Cyber ops background
COO · Offensive Security · GRC · Cloud

SHAKTI PRASAD MAHAPATRO

— Securing the Digital Frontier

COO Aexantis Technologies Pvt. Ltd.
Head Instructor Hackify Cybertech · Bhubaneswar
CEH Jr Pen Tester SOC 2 ISO 27001 HIPAA GDPR PCIDSS
5+
Years in Cyber
5
Organisations
CEH
Certified
COO
Executive
shakti@aexantis ~ threat-recon
$whoami
shakti_prasad_mahapatro
$cat roles.txt
COO @ Aexantis Technologies
Head Instructor @ Hackify Cybertech
$ls certifications/
CEH   GCIA   Jr-Pen-Tester
SOC2   ISO27001   HIPAA   GDPR
$nmap --specialties
Offensive Security   GRC   VAPT
Cloud Security   IAM   Risk Advisory
$ping aexantis.tech
ACTIVE — 0ms latency
$_
01
About
Shakti Prasad Mahapatro
COO
Aexantis Technologies
"A seasoned professional specializing in penetration testing and security analysis — with a relentless drive to safeguard digital assets."

As Chief Operating Officer at Aexantis Technologies, I lead the strategy, execution, and delivery of integrated Cybersecurity, AI, and Data Analytics services for organizations operating in regulated, data-driven, and high-growth environments.

My two-year deep dive into offensive security testing has given me an attacker's mindset and a defender's discipline. From conducting comprehensive network scans with Nmap to simulating real-world cyberattacks with Metasploit, I've built invaluable insight into the tactics employed by malicious actors — and how to stop them.

As Head Instructor at Hackify Cybertech, I transform that field experience into industry-ready talent, building the next generation of cybersecurity professionals.

Arsenal / Tools
Nmap Metasploit Burp Suite BeEF Wireshark OWASP ZAP Kali Linux Nessus OpenVAS Nikto Gobuster SQLmap Hydra John the Ripper BloodHound MobSF Wazuh
Location
Bhubaneswar, Odisha, India
Contact
shaktiprasad24675@gmail.com
Specialisation
Offensive Security · GRC
Status
Open to Opportunities
02
Expertise
CORE DOMAINS
Three operational pillars. Zero compromise.
01
⚔
OFFENSIVE SECURITY
Expert penetration tester with hands-on experience conducting comprehensive VAPT across networks, applications, and cloud environments. Proficient in simulating advanced persistent threats, red team operations, and social engineering scenarios using industry-leading toolkits. Certified Ethical Hacker with a proven track record of identifying critical vulnerabilities before adversaries do.
Pen TestingVAPTRed TeamExploit DevRecon
02
🛡
GRC & COMPLIANCE
Deep expertise in governance, risk, and compliance frameworks including SOC 2, ISO 27001, HIPAA, GDPR, and PCIDSS. Advising regulated enterprises on aligning security posture with business objectives, building compliance roadmaps, and managing audit readiness. Bridging the gap between technical controls and executive-level risk communication.
SOC 2ISO 27001HIPAAGDPRPCIDSS
03
☁
CLOUD & IAM SECURITY
Specialized in cloud security architecture for regulated enterprises, identity and access management (IAM) strategy, and continuous security validation. Experience from TCS cybersecurity consulting — delivering IAM frameworks, strategic security alignment, and complex technical documentation. Ensuring cloud-native environments maintain compliance without sacrificing velocity.
Cloud SecurityIAMZero TrustCSPMDevSecOps
03
Experience
OPS RECORD
Field deployments across industry frontlines
2025
Nov
Present
Current · COO
CHIEF OPERATING OFFICER
Aexantis Technologies Pvt. Ltd. · Ghaziabad
Leading the strategy, execution, and delivery of integrated Cybersecurity, AI, and Data Analytics services for organizations operating in regulated, data-driven, and high-growth environments. Responsible for operational architecture, cross-functional team leadership, and client-facing security program design. Driving the company's growth trajectory while maintaining uncompromising technical standards.
Cybersecurity ServicesAI IntegrationData AnalyticsOperations LeadershipClient Strategy
2025
Oct
Present
Concurrent · Instructor
HEAD INSTRUCTOR
Hackify Cybertech · Bhubaneswar
Leading training and education operations focused on building industry-ready cybersecurity and technology talent. Designing curricula that bridge offensive and defensive security, mentoring the next generation of professionals, and establishing Hackify as a premier cybersecurity training institution in Odisha.
Curriculum DesignMentoringOffensive Security TrainingLab Development
2025
Aug–Oct
3 months
Sr. Executive
SR. EXECUTIVE — CYBERSECURITY & IT COMPLIANCE
Anmol Industries Limited · Kolkata, West Bengal
Blended offensive security (VAPT, threat detection) with defensive strategies (compliance, governance) to maintain a resilient cybersecurity posture for a large industrial enterprise. Managed IT compliance initiatives across regulatory frameworks while conducting regular penetration tests and vulnerability assessments.
VAPTThreat DetectionIT ComplianceGovernance
2024
Dec–Aug
9 months
IT Specialist
IT SPECIALIST
SBI General Insurance · Odisha, India
Provided IT security specialist support within one of India's leading general insurance companies, ensuring systems integrity, regulatory compliance, and continuous security monitoring across critical financial infrastructure in a highly regulated BFSI environment.
BFSI SecuritySystems IntegrityRegulatory ComplianceSecurity Monitoring
2023
Dec–Jun
7 months
Analyst
CYBER SECURITY ANALYST
Tata Consultancy Services · India
Completed a job simulation involving identity and access management (IAM) for TCS, collaborating with a Cybersecurity Consulting team. Acquired expertise in IAM principles, cybersecurity best practices, and strategic alignment with business objectives. Delivered comprehensive documentation and presentations showcasing the ability to communicate complex technical concepts effectively to executive stakeholders.
IAMSecurity ConsultingDocumentationExecutive PresentationBest Practices
04
Projects
Cybersecurity Expertise Across 17+ Security Domains
Covering Vulnerability Assessment & Penetration Testing (VAPT), Security Operations Center (SOC), ISO 27001, Governance Risk & Compliance (GRC), Cloud Security, Identity & Access Management (IAM), Incident Response, Privacy, Security Awareness, and Executive Risk Advisory.
Web Application VAPT
OWASP TOP 10 SECURITY ASSESSMENT

End-to-end web application penetration test covering authentication flaws, access-control gaps, injection paths, session weaknesses, and business logic abuse. Delivered proof-of-concept evidence with remediation priority.

Burp SuiteOWASP ZAPSQLmapNikto
Network Penetration Testing
ENTERPRISE NETWORK ATTACK SURFACE REVIEW

Mapped live hosts, exposed services, weak configurations, credential risks, and lateral-movement opportunities across an internal lab environment using a structured discovery-to-validation workflow.

NmapNessusMetasploitWireshark
Active Directory Security
AD PRIVILEGE ESCALATION LAB

Simulated common Active Directory attack paths, misconfigured permissions, weak password hygiene, exposed shares, and privilege escalation chains with clear hardening controls for identity security.

BloodHoundCrackMapExecImpacketJohn
Cloud & IAM Review
CLOUD MISCONFIGURATION AUDIT

Reviewed identity permissions, storage exposure, logging gaps, and policy weaknesses against secure cloud architecture principles, translating technical findings into board-level risk language.

IAMCSPMZero TrustPolicy Review
Ethical Hacking Methodology
REAL-WORLD ATTACK SIMULATION PIPELINE

A portfolio-ready red-team style workflow that demonstrates disciplined scoping, reconnaissance, vulnerability validation, exploit safety, post-exploitation documentation, and clean remediation reporting.

PTESMITRE ATT&CKOSINTRisk Report
01Reconnaissance
02Enumeration
03Validation
04Remediation
ISO 27001 Implementation
ISMS READINESS & CONTROL MAPPING

Built an ISO 27001-aligned ISMS roadmap covering asset inventory, risk treatment, Annex A control mapping, policy structure, evidence tracking, and internal audit preparation.

ISO 27001Annex ARisk TreatmentAudit Evidence
Compliance Program
MULTI-FRAMEWORK COMPLIANCE MATRIX

Created a unified control matrix to map SOC 2, ISO 27001, HIPAA, GDPR, and PCI DSS requirements into one practical governance and evidence-management workflow.

SOC 2HIPAAGDPRPCI DSS
SOC Operations
SIEM DETECTION & ALERT TRIAGE LAB

Designed SOC workflows for log ingestion, alert enrichment, incident classification, escalation paths, and repeatable detection engineering for suspicious authentication and endpoint activity.

WazuhSplunkSigmaMITRE ATT&CK
Threat Hunting
BEHAVIOR-BASED HUNTING PLAYBOOKS

Developed hunting hypotheses for persistence, lateral movement, suspicious PowerShell, unusual DNS, and privilege escalation using endpoint telemetry and structured investigation notes.

KQLSigmaYARAEDR
Incident Response
DFIR TABLETOP & RESPONSE RUNBOOK

Prepared incident response runbooks for ransomware, credential compromise, phishing, and web defacement with containment actions, communication flow, and post-incident review templates.

DFIRNIST 800-61TimelineContainment
Vulnerability Management
RISK-BASED PATCH PRIORITIZATION

Built a vulnerability lifecycle model that ranks findings by CVSS, exploitability, asset criticality, exposure, business impact, ownership, and remediation SLA.

NessusOpenVASCVSSSLA
Mobile Security
ANDROID APPLICATION SECURITY REVIEW

Assessed mobile app risk across insecure storage, API traffic, hardcoded secrets, weak certificate validation, and platform permission misuse using static and dynamic testing.

MobSFFridaADBBurp Suite
API Security
REST API AUTHORIZATION TESTING

Tested API endpoints for broken object-level authorization, token weakness, excessive data exposure, rate-limit gaps, and insecure error handling.

PostmanBurpJWTOWASP API
Privacy & Data Protection
GDPR DATA FLOW & DPIA REVIEW

Mapped sensitive data movement, lawful basis, retention risk, consent checkpoints, third-party processors, and privacy controls into a practical DPIA-style assessment.

GDPRDPIAData FlowPrivacy Risk
Phishing Defense
EMAIL SECURITY AWARENESS SIMULATION

Designed a safe awareness program covering phishing indicators, reporting behavior, executive impersonation risk, mail authentication, and user-focused security coaching.

DMARCSPFDKIMAwareness
DevSecOps
SECURE CI/CD PIPELINE REVIEW

Reviewed repository security, dependency risk, secret exposure, pipeline permissions, container image hygiene, and security gates for modern application delivery.

SASTDASTSecretsContainers
Executive Risk Advisory
CYBER RISK DASHBOARD FOR LEADERSHIP

Translated technical findings into board-ready risk narratives, heatmaps, maturity scoring, remediation ownership, budget priorities, and strategic security roadmap actions.

Risk RegisterKRIHeatmapRoadmap
Security Architecture
ZERO TRUST SECURITY BLUEPRINT

Defined a layered security architecture across identity, device posture, network segmentation, application access, logging, and continuous validation.

Zero TrustIAMSegmentationMonitoring
05
Education
ACADEMIC BACKGROUND
01
Master's Degree
Manipal University
MBA in Information Technology & Finance
Specialization in IT Strategy, Cyber Risk Management, Financial Risk Analysis, Technology Governance, Digital Transformation, Information Security Management, Business Continuity Planning, IT Compliance, Enterprise Risk Management (ERM), Cybersecurity Governance, Data-Driven Decision Making, FinTech, and Strategic Technology Leadership.
02
Bachelor's Degree
BERHAMPUR UNIVERSITY
Chemistry — Bachelor of Science
03
Intermediate · Class XII
KSUB COLLEGE OF TEACHER EDUCATION
Physics, Chemistry & Mathematics · Bhanjanagar
04
Matriculation · Class X
ST. XAVIER'S HIGH SCHOOL
Secondary Education
Cybersecurity lab
"Continuous learning is the most dangerous weapon in any security professional's arsenal."
Certifications
Certified Ethical Hacker (CEH)
Jr Penetration Tester Certificate
GCIA — Intrusion Analyst
Advanced Cybersecurity Threats & Governance
Continuous Security Validation
HTM 5
Network operations
06
Skills
SKILLS & ARSENAL
⚔
OFFENSIVE SECURITY
Penetration Testing93%
VAPT91%
Threat Intelligence88%
Red Team Operations85%
📋
GRC & COMPLIANCE
ISO 2700190%
SOC 2 Advisory88%
HIPAA / GDPR / PCIDSS87%
Risk Advisory92%
☁
CLOUD & IAM
Cloud Security86%
Identity & Access Mgmt89%
Cyber Operations91%
Security Validation88%
THINK
LIKE AN
Attacker.
DEFEND
LIKE A
FORTRESS.
"With a passion for cybersecurity and a relentless drive to safeguard digital assets — I remain committed to making a positive impact in the cybersecurity landscape. Whether identifying vulnerabilities or providing strategic guidance, I empower organizations to navigate cyberspace with confidence and resilience."
Shakti Prasad Mahapatro, COO · Aexantis Technologies
07
Contact
LET'S
CONNECT

Whether you're seeking cybersecurity consulting, GRC advisory, offensive security assessments, or a strategic partnership — I'm ready to engage.

📍
Bhubaneswar, Odisha, India
Send a Message →
Cyber ops Server room Security team
Available for consulting engagements, security assessments, speaking opportunities, and strategic advisory roles across regulated industries.