Get in touch
Currently open to security engineering and DevSecOps roles. Also happy to talk about a detection problem that's been bothering you, or an OT environment nobody has ever put a sensor in.
Every email gets a reply within two working days. Usually the same day. Vulnerability reports on any of the projects are acknowledged within 72 hours. If you don't hear back inside that window, assume the mail went astray and send it again. Silence here is a failure, not an answer.
CHANNELS
Best for anything substantive. I read everything and reply to most of it.
Issues and pull requests on any of the projects. Bug reports especially welcome. I would rather hear it from you than from a stranger in production.
For recruiters and anything role-shaped.
Paid consulting: custom detection rules, SIEM tuning, or an MCP server built for your stack.
QUESTIONS I GET ASKED
What kind of role are you looking for?
Network security and detection engineering: protocol and VPN internals, SIEM work, OT/ICS security, and the infrastructure underneath all three. The day job is infrastructure-heavy: RKE2 Kubernetes on bare hypervisors, Terraform, Ansible. The open-source work is detection-heavy: 79 rules and an MCP server for Wazuh. Roles that touch both are the ones I want most.
Are you open to relocating?
Yes. I am in Bengaluru and work on IST (UTC+5:30). Japan is the medium-term aim and I am studying towards the JLPT, but I am open to relocation or visa sponsorship anywhere the work is interesting. Remote also works where the time-zone overlap with your team is workable.
Do you take freelance or consulting work?
Yes. Custom detection rules, SIEM tuning, and MCP servers built for a specific stack. Topmate is the fastest way to book a call. For anything larger than a call, email is better, and I will send scope and pricing before any work starts.
How quickly will you reply?
Within two working days for anything sent to email, and usually the same day. Vulnerability reports on any of the projects are acknowledged within 72 hours. If I have not replied inside that window, the mail went astray. Send it again rather than assuming disinterest.
Can I deploy your detection rules in production?
The licences say yes: MIT for sb-siem-mcp, Apache 2.0 for both rule packs. Read the scope and limits on each project page first. OT Sentinel is hardware-validated for Modbus only, its CDB allowlists ship empty by design, and nothing in it should reach a live plant without testing on your own hardware and tuning to your own traffic.
More detail on the projects those answers refer to lives in the work, and the reasoning behind them in the words.
A NOTE ON FORMS
There isn't a contact form here, and that's deliberate. This site is static HTML with no backend, so a form would mean handing your message to a third-party service that neither of us needs in the loop. Email works, and it lands in a place I actually check.
SECURITY REPORTS
Found something in one of the projects? Email me directly rather than opening a public issue, and I'll acknowledge within 72 hours. sb-siem-mcp has a full disclosure policy in docs/SECURITY.md.