ruben@secops:~$
Ruben Abraham Shibu

ruben@secops:~$ whoami

Ruben Abraham Shibu

Security Engineer
Offensive Security · AppSec · Cloud Security · AI Security

I break things on purpose so they don't break for real. CEHv11-certified, with 3+ years spent moving between the attacker's seat and the defender's — pentesting web, mobile and network targets by day, and picking apart how AI systems fail by night. I like the moment a "secure" system turns out not to be, and I like explaining why in a way a developer can actually act on. Off the clock, I'm usually organizing something for IEEE or arguing that the internet needs more cyber hygiene awareness, not less.

CEHv11 VAPT SAST IAST SCA SecOps LLM Cloud

ruben@secops:~$ cat focus.log

What I Work On

01 · APPSEC

Application Security

Web, API, mobile and network penetration testing end to end — plus secure code review, IAST, DAST and SCA across the SDLC so findings get fixed, not just filed.

02 · AI / ML

AI Pentesting

Probing LLM-backed apps and AI pipelines for prompt injection, data leakage and the new class of failure modes that traditional AppSec testing misses.

03 · CLOUD

Cloud Security

Cloud configuration reviews and cloud security testing to catch misconfigurations and excess privilege before attackers do.

04 · COMPLIANCE

Security Compliance & SecOps

Embedding security operations and compliance checks into CI/CD pipelines, so secure practices scale with the team instead of bottlenecking it.

05 · RESEARCH

Security Research

Digging into emerging attack techniques, writing up findings, and contributing to the wider community through IEEE and Cyberdome.

ruben@secops:~$ cat experience.log

Experience

OCT 2025 — PRESENT

Consultant, Offensive Security Services — Ultraviolet Cyber, Bangalore

  • End-to-end web, Android and network penetration testing, plus REST/SOAP API security assessments
  • Mobile app testing covering auth, insecure storage and communication flaws
  • SAST/IAST/SCA across Java, Python, TS, JS, C#, C++ using Checkmarx, Seeker and Black Duck
  • Advisor on secure coding, threat modeling and vulnerability management for enterprise clients
OCT 2024 — OCT 2025

Cyber Security Consultant — BlackDuck, Bangalore

  • Web, mobile and network penetration testing using Burp Suite, ZAP and standard frameworks
  • Embedded security into Secure SDLC / CI-CD pipelines, remediating automated tool findings
  • Delivered SCA with Black Duck and CheckmarxOne for open-source risk and license compliance
JUL 2022 — OCT 2024

Cyber Security Consultant — Synopsys, Bangalore

  • Web application and network penetration testing, internal and external
  • Secure code review and SAST across multiple languages, manual and tool-assisted
  • IAST with Seeker and SCA with Black Duck / CheckmarxOne

ruben@secops:~$ ls skills/

Skills

OFFENSIVE / TESTING

Burp SuiteZAPMobSF NMAPNessusKali Linux VAPTNetwork Pentesting

APPSEC / DEVSECOPS

SASTDASTIAST — Seeker SCA — Black DuckCheckmarx / CheckmarxOne Secure Code ReviewSecOps

CLOUD / AI / COMPLIANCE

Cloud Security TestingCloud Config Review AI/ML Security TestingAI-Assisted Pentesting Security Compliance

LANGUAGES

PythonJavaC / C# JavaScriptTypeScript

PRACTICE

Vulnerability RemediationCompliance Threat ModelingPublic Speaking

ruben@secops:~$ cat education.log volunteering.log

Education & Involvement

  • B.Tech, Computer Science — APJ Abdul Kalam Technological University2022
  • Chair, IEEE Future Networks — Kerala Section2025 —
  • Treasurer, IEEE ComSoc Kerala Chapter2023 —
  • Student Cadet, Kerala Police Cyberdome2019 —

ruben@secops:~$ mail --contact

Contact

LINKEDIN
GITHUB
LOCATION
Kerala, India

ruben@secops:~$