Skip to content
Hem GabhawalaEmail

Available now for security internships & part-time roles

I break systems to understand them, then build what stops them breaking.

Cybersecurity engineer. Offensive security and VAPT by training, moving into governance, risk & compliance and AI security.

TryHackMe, globally
Top 2%

TryHackMe, globally

Hands-on labs
175+

Hands-on labs

Security platforms built
3

Security platforms built

Live VAPT internship
1

Live VAPT internship

Email me

Offensive instinct, turned into preventive design.

Break

I started in offensive security. A VAPT internship at HackersVilla Cybersecurity — live vulnerability assessments, penetration testing and network reconnaissance against real systems, with remediation reports engineering teams acted on. Alongside it, 175+ TryHackMe labs through privilege escalation, Active Directory and OWASP web exploitation, to the top 2% globally.

Understand

That work trains a specific instinct: not just where a vulnerability is, but why it matters and what it costs. Most people entering GRC or AI security arrive from compliance frameworks or machine learning. I arrived from watching systems actually fail.

Build

So I build the other side of it. Dharma treats compliance as an engineering problem — evidence mapped to controls by a local AI model that never sends data off-site, hash-chained so no record can be quietly edited. VaultIQ starts from the position that AI security is architecture, not filters: files are encrypted in the browser, and the model that scans them for AI-generated content is one I trained and measured at 98.3% accuracy.

You can't govern risk you've never actually seen exploited. I've seen it. Now I want to build the systems that prevent it.

Aug 2023
Started B.Tech, Computer Science (Cybersecurity)

Enrolled at Navrachana University, Vadodara — chose the cybersecurity specialization deliberately, not by default.

Mar 2024
VAPT Intern at HackersVilla Cybersecurity

Live vulnerability assessments, penetration testing, and network reconnaissance on real systems — writing remediation reports engineering teams acted on.

Three systems, built end to end.

Two turn offensive knowledge into preventive architecture. The third is the offensive work they came from.

Dharma

Next.js · tRPC · PostgreSQL + pgvector · Ollama (local LLM) · MinIO · Docker

Private repository — walkthrough available on request

Runs on local AI — sensitive data never leaves the org

Compliance that can prove no one tampered with the evidence.

Multi-container platform (Next.js, tRPC, PostgreSQL + pgvector, MinIO, Redis/BullMQ) that maps evidence to controls with a local Ollama model, so documents never touch a public AI API. Evidence is hash-chained — alter one record and the signature chain breaks — with multi-tenant workspaces and Stripe billing in development.

VaultIQ

React 19 · Python / FastAPI · Apache Spark · AWS S3 · AES-256

View source

98.3% AI-content detection · ROC-AUC 0.997

Encrypt documents in the browser, then catch AI-written submissions with 98% accuracy.

React 19 / Node / Python-FastAPI platform on AWS S3. Files are AES-256 encrypted in the browser with SHA-256 integrity checks; a hybrid detector — fine-tuned RoBERTa plus a calibrated logistic-regression model over 20 linguistic features — flags AI-generated text from GPT-4, Claude and Gemini, with Apache Spark running the analytics.

Network Reconnaissance Tool

Python · Nmap · Sockets

View source

Offensive tooling — the practice behind the defensive work

The reconnaissance phase of a real engagement, scripted.

Python wrapping Nmap for TCP/UDP port discovery, with DNS resolution and traceroute mapping, exposed as quick and full scan modes that emit one consolidated report.

More projects on GitHub

What I can do, and where it is heading.

Not a list of tools. The offensive base is where I started; GRC and AI security are where it is going; the engineering underneath is what lets me build these systems rather than only test them.

Capability arc: offensive security is the base, and it feeds upward into two directions — GRC and AI security. All three stand on a substrate of software engineering and cloud infrastructure.

Where I started — VAPT & Offensive Security

  • Vulnerability Assessment & Penetration TestingLive engagements at HackersVilla Cybersecurity
  • Network ReconnaissanceEnumeration, service/version mapping, attack-surface discovery
  • OWASP Web & API ExploitationOWASP Top 10 / API Top 10
  • Privilege Escalation & Active DirectoryLinux/Windows privesc, AD compromise
  • Remediation ReportingActionable findings engineers can act on

Tools I've used to find what needed governing

  • Burp Suite
  • Nmap
  • Metasploit
  • Wireshark
  • Postman
feeds into

Where I'm heading — GRC

  • Risk Management
  • Compliance Automation
  • Audit-Trail Integrity
  • Cryptographic Evidence Logging
  • Governance Frameworks
  • Incident Response

Where I'm heading — AI Security

  • Secure AI System Design
  • Client-Side Encryption (AES-256)
  • AES-256 Encryption
  • AI/ML Foundations (AWS Academy)
  • Data-Pipeline Security
all three stand on

The engineering underneath all three

  • Python
  • Java
  • SQL
  • FastAPI
  • Flask
  • REST APIs
  • PostgreSQL / MySQL
  • Git & GitHub

Cloud & infrastructure

  • AWS
  • Docker & Containerization
  • Linux/Unix Administration

Certifications

  • AWS Academy — Machine Learning Foundations

    AWS Academy

    View2026
  • AWS Academy — Data Engineering

    AWS Academy

    View2026
  • Google Cybersecurity Professional Certificate

    Google / Coursera

    View2024
  • Information Security Education and Awareness (ISEA)

    CDAC / MeitY

    View2024

TryHackMe paths completed

  • Web Application Pentesting

    TryHackMe

    View2025
  • Offensive Pentesting

    TryHackMe

    View2025
  • Jr Penetration Tester

    TryHackMe

    View2025
  • Web Fundamentals

    TryHackMe

    View2025
  • Cyber Security 101

    TryHackMe

    View2025
  • Pre Security

    TryHackMe

    View2024

Open to security roles.

Available now for internships and part-time roles, remote or on-site. A direct email is the fastest way to reach me — I reply to every one.

hemgabhawala@icloud.com
Vadodara, Gujarat, India