Experience
-
Jan 2026 to Present
Security Engineer · Saint-Gobain INDEC (Grindwell Norton Limited)
Mumbai, India
Vulnerability validation, exploitability analysis and risk assessment of emerging threats across enterprise infrastructure, cloud and business-critical applications. Runs attack surface management end to end, and operationalises newly disclosed CVEs into advisories the infrastructure, cloud and application teams can act on.
-
Apr 2024 to Jan 2026
Cyber Security Consultant · Security Brigade Infosec Pvt Ltd
Mumbai, India
Owned security assessment operations for the Mahindra & Mahindra Group across national and international subsidiaries: internal and external network testing, red-team retesting to verify mitigations, and advanced evasion work to measure EDR coverage and improve SOC detection.
-
Dec 2022 to Apr 2024
Security Researcher · Security Brigade Infosec Pvt Ltd
Mumbai, India
VAPT across Mahindra & Mahindra subsidiaries, dark web and breach monitoring for exposed credentials, and working alongside development teams through the patching cycle to closure.
-
May 2022 to Oct 2022
Cyber Security Trainer · Encryptic Security Pvt Ltd
Mumbai, India
Taught batches of 20+ students, from networking and common web attacks through to SSRF and XXE, with hands-on exploitation exercises throughout.
What I do
- Red teaming
- Internal & external network penetration testing
- Active Directory attack paths
- Privilege escalation
- EDR evasion
- Social engineering
- Web application testing
- API security testing
- Mobile application testing (Android/iOS)
- Source-assisted review
- OWASP Top 10 / ASVS
- BloodHound
- Impacket
- Certipy
- NetExec / CrackMapExec
- Burp Suite
- Metasploit
- Nessus
- Nmap
- Ligolo-ng
- Responder
- Python
- Bash
- PowerShell
- Attack surface management
- Vulnerability intelligence
Certifications
8Offensive Security · 2025
Offensive Security · 2025
Altered Security · 2025
SecOps Group · 2024
EC-Council · 2022
eLearnSecurity / INE · 2022
SecOps Group · 2023
SecOps Group · 2023
Security acknowledgements
11 organisationsOrganisations that have credited me for responsibly disclosed vulnerabilities.
Education
Lovely Professional University · Pursuing
Institute of Business Studies & Research, Navi Mumbai · 2021
Writeups
47 Proving Grounds boxes documented end to end: 17 Windows, 25 Linux and 5 Active Directory.
Frequently asked
Who is Nitesh Gupta?
Nitesh Gupta is a cyber security consultant and red teamer based in Mumbai, India. He works on Active Directory attack paths, network and application penetration testing, and enterprise security assessments, and holds the OSCP, OSCP+ and CRTP certifications.
What does Nitesh Gupta specialise in?
Red teaming and Active Directory security in particular: Kerberos attacks, ACL and ADCS abuse, lateral movement and domain escalation, alongside web, mobile and API penetration testing.
What certifications does Nitesh Gupta hold?
OSCP, OSCP+, CRTP, CNPen, CEH, eJPT, CAP and CNSP.
Is Nitesh Gupta available for security consulting?
Yes. He takes on penetration testing, red team and Active Directory security assessment work. The fastest way to reach him is by email at [email protected] or through LinkedIn.
Where can I read Nitesh Gupta's security writeups?
All 47 Offensive Security Proving Grounds walkthroughs are published at niteshgupta.com/writeups/, covering Windows, Linux and Active Directory boxes.
Get in touch
Open to penetration testing, red team and Active Directory security assessment work.