NBNirmala NB

Nirmala NB

Cyber Security Engineer

Security sign-off at Emirates NBD, Dubai. Studying for the OSCP in the evenings.

I find the holes in banking software before someone else does. Four years in banking, from network and firewall governance to application, API and vulnerability testing. I embed security into the full delivery lifecycle, working with development, risk, storage and infrastructure teams, and give the go/no-go on code, pipelines and releases. Lately that includes security-testing LLM integrations before they ship.

Experience

Security Assessorpresent

Apr 2026 — Present

Emirates NBD, Dubai

  • Review firewall change requests (port, service, protocol, source, destination, justification) on least-privilege and segmentation principles, assess wireless requests, and troubleshoot Linux and infrastructure issues across pre-production and production.
  • Assess banking applications end to end — container and proxy through the BFF to core services — covering API security (authentication, authorization, data exposure, input validation) and the internal API gateways routing traffic across the organization.
  • Perform application security testing and secure code review with development and risk teams, review CI/CD pipeline changes, code and dependency upgrades, and give the security sign-off on code, pipelines and releases before go-live.
Show 3 more
  • Review Kafka topics for access control, data sensitivity and secure transport; cover the database lifecycle through encryption at rest and in transit; define secrets management rules and check storage configurations against baselines with the storage team.
  • Review third-party integrations for data flow, API exposure and vendor risk, security-test LLMs before AI integration, analyze organization-level AI risk (data leakage, prompt injection, model misuse) and run package and malware analysis.
  • Run pre-production security reviews against the bank baseline, verify ELK logging and monitoring, confirm scans are remediated or risk-accepted, and give the final go-live sign-off; investigate P1 incidents, support hotfixes and document on Confluence.

Lead Security Analyst

Dec 2025 — Apr 2026

ActivGreen, Trivandrum

  • Led vulnerability assessments and penetration tests across enterprise applications, infrastructure and networks, including onsite engagements in Dubai, and assessed networks with Nmap, Nessus and Nexpose.
  • Triaged application security incidents with development teams, traced root cause, pushed WAF rule updates to prevent repeat attempts, scored findings by CVSS and validated the fixes.
  • Tested Android and iOS apps and Android SDKs for insecure storage, session handling and certificate pinning, reviewed third-party vendor data flows and assessed AWS, Azure and GCP for misconfigurations.

Security Consultant

Mar 2023 — Nov 2025

Activ Bytes, Trivandrum

  • Ran manual penetration tests on web and API systems and found 50+ critical and high-risk issues including authentication bypass, IDOR and RCE, mapped to OWASP Top 10 and the API Security Top 10.
  • Performed secure code review, CI/CD pipeline reviews and threat modeling with development teams, finding security loopholes early and driving remediation before release.
  • Security-tested LLM-backed features and reviewed AI integrations for prompt injection and data leakage risk, verifying authentication, storage and transport findings from MobSF APK scans.
Show 1 more
  • Wrote risk-based reports covering business impact, CVSS severity, remediation and validation, and ran purple team engagements onsite in Abu Dhabi with SOC detection and response teams.

VAPT Executive

Aug 2022 — Feb 2023

SIDR Solutions, Mumbai

  • Performed vulnerability assessments and penetration tests for enterprise clients, including ATM security testing with hard disk imaging and malware analysis.

Skills

Application & API Security
OWASP Top 10 · OWASP API Security Top 10 · OWASP LLM Top 10 · SAST · DAST · SCA · Secure code review · Security design review · Threat modeling · API gateway security · CVSS scoring · Mobile application security
Infrastructure, Cloud & Data Security
VM & server hardening · Firewall & segmentation review · Least privilege · CI/CD security · Container security · Secrets management · Encryption at rest & in transit · Kafka security · Linux
Governance, Risk & Response
Secure SDLC · DevSecOps · Third-party & vendor risk · AI/LLM security · Change management · Incident response · Incident triage & root-cause analysis · Malware analysis · AWS, Azure & GCP assessment · Android & iOS application testing
Frameworks, Tools & Scripting
MITRE ATT&CK · PTES · Burp Suite · MobSF · Nessus · Nexpose · Nmap · Checkmarx · DB Compass · Sysdig · LogRhythm · Darktrace · FTK Imager · Python · Bash

Education & certifications

Bachelor of Engineering — Visvesvaraya Technological University, India

2022

Certifications

  • CEH (in progress, expected 2026)
  • OSCP (in preparation)

Languages

English (fluent) · Malayalam (native) · Kannada (native) · Hindi (conversational)