██████████████decrypting identity
000

// 01 — surface · DIVYANSH://VOID

security engineer

View Resume↓ Download

// 02profile

Profile

I build end-to-end platforms that assume hostile input.Full-stack developer with a security habit — CS at VIT (classof 2027), Hack Energy 2.0 finalist, and a blockchain dev whoaudited Ethereum contracts at IBM. I ship validated UIs, modularPython backends, data pipelines, and tooling that maps attack surface.
3+
years building
3
dev internships
5
certifications
150+
students mentored
  • Python
  • JavaScript
  • HTML
  • CSS
  • REST APIs
  • SQL
  • MySQL
  • ElasticSearch
  • Git
  • GitHub Actions
  • Linux
  • Web Crawling
  • OWASP Top 10
  • Threat Modeling
  • Solidity
  • Ethereum

// 03record

Experience

  1. Backend Engineer · XtraGrad

    1 Jun – 30 Jun 2026

    • Building the backend for an AI-powered HR platform — designing APIs, data models, and AI integration layers for automated recruitment and candidate workflows.
    • Architecting scalable Python services and integrating LLM-driven features to automate HR decision pipelines end-to-end.
  2. Blockchain Developer · IBM

    May 2025 – Jun 2025

    • Audited Ethereum smart contracts for reentrancy, improper access control, and gas-misuse vulnerabilities.
    • Applied secure coding and input validation to harden contract logic; ran iterative testing cycles to eliminate logic flaws pre-deployment.
  3. Frontend Developer · 1Stop.ai

    Jan 2024 – Mar 2024

    • Built and optimised responsive UIs with HTML, CSS, and JavaScript; restructured frontend architecture to cut load times and improve cross-device consistency.
    • Enforced strict input validation and secure JavaScript patterns, reducing client-side attack surface and improving reliability.

// 04systems

Systems

Full-Stack

core

End-to-end platforms with responsive, validated UIs and clean REST APIs. HTML/CSS/JavaScript on the front, modular Python services behind — architected for load times and cross-device consistency.

  • JavaScript
  • Python
  • REST APIs
  • Responsive UI

Security

OWASP Top 10 and threat modeling by default. Smart-contract auditing (reentrancy, access control, gas misuse), parameter fuzzing for SQLi/XSS, and strict input validation to shrink the attack surface.

  • OWASP Top 10
  • Threat modeling
  • Smart-contract audit
  • Fuzzing

Backend & Data

Modular Python backends, distributed web crawlers, and data pipelines with per-stage validation and automated reporting — indexed in ElasticSearch for real-time querying.

  • Data pipelines
  • Web crawling
  • ElasticSearch
  • SQL / MySQL

Blockchain

Ethereum smart-contract development and security auditing at IBM — secure coding, iterative testing, and logic-flaw elimination before deployment.

  • Ethereum
  • Solidity
  • Contract auditing
  • Secure coding

// 05core

Core

01/05 · AI threat-intelligence platform & vulnerability scanner

CivicShield

AI-powered cybersecurity platform with a real-time global threat dashboard. Visualises active attack paths on a 3D globe, auto-classifies severity (Low→Critical), and streams live threat feeds for DDoS, ransomware, and phishing events. Full vulnerability scanner, attack-surface mapper, phishing detector, and API security analyser — backed by CivicShield AI for scan-derived intelligence insights. Hack Energy 2.0 Finalist.

  • Python
  • JavaScript
  • AI/ML
  • REST APIs

02/05 · End-to-end encrypted AI chat

CipherMind

Encrypted AI chat where every message is AES-256-GCM ciphered before leaving the browser — zero plaintext in transit. Session keys are derived via PBKDF2 and integrity is guaranteed by HMAC-SHA512. The Groq Llama 3.3 70B backend runs server-side with the API key fully protected. Tracks encrypted/decrypted message counts, token usage, and HMAC checks per session.

  • React
  • TypeScript
  • AES-256-GCM
  • PBKDF2

03/05 · Automated Solidity smart-contract security auditor

ChainAudit

Static analysis engine that parses Solidity smart contracts, extracts the AST, and runs a suite of vulnerability detectors — reentrancy, integer overflow/underflow, unchecked external calls, improper access control, and gas-griefing vectors. Generates structured audit reports with per-finding severity ratings (Critical → Low) and remediation guidance. Built on the blockchain security knowledge from the IBM auditing engagement.

  • Solidity
  • JavaScript
  • AST Analysis
  • Static Analysis

04/05 · ML pipeline predicting 2026 road-accident severity & blackspots

Accident Risk Model

End-to-end machine learning pipeline that ingests road-accident records and predicts 2026 accident occurrences and geographic blackspots — high-risk locations where collisions are statistically concentrated. Exploratory data analysis surfaces hidden patterns; feature engineering extracts time-of-day, weather, road-condition, and vehicle-type signals. The trained classifier outputs risk-tier scores with per-feature importance breakdowns and pinpoints accident-prone zones for targeted intervention.

  • Python
  • scikit-learn
  • pandas
  • EDA

05/05 · Enterprise static security scanner for banking systems

SecureScout

Production-grade security platform built for PSB Hackathon 2026 (UCO Bank × IIT Kharagpur). Detects vulnerable dependencies, hardcoded secrets, weak cryptography, injection flaws, and insecure configurations in Python projects. Ships a full Next.js dashboard with 5-tier RBAC, immutable audit logging, and a CI/CD gate that exits non-zero on Critical findings.

  • Python
  • TypeScript
  • Next.js
  • Express

// 06vault

Vault

channel secured · clearance granted
Security is not a feature you bolt on — it is the substrate everything else runs on. Every system I ship assumes hostile input, least privilege, and an audit trail.

certification roadmap

  1. 2024

    Frontend Developer — 1Stop.ai

  2. 2025

    Blockchain Developer — IBM

  3. 2026

    Google Cybersecurity Professional — Coursera

  4. 2026

    Hack Energy 2.0 Finalist — CivicShield

  5. 2027

    B.Tech CSE — VIT (expected)

// live shell — type a command

divyansh@void:~/vault

DIVYANSH://VOID — vault shell v1.0

type 'help' for commands · 'sudo hire me' for the good stuff

// 08signal

Signal

initiate
contact_

Open to internships, security work, and ambitious builds. Signal travels fastest by email — the form transmits straight to my inbox.

divyanshg2602@gmail.com