SHEMKUMAR P

AI Security Engineer

@ Votal AI  ·  Building Secure AI Products & Web Pentesting Platform

30+Secured Sites
150+CTF Participants
LLMRed Teaming
sam@votal:~$ whoami
AI Security Engineer | LLM Red Teamer | AppSec → AI Security
sam@votal:~$ working_on
Securing AI products & building a web pentesting platform @ Votal AI
sam@votal:~$ location
Chennai, Tamil Nadu, India
sam@votal:~$ status
Status: ONLINE & HUNTING PROMPT INJECTIONS
Shemkumar P

About Me

AI security engineer protecting LLM-powered products and the web apps around them

I'm an AI Security Engineer at Votal AI, where I help build and secure AI products end-to-end. My day-to-day spans LLM red teaming (prompt injection, jailbreaks, data leakage, tool/agent abuse), securing the surrounding web apps and APIs, and building a web pentesting product that streamlines vulnerability discovery for modern stacks.

I came into AI security from a strong AppSec and red team background — OWASP Top 10, WordPress hardening, VAPT, and responsible disclosures across 30+ company and government websites. That foundation now informs how I model threats for LLM features, agents, RAG pipelines and AI-augmented workflows.

As a co-founder of Cyber Sentinels at Rajalakshmi Engineering College, I organized CTF competitions for 150+ participants and ran the infrastructure on AWS. I love building tooling, sharing knowledge, and playing CTFs with my team on CTFtime.

B.Tech in Information Technology, Rajalakshmi Engineering College. Currently focused on shipping secure AI products and growing the next generation of AI security tooling.

LocationChennai, India
Current RoleAI Security Engineer
CompanyVotal AI
FocusLLM Red Teaming · AppSec
EducationB.Tech IT
LanguagesEnglish, Tamil

Experience

From AppSec and red teaming to securing AI products at Votal AI

AI Security Engineer

LLM Red Teaming · AppSec · Product Security

Votal AI

Present Remote · India
  • Securing AI products end-to-end — LLM features, agents, RAG pipelines, and the web apps and APIs that wrap them
  • Red teaming LLMs for prompt injection, jailbreaks, data leakage, unsafe tool use, and policy bypass
  • Helping build a web pentesting product that accelerates vulnerability discovery for modern web stacks
  • Threat modeling AI workflows and collaborating with engineering to ship safe-by-default features
  • Driving responsible AI security practices, internal guidelines and developer enablement

Application Security Engineer

Web & API Security · VAPT

CyberneticsPlus Services Pvt Ltd

July 2025 Bengaluru, Karnataka
  • Conducted comprehensive security testing on web and API applications to identify critical vulnerabilities
  • Identified and reported OWASP Top 10 vulnerabilities including SQLi, XSS, IDOR, authentication bypasses
  • Collaborated with development teams to implement secure coding practices
  • Performed manual and automated vulnerability assessments on production applications
  • Documented findings with detailed reproduction steps and remediation guidance

Security Analyst

WordPress & Web App Security

Veegam Software Pvt. Ltd.

April 2025 - June 2025 Hyderabad, Telangana
  • Manual security testing on WordPress applications and admin dashboards
  • Identified critical vulnerabilities: Remote Code Execution (RCE), IDOR, OTP bypass, XSS
  • Documented findings with clear reproduction steps and remediation guidance
  • Hardened WordPress environments against common attack vectors
  • Security audits on custom plugins and themes

Co-Founder & CTF Organizer

Cybersecurity Community · CTF Infrastructure

Cyber Sentinels, Rajalakshmi Engineering College

January 2025 - May 2025 Chennai, Tamil Nadu
  • Co-founded Cyber Sentinels club focused on practical skill development
  • Organized CTF challenges for 150+ participants
  • Managed CTF infrastructure on AWS EC2 & Docker with 99.9% uptime for 120+ participants
  • Developed custom challenges simulating real-world vulnerabilities
  • Conducted hands-on workshops on pentesting, OSINT, and secure coding

Projects

Security research, AI security tooling and pentesting product work

Web Pentesting Product (Votal AI)

AppSecAutomationLLMAPIs
  • Contributing to a web pentesting platform that automates discovery, triage and reporting
  • Designing test modules around OWASP Top 10 and modern auth patterns (JWT, OAuth, SSO)
  • Integrating LLM-assisted analysis to reduce noise and accelerate remediation

LLM Red Teaming Toolkit

Prompt InjectionJailbreaksRAGAgents
  • Test suites for prompt injection, jailbreaks, and data exfiltration on LLM features
  • Evaluations for unsafe tool use and agent abuse in multi-step workflows
  • Repeatable harnesses to regression-test guardrails as models and prompts evolve

Cyber Attack Detection Using Server Logs

PythonFlaskRegexML
  • Flask app for real-time attack detection from server logs
  • Pattern recognition for SQLi, XSS, Command Injection and Path Traversal
  • Reduced breaches by 25% via early threat detection and automated alerting

Google Dorking for Security Research

OSINTReconInfoSec
  • Methodology for finding exposed credentials, sensitive data and misconfigurations
  • Specialized dorks for high-signal recon
  • Automation to streamline OSINT workflows

WiFi Portal Automation System

PythonSeleniumAutomation
  • Python + Selenium automation for captive portal authentication
  • Reduced login time by 80% with parallel processing
  • Secure credential management with encryption best practices

Technical Arsenal

Technologies and tools I work with

AI Security

LLM Red TeamingPrompt InjectionJailbreaksRAG SecurityAgent SecurityOWASP LLM Top 10Guardrails

Cybersecurity

Penetration TestingVAPTRed TeamingOWASP Top 10OSINTReverse Engineering

Programming & Scripting

PythonJavaScriptBashMySQLFlaskGitSQL

Security Tools

Burp SuiteMetasploitNmapWiresharkOWASP ZAPNikto

Cloud & DevOps

AWS EC2AWS S3DockerKubernetesCI/CD

Web Development

HTML5CSS3FlaskREST APIsReactWordPress

Operating Systems

LinuxKali LinuxParrot OSUbuntuWindows

Achievements

Recognition and accomplishments in cybersecurity

Pentathon 2025 CTF National Finalist

Ranked 17th in the Pentathon 2025 national finals across web exploitation, cryptography, and vulnerability analysis.

PENTATHON 2024 CTF Runner-Up

2nd place in Prelims and Top 10 in Finals — vulnerability analysis, exploit dev, reverse engineering, cryptography.

NCIIPC RVDP Acknowledgements

Multiple acknowledged disclosures to NCIIPC India (a unit of NTRO), including data breach on EMIS TN Schools Portal and admin panel access on a tn.gov.in subdomain.

Dr. Care Homeopathy RCE

Discovered a critical RCE on drcarehomeopathy.com; recognition led to a paid security internship.

Tamil Nadu Scholarship Portal Data Leak

Identified data leakage exposing Aadhaar and bank details; responsibly disclosed to protect thousands of students.

Government Portal Admin Bypass

Reported an authentication bypass exposing the admin panel of a government portal.

Engineering College Website RCE

Gained reverse shell on an educational institution website and provided full remediation guidance.

Enterprise Application RCE

Reported RCE in an enterprise application used by a major tech company; received formal appreciation.

30+ Websites Secured

Responsibly disclosed and helped remediate vulnerabilities across 30+ company and government websites.

TryHackMe

View Profile

CTFtime Team

Team Profile

Get In Touch

Let's connect on AI security, AppSec or CTFs

TryHackMe

Check profile