skills

Offensive Security

Penetration Testing Vulnerability Assessment Ethical Hacking Web Application Security OWASP Top 10 Active Directory Attacks Network Security Privilege Escalation OSINT & Threat Intel MITRE ATT&CK Digital Forensics Cryptography

Tools & Platforms

Burp Suite Nmap Kali Linux Metasploit Wireshark Nessus / OpenVAS Active Directory Intune / Autopilot ServiceNow Nexthink TryHackMe HackTheBox

Infrastructure & Defensive

TCP/IP & LAN/WAN Firewall Configuration Network Enumeration Cisco Infrastructure Packet Analysis IDS / IPS Endpoint Security Zero Trust Incident Response Cyber Essentials GDPR Awareness Intrusion Response (IRS) Network Security Monitoring Anomaly Detection Defence in Depth Threat Mitigation

Certifications & Programming

CEH V12 ICMCP MSc Applied Cyber Security GCHQ-Accredited Fortinet NSE 1 & 2 Pre Security (SEC0) Python Bash / Shell PowerShell SQL Machine Learning
03 //

Experience

Sep 2025 — Present
Eurostop Ltd.
London, UK

Technical Support Analyst

Primary technical escalation point for enterprise EPOS and retail systems, overseeing secure data flows across in-store tills, middleware, head-office platforms, and third-party integrations.

  • Investigate and resolve complex data integrity failures across interconnected retail systems.
  • Enforce operational security controls including secure access management and incident investigation workflows.
  • Drive process improvements that enhance system resilience and reduce operational disruption.
EPOS SystemsSQLMiddlewareData AnalysisIncident Response
Feb 2025 — Sep 2025
Diageo
Belfast, UK

DSS Engineer

Delivered enterprise-grade IT support for VIP executive clients, managing the full hardware and software lifecycle with a focus on security-hardened configurations.

  • Proposed security-first asset lifecycle improvements including Intune-Autopilot integration and Nexthink tracking.
  • Resolved Active Directory and authentication compliance issues across enterprise user accounts.
  • Configured tenant lock and ServiceNow workflows, improving IT efficiency and security posture.
Active DirectoryIntuneServiceNowNexthinkWindows OS
Jan 2024 — Jan 2025
Concentrix
Belfast, UK

Technical Support Engineer

Provided Tier 1–2 support for BT Broadband products, exceeding performance benchmarks through technical precision and cyber-awareness education.

  • Reduced query resolution time by 35% through structured diagnostic workflows.
  • Achieved an 85% increase in customer satisfaction ratings.
  • Reduced escalated tickets by 80% across broadband, mobile, and home tech.
  • Educated customers on phishing and cybersecurity scams, reducing breach incidents.
BT BroadbandHome NetworkingCyber AwarenessTelephony
Jan 2022 — Jul 2022
Clariant India Ltd.
Mumbai, India · Internship

Network Security Operations Specialist

Led network infrastructure operations for a large enterprise, delivering measurable security and efficiency improvements across 250+ devices.

  • Reduced network outage response time by 30% via ServiceNow-integrated processes.
  • Decreased security breaches by 25% through hardened device configurations.
  • Configured 250+ machines, increasing onboarding efficiency by 25%.
  • Delivered cybersecurity awareness training, raising employee threat awareness by 15%.
ServiceNowNetwork SwitchesRoutersSecurity ConfigCisco
04 //

Projects

🎯
Ongoing · TryHackMe & HackTheBox

CTF & Penetration Testing Labs

Active CTF competitor building offensive skills across enumeration, exploitation, and privilege escalation. Currently active on the Junior Penetration Testing path on TryHackMe.

  • Active on Junior Penetration Testing path on TryHackMe
  • Practising manual exploit identification and vulnerability chaining
  • Developing recon, web app testing, and post-exploitation techniques
NmapBurp SuiteMetasploitLinuxWeb Exploitation
🤖
Queen's University Belfast · 2023

ML Attacks on Physical Unclonable Functions

MSc dissertation weaponising GANs against PUF-based hardware authentication. Synthesised challenge-response pairs to train ML attack models against hardware security mechanisms.

  • Demonstrated measurable PUF vulnerability through GAN-synthesised datasets
  • Evaluated attack success rates and proposed countermeasures
  • Advanced hardware-level threat research across ML and cryptography
PythonGANsMachine LearningCryptographyPUFs
🔐
Queen's University Belfast · 2023

Honey Encryption: Brute-Force Resistant Security

Researched Honey Encryption returning fake plausible plaintext on incorrect decryption, blinding brute-force attacks. Proposed a developer API for real-world integration.

  • Designed a developer API for web and cloud application integration
  • Applied DTE encoding to passwords, PINs, and biometrics
  • Mapped use cases across internet banking and cloud security
PythonEncryptionDTEAPI DesignCloud Security
🔎
Queen's University Belfast · 2023

NTFS Digital Forensics: File Recovery on Windows 10

Forensic investigation into deleted file recovery using MFT analysis, slack space, disk imaging, and CLI tools. Applicable to cybercrime investigation and incident response.

  • Analysed MFT entries, slack space, and disk imaging for artifact recovery
  • Compared CLI tools and recovery software for forensic soundness
  • Documented best practices for evidence preservation and breach analysis
NTFSDisk ImagingMFT AnalysisWindows ForensicsCLI Tools
🛡
Queen's University Belfast · 2022

Automated Network Intrusion Response System (AIRS)

Research into automated self-defence for enterprise networks — integrating IDS/IPS detection with an Intrusion Response System (IRS) that delivers pre-configured active and passive countermeasures to contain attackers and restore system health.

  • Classified IRS response models — notification, manual, and automatic (expert, adaptive, associative) — and mapped active vs passive mitigations
  • Evaluated agent-based IDS/IRS architectures: CSM, EMERALD, JiNao, and NetSTAT
  • Assessed weaknesses (false positives, scalability, alert flooding) and future directions in real-time response and risk assessment
IDS/IPSIRSNetwork SecurityThreat MitigationAnomaly Detection
🧰
2026 · Client-Side Security Toolkit · github.com/atharvak161/cybersec-toolkit

Cybersec Toolkit

A client-side cybersecurity utilities toolkit — encoding/decoding, hashing, JWT/AES/RSA tools, a CyberChef-style recipe chainer, and OSINT lookups. Nothing ever leaves the browser except a few clearly-disclosed public API calls.

  • Encoding, hashing, and JWT/AES/RSA tooling with a CyberChef-style recipe chainer
  • OSINT lookup utilities alongside classic encode/decode and crypto tools
  • Fully client-side — no data leaves the browser except disclosed public API calls
JavaScriptWeb Crypto APIJWTOSINTClient-Side Security
🗄
2026 · Cybersecurity Knowledge Base · github.com/atharvak161/cybersec-vault

The Vault

A fast, fully client-side knowledge base for 248 cybersecurity notes — cloud, GRC, OSCP, and red-team — with an Obsidian-style reader: instant full-text search, a command palette, wiki-style cross-links, an interactive link graph, and backlinks. No backend, nothing leaves the browser.

  • 248 interlinked notes across four tracks with full-text search and a ⌘K command palette
  • Wiki-links, backlinks, an interactive link graph, and a scroll-spy table of contents
  • Fully static and client-side — HTML sanitised with DOMPurify, all assets vendored, zero external calls
JavaScriptMarkdownFull-Text SearchGraph ViewClient-Side
🔎
2026 · Full-Stack · github.com/atharvak161/jobscope

JobScope — UK Job Aggregator

UK job aggregator that filters listings by visa sponsorship status and security clearance requirements — built for candidates who need to know eligibility before they apply. Resume parsing powered by Claude AI.

  • Filters roles by visa sponsorship and security clearance eligibility
  • Claude AI resume parsing for automated candidate-to-role matching
  • IDOR, SSRF, and prompt-injection defences built in from the ground up
Next.js 16TypeScriptPostgreSQLPrisma 7Claude AI
📋
2026 · Full-Stack · github.com/atharvak161/Blueprint

Blueprint — Project Management Tool

A project management dashboard for tracking tasks, milestones, and team progress. Built as a single-page app with a clean kanban-style interface.

  • Visual project and task tracking with status columns
  • Milestone management with progress indicators
  • Deployed via GitHub Actions to GitHub Pages
💷
2026 · Full-Stack · github.com/atharvak161/finance-dashboard

Finance Dashboard — Personal Finance Tracker

Comprehensive personal finance tracker for NRI/UK professionals. Tracks income, expenses, investments, debts, and goals across GBP and INR. Includes ROAI analytics, envelope budgeting, bill calendar, SMS transaction parsing, and OLED dark mode.

  • Cross-currency portfolio tracking with real-time ROAI metrics
  • SMS and CSV bank import with auto-categorisation
  • Privacy mode, keyboard shortcuts, and OLED dark mode

📝 Offensive Security Writeups

Documented security research — vulnerability analysis, exploitation methodology, and remediation.

🧵
TryHackMe

Flag Vault 2

Exploited a format string vulnerability (CWE-134) in printf() to leak a flag from stack memory — no buffer overflow needed.

CWE-134 · CWE-787 · A03:2021
Read Writeup →
💾
TryHackMe

Flag Vault

Exploited a stack buffer overflow (CWE-121) via gets() to overwrite an adjacent stack variable and bypass authentication.

CWE-121 · CWE-676 · A04:2021
Read Writeup →
🔐
TryHackMe

Capture!

Built a custom Python script to enumerate valid usernames via differential error messages and solve math-based CAPTCHAs programmatically.

CWE-307 · CWE-200 · A07:2021
Read Writeup →
🏳
TryHackMe

Simple CTF

Exploited CVE-2019-9053 (time-based blind SQLi, CVSSv3 9.8) in CMS Made Simple to extract credentials, then escalated to root via vim sudo misconfiguration.

CVE-2019-9053 · CWE-89 · A01:2021
Read Writeup →
🥒
TryHackMe

Pickle Rick

Retrieved credentials via information disclosure in HTML comments and robots.txt, then achieved RCE and root escalation through a misconfigured sudo policy.

CWE-540 · CWE-284 · A01:2021
Read Writeup →
05 //

Education

2022 — 2023

MSc Applied Cyber Security

Queen's University Belfast

GCHQ-accredited. Modules: Network Security & Monitoring, Malware Analysis, Software Assurance, Computer Forensics, Applied Cryptography. Dissertation: ML Attacks on PUFs.

2019 — 2022

BSc Computer Science

Pillai College of Arts, Commerce & Sciences

Core modules in network technologies, routing protocols, Cisco infrastructure, and network security. Python specialisation.

06 //

Certifications

🛡
EC-Council
Certified Ethical Hacker (CEH V12)
Credential IDECC9421760853
🔒
Fortinet
Network Security Expert (NSE) Level 1
Credential IDPggZRhVh2p
🔒
Fortinet
Network Security Expert (NSE) Level 2
Credential IDuTMYfCWHCd
🛡️
TryHackMe
Pre Security (SEC0)
🎯
TryHackMe
Junior Penetration Testing Path
In Progress · Active
07 //

Badges

Pre Security (SEC0) badge Pre Security (SEC0) Exam TryHackMe Pre Security certification Ruby League badge Ruby League epic: 0.1% Ruby League 1st place Sapphire League badge Sapphire League epic: 0.3% Sapphire League 1st place Platinum League badge Platinum League epic: 0.3% Platinum League 1st place Ice badge Ice rare: 1.9% Exploiting Windows via a media server 90 Day Streak badge 90 Day Streak rare: 2.1% Hacking for 90 days solid Sword Apprentice badge Sword Apprentice rare: 2.7% Completing the SQLMap room Metasploitable badge Metasploitable rare: 7.6% Exploiting machines with Metasploit Blue badge Blue rare: 8.4% Hacking into Windows via EternalBlue
08 //

Currently Learning

Active Focus

🎯

TryHackMe — Offensive Pentesting Path

Advanced exploitation, Active Directory attacks, and post-exploitation methodology beyond the Jr path.

● In Progress
💻

HackTheBox — Active Machines

Practising real-world enumeration, foothold identification, and privilege escalation on live boxes.

● Ongoing
📖

OSCP Preparation

Building methodology for OffSec Certified Professional — buffer overflows, manual exploitation, and structured report writing.

◆ Targeting 2025–26

Certification Roadmap

CEH V12

Certified Ethical Hacker — foundations of offensive security

✓ Completed

TryHackMe Jr Pentest Path

Structured junior penetration testing curriculum

● Ongoing

eJPT — eLearnSecurity Junior Penetration Tester

Hands-on entry-level pentesting certification

□ Upcoming

TryHackMe — Penetration Tester (PT1)

Intermediate penetration testing certification — the PT1 exam

□ Upcoming

OSCP — OffSec Certified Professional

Industry-standard offensive security certification

□ Upcoming

CPTS — Certified Penetration Testing Specialist

Hands-on penetration testing certification — Hack The Box

□ Upcoming

CRTO — Certified Red Team Operator

Red team operations, C2 frameworks, and adversary simulation

□ Long-term Goal
09 //

Testimonials

Atharva demonstrated an unwavering commitment to his tasks. His ability to handle a wide array of responsibilities — from managing security for laptops for new joiners to troubleshooting network issues — showcased his versatility and problem-solving skills. His attention to detail and meticulous approach in cybersecurity, network ops, and overall tech support were truly commendable. His proactive attitude greatly contributed to the smooth operation of our IT support functions. He has proven to be a valuable asset, and I am confident that he will continue to excel in his future endeavors.

KK
Ketan Karkhanis
Head — Enterprise IT & Smart Workplace · Clariant
💼 LinkedIn Recommendation · Oct 2023

Atharva’s expertise in network support was evident throughout his internship. His adeptness in configuring and troubleshooting network devices ensured uninterrupted connectivity. Noteworthy was his initiative in setting up VPN connections for remote employees, showcasing his grasp of complex tunneling protocols and encryption methods. His proactive approach stood out — he not only excelled in routine tasks but also proposed network optimisation and security enhancement measures. He is a promising candidate for any network-related role, and I’m confident he will continue making valuable contributions.

SD
Sunil Dhanawade
Scientific IT Specialist · Clariant
💼 LinkedIn Recommendation · Aug 2023
10 //

Resume

Atharva_Kulkarni_Resume.pdf
Your browser doesn't support embedded PDFs.
Click here to view the CV or download it directly.
11 //

Contact

Let's connect

Open to Junior Penetration Tester roles and security engineering opportunities in the UK. Always happy to discuss offensive security, CTF challenges, or potential collaborations.