Open to full-time & contract·From Q4 2026 · Durgapur, IST

Tanisha Brahma

SOC analyst · Detection engineering · Applied cryptography

  • 912 detections shipped
  • 11 credited CVEs
  • 3h 14m fastest containment

Work

Four case studies: detection engineering, incident response, post-quantum migration and a custodial wallet audit.

Sentinel Grid

Detection-as-code for a 40,000 EPS estate: 912 hand-edited correlation rules rebuilt as version-controlled Sigma, every change gated behind telemetry-backed unit tests, alert queue cut by two thirds without losing a true positive.

SigmaPythonSplunk ESCI
001

Blackout

Nine hours from first alert to eradication. A build server started signing artefacts it had not built — a stolen signing key used from another network. The timeline of that night and what it changed.

Incident responseCode signingHSMForensics
002

Lattice

Hybrid X25519 + ML-KEM across a payments fabric — post-quantum key exchange with no flag day. Both schemes ran in parallel for two quarters, and every millisecond of the cost was measured.

RustliboqsBoringSSLML-KEM-768
003

Redline

Breaking a custodial wallet before someone else did: a four-week assessment that recovered a signing key from a memory dump, then again from a timing side channel — and the remediation written with the team that fixed it.

Key managementECDSATiming analysisHSM
004

About

SOC analyst turned detection lead, now independent, writing production cryptography from Durgapur.

// Brief@Junecoderr

I catch intrusions for a living and write the cryptography that makes them expensive. Somewhere between a noisy alert queue and too much curiosity, good detections tend to happen.

06Years in security
11Credited CVEs
23Incidents led
912Detections shipped
┌┐└┘Tanisha Brahma

Experience

Six years across an enterprise SOC and independent practice.

Independent Practice

Detection Engineering & Applied Cryptography

Jul 2024 — Present
  • Rebuilt a tier-1 payments processor's SOC ruleset as version-controlled Sigma — 912 rules migrated, false positives down 68% without losing a single true positive.
  • Led incident response for a supply-chain signing-key compromise: containment in 3h 14m, 2,481 artefacts revoked, zero downstream impact.
  • Shipped a hybrid X25519 + ML-KEM-768 handshake across 4,900 payment endpoints with 1.8ms mean overhead and zero downtime.
  • Maintain Cryptkit, an open-source constant-time primitives library — 41k downloads a month, 23 contributors, timing tests that fail the build in CI.
SigmaRustPythonSplunk ESliboqsProVerif
Enterprise SOC

Tier-2 Analyst → Detection Lead

2020 — Jul 2024
  • Started on a tier-two console triaging endpoint alerts; moved into detection engineering when it became clear the rules were the product, not the console.
  • Led 23 incidents from first alert through post-mortem — containment first, attribution last, and a write-up that names the control that failed.
  • Learned cryptography by necessity: half the incidents traced back to a primitive used wrongly — a nonce reused, a key stored beside its data, a comparison that leaked timing.
Splunk ESSigmaPythonMITRE ATT&CK

Recognition

Certifications, credited CVEs, talks and papers.

Certifications

  • OSCPOffensive Security Certified Professional2021
  • GXPNGIAC Exploit Researcher and Advanced Penetration Tester2023
  • CISSPCertified Information Systems Security Professional2024
  • CKSCertified Kubernetes Security Specialist2025

CVE credits

  • CVE-2025-41802Session inheritance across resumption in a TLS terminatorCVSS 8.6
  • CVE-2024-33917Certificate chain validation bypass on renegotiationCVSS 7.4
  • CVE-2024-28450Nonce reuse in an AEAD wrapper under key rotationCVSS 6.8
  • CVE-2023-51166Timing disclosure in ECDSA scalar multiplicationCVSS 5.9

Talks & papers

  • Nullcon GoaDetections are a codebase, not a console2026
  • Real World CryptoShipping hybrid post-quantum without a flag day2026
  • BSides BangaloreNine hours: anatomy of a signing key compromise2025
  • IACR ePrintA symbolic model for identity-hiding Noise variants2024

Skills

Detection tooling, cryptographic primitives and the languages they ship in.

Detection & response

  • Sigmacore
  • Splunk ES / SPLcore
  • MITRE ATT&CKcore
  • Detection-as-codecore
  • Telemetry pipelines
  • Incident responsecore
  • Threat hunting
  • Post-mortems

Cryptography

  • X25519core
  • ML-KEM-768core
  • AEAD constructionscore
  • Noise protocol
  • Constant-time codecore
  • Lattice attacks
  • liboqs
  • BoringSSL
  • dudect

Languages & tooling

  • Rustcore
  • Pythoncore
  • Go (reading)
  • ProVerifcore
  • Git / GitHub
  • HSM integration
  • CI/CD
  • PGP · Ed25519
  • criterion
  • 90-day disclosure

core used in production in the last twelve months.

Contact

Email is fastest. Encrypted mail welcome; the PGP fingerprint is below.

let's talk

Fastest routetanishabrahma26@gmail.com
Replies within two working days.
Or draft it here
STEP 01 / 04
Tanisha Brahma
PGP 9F2C 47AD 10B8 6E31 D4A9 2C05 88FE 7B14 A3D6 0E92Durgapur, India