Skip to content
View sumansingh20's full-sized avatar
πŸ†
Focusing
πŸ†
Focusing

Organizations

@iit-patna-1

Block or report sumansingh20

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sumansingh20/README.md

Hi, I'm Suman Kumar πŸ‘‹

πŸ“ India
πŸ” Security Engineer | πŸ›‘οΈ Cloud security | βš™οΈ Backend & Systems Builder

Python Java Node.js Go Linux Docker Kubernetes Cybersecurity AI Security

I break systems deliberately β€”
so they fail safely in the real world.


🧠 Who I Am

I’m a security-first engineer with a strong backend and systems foundation.
I don’t believe in checkbox security. I believe in attack-aware engineering.

My approach is simple but strict:

If a system can be abused, it will be.
So design it assuming an intelligent adversary.

I actively work across:

  • Offensive security (how systems break)
  • Defensive engineering (how systems survive)
  • Backend & infrastructure (where attacks actually land)

🧭 Engineering Mindset

  • πŸ” Security is not a layer, it’s a baseline
  • 🧠 Threat models matter more than tools
  • πŸ§ͺ Proof-of-concept is useless without mitigation
  • πŸ—οΈ Systems should fail safely, not silently
  • πŸ€– AI without security is technical debt at scale

πŸš€ Current & Ongoing Projects

πŸ›‘οΈ CyberShield Defend

Defensive security tooling & automation for modern threats
Focus areas:

  • Threat detection logic
  • Secure automation
  • Practical defense workflows

πŸ”— https://github.com/sumansingh20/CyberShield


πŸ“¬ BharatMail β€” Secure Email Platform

A privacy-first, security-centric email system
Designed with:

  • Zero-trust mindset
  • Attack surface minimization
  • Secure auth & storage principles

πŸ”— https://github.com/sumansingh20/BharatMail


πŸ” Penetration Testers & Secure Modern Web Apps

Hands-on repository covering:

  • Real-world vulnerabilities
  • Exploitation techniques
  • Secure-by-design fixes

πŸ”— https://github.com/sumansingh20/Penetration-testers-and-secure-modern-web-apps


🧰 Technical Expertise

πŸ” Security & DevSecOps

  • Web, Network & System Penetration Testing
  • Threat Modeling & Risk Analysis
  • OWASP Top 10 (Web, API)
  • Linux Hardening & Secure Configurations
  • Docker & Kubernetes Security
  • CI/CD Security Pipelines
  • Cloud Security Fundamentals

Tools: Nmap Β· Burp Suite Β· Metasploit Β· Wireshark Β· Linux


πŸ–₯️ Backend & Systems

  • Secure REST API design
  • Authentication & Authorization models
  • Role-based & policy-based access control
  • Secure data handling & validation
  • Microservices security concerns
  • High-risk input & boundary defense

Languages: Python Β· Java Β· Node.js Β· Go Β· C / C++ Β· Bash


☁️ Cloud & Databases

  • Cloud threat models (AWS / Azure / GCP)
  • IAM & permission boundaries
  • Secure storage & secrets handling

Databases: PostgreSQL Β· MySQL Β· MongoDB Β· Redis


πŸ€– AI & Security

  • ML-assisted malware detection concepts
  • Adversarial attack surfaces in AI systems
  • Securing AI pipelines & data flows
  • Understanding how AI changes threat models

Libraries: TensorFlow Β· PyTorch Β· Scikit-learn Β· Pandas Β· NumPy


πŸ” What I’m Actively Working On

  • Advanced penetration testing methodologies
  • Malware behavior & analysis fundamentals
  • Secure system design under adversarial conditions
  • AI + Cybersecurity intersections
  • Turning exploits into engineering rules

πŸ“Š GitHub Activity


πŸ“ˆ GitHub Contribution Graph

Suman Kumar GitHub Contribution Graph


🐍 Contribution Activity

Contribution Snake

🌐 Writing & Knowledge Sharing

  • Cybersecurity fundamentals
  • Exploit breakdowns
  • Secure architecture concepts
  • AI security risks & design lessons

(Actively expanding technical writing)


πŸ”— Connect With Me


🧠 Philosophy

Attackers think in possibilities.
Defenders think in guarantees.
I train myself to think like both.

Secure systems aren’t built by fear β€”
they’re built by understanding failure.

Pinned Loading

  1. openclaw openclaw Public

    Forked from openclaw/openclaw

    Your own personal AI assistant. Any OS. Any Platform. The lobster way. 🦞

    TypeScript 1

  2. SecureVault SecureVault Public

    1

  3. CyberShield CyberShield Public

    TypeScript 1

  4. Blockchain- Blockchain- Public

    JavaScript 1

  5. EncryPtion-Secure EncryPtion-Secure Public

    TypeScript 1

  6. KavachSecurity KavachSecurity Public

    1