Security Engineer · AI/ML Builder

Security is a design principle,
not a feature.

I build full-stack AI and security systems — autonomous threat detection, cloud-native SaaS, and local inference — with hardened architecture at every layer.

9+
Years hands-on
6
Projects shipped
2
Post-grad programs

// about

Security mindset, builder's hands.

Karan Gill

Education

Cambrian College · Sudbury

Two Graduate Certificates — Cybersecurity & AI/ML

Punjabi University · Patiala

Bachelor of Computer Applications

Cybersecurity and AI/ML graduate building at the intersection of both domains. I design and ship production systems — from autonomous threat detection platforms to full-stack AI SaaS on AWS. Security-first mindset and AI-native workflow. Based in Sudbury, ON. Open to work.

Defensive Systems Privacy-first AI SIEM Monitoring Local LLMs / RAG Off-cloud Data

// experience

Professional journey.

Capstone · Internship Jan 2025 – Apr 2025 · 4 mos

Cybersecurity Capstone Intern

Spectrum Telecom Group Ltd.

Greater Sudbury, ON · Remote

Built and secured a full virtualized lab environment to support the company's ISO 27001 certification effort — SIEM, Active Directory, and network hardening, end to end.

  • Designed and deployed a full virtual lab using a hypervisor — provisioning and configuring Windows Server, Windows Enterprise, Wazuh SIEM, and a MikroTik router/firewall, all scoped to the company's ISO 27001 certification effort.
  • Deployed and configured Wazuh SIEM from scratch for real-time threat detection and centralized log management across the infrastructure.
  • Built and managed Active Directory environments — user accounts, groups, organizational units, Group Policy Objects (GPOs), and credential lifecycle management.
  • Configured and managed Windows Server roles and services to support internal IT operations.
  • Monitored and analyzed Windows Event Logs to identify anomalous activity and support incident-triage workflows.
  • Aligned SIEM alert rules, virtual-environment design, and documentation with ISO 27001 information-security management standards.
  • Configured MikroTik router/firewall policies to enforce network segmentation and access control.
Wazuh SIEMWindows ServerActive DirectoryGPOMikroTikISO 27001Hypervisor / VMs
Self-Directed Jul 2017 – Present · 9 yrs

Independent AI & IT Practitioner

Self Practitioner

Nine years of hands-on practice across custom hardware, advanced Windows administration, home networking, and AI-native development — applying academic knowledge to real-world builds.

  • Designed, assembled, and maintained high-performance custom PC builds — deep practical knowledge of hardware compatibility, BIOS configuration, and component-level troubleshooting.
  • Managed and optimized Windows 10/11 at an advanced level: performance tuning, registry editing, driver management, startup optimization, and system recovery.
  • Configured home network environments — router dashboards, firewall rules, port forwarding, DNS, and LAN/WLAN segmentation.
  • Operated AI-native development workflows using Cursor IDE and coding agents to architect, direct, and ship complete AI systems — mirroring how modern AI teams build software.
  • Actively researched AI, cybersecurity threats, vulnerability disclosures, and emerging attack techniques — applying academic knowledge to real-world security context.
  • Continuously tested emerging AI models, LLM tooling, and agentic frameworks — maintaining current fluency across OpenAI, Anthropic, Google Gemini, Ollama, and OpenRouter.
Windows 10/11NetworkingCursor IDELLM ToolingOllamaAgentic FrameworksCustom PC

// projects

Things I've shipped.

Featured Project

SentinelAI

Autonomous threat intelligence and incident response platform built to act as a Tier-1 SOC analyst — ingests logs, detects anomalies, classifies threats, maps them to MITRE ATT&CK, and generates explainable incident reports with remediation playbooks. Built with SHAP explainability for ISO 27001 / regulated-industry contexts.

PythonELK StackFastAPIMITRE ATT&CKSHAP
Security

AI Red-Team Agent

Authorized local-lab security assessment agent that uses an LLM ReAct loop to probe for OWASP Top 10 vulnerabilities. Every tool call is checked against a scope.yaml allowlist before execution — LLM output is treated as untrusted, not ground truth. Maps findings to MITRE ATT&CK with CVSS v3.1 estimates and streams to a live dashboard.

PythonLLM ReActOWASP ZAPNucleiPlaywrightStreamlitMITRE ATT&CK
AI/ML · Security

CodeGuard

AI-powered security code review tool. Analyzes submitted code across 10 languages and returns a three-part structured review: a severity-graded vulnerability report with CWE IDs and line references, a corrected version with every fix annotated inline, and a plain-language developer briefing calibrated to experience level.

TypeScriptNext.jsPythonFastAPIAWS BedrockTerraform
AI/ML · Privacy

Local RAG System

Production-grade, privacy-first retrieval-augmented generation — chat with your own documents entirely on your machine. Combines hybrid search (ChromaDB vector + BM25 keyword) with automatic PII scrubbing and prompt-injection quarantine before anything is indexed. Runs local Ollama models or cloud APIs behind a Streamlit + FastAPI stack.

PythonOllamaChromaDBBM25FastAPIStreamlit
AI/ML · Coaching

AI Interview Coach

An intelligent mock interview platform that provides real-time feedback on spoken responses. Analyzes clarity, confidence, and structure using the STAR framework. Runs locally via Ollama for maximum privacy.

PythonOllamaSTTFastAPIStreamlitOpenAIGeminiDockerHybrid Cloud
AI/ML · Security

VulnPredict

ML-driven vulnerability prioritization. Ingests CVE and exploitation intelligence from NVD, CISA KEV, EPSS, and ExploitDB, builds structured features, and trains LightGBM models to predict 30/60/90-day exploitation-likelihood windows. Surfaces results through a FastAPI backend, Plotly Dash dashboard, and Slack alerts.

PythonLightGBMPostgreSQLAirflowFastAPIPlotly Dash

// skills

The arsenal.

Security

SOC / SIEM Wazuh & ISO 27001
Network Defense Firewalls & Pen Testing

AI/ML

Python AI & Backend
Local LLMs RAG & NLP

Infrastructure

AWS Cloud Architecture & ML
Windows Server Hardening & AD

// content

Breaking down tech, in public.

Karan Gill's @gamergoesdigital content
Instagram @gamergoesdigital

Documenting the journey from student to tech professional in real time — tech concepts broken down simply, honest takes on AI and the job market, and the unfiltered reality of job-hunting and immigration as a new grad in Canada. No corporate speak. No pretending to have it figured out. Follow along — it's going to be an interesting ride. 🎮💻

Karan Gill on his motorcycle in a remote mountain range

// beyond work

Gamer on Adventure

When I'm not securing systems, I'm gaming (since I was 6) or chasing remote roads on my motorcycle. Strategy, precision, and the open road — same mindset, different arena.

// contact

Let's solve real problems — with security at the core.

Open to security-engineering and AI/ML roles. Reach out — I reply fast.

karangill.1708@gmail.com