Skip to content
View iam-niranjan's full-sized avatar
:octocat:
Building secure systems with automation and coffee
:octocat:
Building secure systems with automation and coffee

Block or report iam-niranjan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
iam-niranjan/README.md

Hey, I'm Niranjan Ganesan 👋

Security Leader · Cloud Security · Vulnerability Research · Governance · AI Security

Research Interests

• Vulnerability Research
• Application Security
• Cloud Security
• AI and Agent Security
• Open Source Security
• Security Automation
• Responsible Disclosure
• Security Governance and Compliance

Security Contributions

Security Advisories & Vulnerability Research

GHSA r7w7 vpq8 c5vv | mail-parser polynomial ReDoS in email header parsing | Package Usage 3.2M+ PyPI downloads/month

GHSA fr3h cpq2 9496 | mail-parser path traversal vulnerability in attachment extraction | Package Usage 3.2M+ PyPI downloads/month

GHSA 78xv 5vfh jh5q | mail-parser denial of service via attacker controlled header names | Package Usage 3.2M+ PyPI downloads/month

GHSA 72px j8gh p79x | mail-parser sender IP address spoofing in get_server_ipaddress() | Package Usage 3.2M+ PyPI downloads/month

GHSA 24mq 4vc6 2prf | mail-parser uncaught exceptions and silent header loss on attacker controlled input | Package Usage 3.2M+ PyPI downloads/month

GHSA-2jj6-v3xw-49w3 | Server-Side Template Injection / sandbox escape in liquidpy leads to arbitrary code execution | Package Usage 317K+ PyPI downloads/month

fastjsonschema Security Fix | fastjsonschema code injection via unescaped property name in generated Python validator leads to arbitrary code execution | Fixed in 2.22.2 | Package Usage 138M+ PyPI downloads/month

Selected Publications

CCSK Success Story: From an IT and Cloud Security Manager · Cloud Security Alliance, 2022 · Read

Certifications

AI Governance & Threat Intelligence
ISO 42001:2023 Lead Auditor · Certified ATT&CK Cyber Threat Intelligence · Certified ATT&CK Security Operations Center Assessments

Governance, Risk & Audit
CISA · CISM · CRISC · CGEIT · CCISO · Certified GCHQ Cyber Incident Planning & Response (CIPR)

Privacy
CDPSE · CIPT · Privacy Engineering Certification

Cloud Security
AWS Certified Security Specialty · AWS Certified Solutions Architect Associate · CCSK · CCZT · Certified Advanced Cloud Security Auditing (CSA STAR)

ISO Standards
ISO 27001:2022 Lead Auditor · ISO 27001:2013 Lead Auditor

Technical & Practitioner
CompTIA Security+ · CompTIA PenTest+ · CompTIA Network Vulnerability Assessment Professional · Redis Security · VMware Certified Associate Data Center Virtualization

Service Management & Agile
ITIL v4 Foundation · Certified Scrum Master · Certified Agile Leader 1 · Certified Agile Leadership Essentials (CAL E) · Certified Agile Leadership for Teams (CAL T) · Certified Agile Leadership for Orgs (CAL O) · Cyber Supply Chain Management

Verified Credentials

Credly Accredible

Contact

Portfolio LinkedIn

Pinned Loading

  1. docdrop docdrop Public

    Drop a document. Get clean Markdown. No AI, no account, no history.

    JavaScript 1

  2. wcag-skills wcag-skills Public

    Turn the official WCAG 2.2 accessibility guidelines into verified SKILL.md files, with independent validation.

    Python

  3. slack-n8n-integration-hub slack-n8n-integration-hub Public

    JavaScript 3 2

  4. Vendor-Security-Assessment-Questionnaire-Generator Vendor-Security-Assessment-Questionnaire-Generator Public

    Vendor Security Assessment Questionnaire Generator

    JavaScript