// CLASSIFIED SUMMARY
I'm Nisarg Chasmawala, codename HEAVEN: an award-winning Offensive Security Engineer, Penetration Tester and Red Team Operator working across enterprise and cloud environments. Indian-origin, now UK-based as an international postgraduate, studying for an MSc in Cyber Security at Birmingham City University, England, UK (expected March 2027). Most of what I do sits where vulnerability assessment meets AI and Machine Learning threat intelligence, and most of it involves writing the offensive tooling myself so the assessment can run on its own.
// LIVE ENGAGEMENT. As Lead Security Consultant to Nehemiah Housing Association, a £9.1M UK social housing provider holding data on 4,000 residents, I ran a full security posture assessment and Cyber Essentials v3.3 gap analysis. HEAVEN executed 1,800+ non-disruptive checks across live cloud platforms, public web applications and internal networks, surfacing 167 vulnerabilities including an unauthenticated SQL injection candidate and severe architectural exposures. NIST SP 800-115 methodology confirmed which historical fixes had actually held. The output was a finance-aligned remediation roadmap presented to the board, plus an 11-part compliance toolkit covering patch management, MFA enforcement and runbooks, written so the certification survives past the audit.
// OFFENSIVE TRADECRAFT. CPENT-certified across the full attack chain: external and internal infrastructure testing, network exploitation, Active Directory abuse, web and REST API attacks, cloud (AWS IAM) privilege escalation, OSINT, and digital forensics. In live MSc engagements I chained CVSS 10.0 RCE exploits against Redis, Openfire and Gitea, pivoting from replication abuse and admin console exploitation through Git Hooks weaponisation to system-level access.
// GenAI-AUGMENTED TOOLING. I use Large Language Models and Generative AI to design, script and ship custom offensive tools quickly. The flagship is HEAVEN, an autonomous penetration testing framework: extensible specialised modules, deterministic false-positive suppression, an AI attack-chain planner running an observe-plan-act loop with an offline credential-free fallback, a multi-feature ExtraTreesRegressor that prioritises CVSS v3.1 findings through EPSS and CISA KEV, mapping to MITRE ATT&CK, the Cyber Kill Chain and OWASP, and a PostgreSQL backend. Next to it sits HEAVEN-GeoIntel, an offline-first Next.js OSINT platform that unifies 7 identifier types, correlates bundled datasets with free-tier intelligence, and automates credential breach and info-stealer analysis with full OPSEC and no commercial API keys.
// CLEARANCE. CPENT · CEH Master · CHFI (90.7%) · ISO 27001:2022 & 27701:2025 LA · CRTOM · CLLMSP · 23 certifications in total · 8 live offensive and ML projects on GitHub. 🏆 1st Place at the BCU Cyber Security Society Hackathon (STEAMhouse, UK) · 🥈 Runner-Up at the BCU AI Hackathon 2026 · 🏅 Top 5 Finalist at Unihack 2026.