Joshua
Alwin
Breaking into systems and building the defenses that stop the next attacker
About
Security is a mindset, not a checklist.
I'm a security engineer who thinks like an attacker. At Google and KPMG, I broke into web apps, APIs, cloud environments, and Active Directory networks, uncovering critical vulnerabilities across systems serving millions of users. Now, I'm channeling that same offensive mindset into a Master's in Cybersecurity Engineering at the University of Maryland, going deeper into AI security and the evolving threat landscape around machine learning.
I compete in CTFs under the alias T3rminux and recently won the Bugcrowd Student CTF. That same adversarial energy carries into my role as a graduate teaching assistant, where I design CTF challenges and hands-on labs for courses in penetration testing and cloud security.
Right now, I'm sharpening my offensive tradecraft across cloud, web, and AI attack surfaces. If your team needs someone who breaks things with purpose and builds things that last — let's make it happen.

M.S. in Cybersecurity Engineering
University of Maryland, College Park
2024 – Present
B.E. in Electronics & Communication Engineering
VIT, Vellore
2018 – 2022Bugcrowd x HTB CTF Winner
Student CTF champion as T3rminux
UMD MAGE Feature
News story highlighting my journey
2× KPMG Awards
Applause & Encore Award recipient
TryHackMe Top 1500
Global ranking out of 3M+ users
Experience
Security Consultant Intern, Mandiant Red Team
@ Google LLC
Worked as a Security Consultant Intern on Mandiant's Red Team conducting offensive security engagements against Fortune 500 clients. Developed internal tooling adopted in production red team operations and identified critical vulnerabilities across consumer platforms serving millions of users.

Teaching Assistant, Penetration Testing (ENPM634)
@ University of Maryland
Supporting the graduate-level penetration testing coursework at the University of Maryland by assisting students with hands-on labs and technical concepts, while designing and building CTF challenges and practical lab environments across offensive security domains.
Associate Security Consultant
@ KPMG
Worked as an Offensive Security Consultant delivering 100+ security assessments, red team engagements, and source code reviews across Web, Networks, API, mobile, Thick/Thin Client, and cloud environments for Fortune 500 clients based in Europe and Asia.

Teaching Assistant, Cloud Security (ENPM665)
@ University of Maryland
Supported graduate-level cloud security coursework at the University of Maryland by developing hands-on labs and delivering lectures across AWS, GCP, and Azure, while curating practical assignments on cloud penetration testing, compliance benchmarking, and incident response.
Projects
Phishing Analysis Pipeline
Automated phishing deliverability analysis tool built for red teamers at Google. Uses Postfix for email ingestion, FastAPI backend integrating VirusTotal, Gemini, and SpamAssassin, with a React frontend for campaign effectiveness tracking.
ML Security Playground
Collection of ML security projects covering spam classification, network anomaly detection, and malware family classification using scikit-learn and transfer learning with ResNet50.
WalkMyNFS
Bash utility for NFS reconnaissance during internal penetration tests. Auto-discovers and mounts network shares in read-only mode for safe enumeration of misconfigurations and sensitive files.
Wario
Breach simulation platform built on MITRE Caldera to automate red teaming capabilities. Developed at KPMG, enabling automated adversary emulation and attack chain execution by building custom Active Directory (AD) capabilities on top of Caldera's existing framework.
Certifications

OffSec Certified Professional+ (OSCP+)
OffSec

OffSec Wireless Professional (OSWP)
OffSec

Certified Red Team Professional (CRTP)
Altered Security

AWS Certified Solutions Architect – Associate
Amazon Web Services (AWS)

OffSec Certified Professional (OSCP)
OffSec

Certified Ethical Hacker (CEH) Practical
EC-Council

eLearnSecurity Junior Penetration Tester (eJPT)
INE Security

Certified Mobile Pentester (CMPen) – iOS
The SecOps Group

Certified AppSec Practitioner (CAP)
The SecOps Group

Microsoft Certified: Security, Compliance, and Identity Fundamentals
Microsoft

Microsoft Certified: Azure Fundamentals
Microsoft
Blog
Feb 2026From Breaking In to Building Up: Passing the AWS SAA
How learning cloud architecture changed the way I approach cloud security.
Nov 2025Gliding Through OSWP: The Calm After the Storm
Learn, have fun, hack wireless. All three APs down in under 120 minutes.
Oct 2025Conquering the OSCP+: A Guide to the Mental Marathon
You don't fail because you can't hack — you fail because you break. A guide to the 24-hour exam.
Apr 2022CEH Practical Review: A Beginner Level Cybersecurity Cert?
Six hours, 20 scenarios, 19/20. An honest take on what the CEH Practical actually tests.
Nov 2021eJPT Review: My First Ever Pentesting Certification
Where the offensive security journey started. 72-hour exam, routing rabbit holes, and a 1:20 AM pass.
Contact
Let's connect and build something together.
Whether it's a security engagement, research collaboration, or just a conversation about offensive security, I'm always open to connect.
$ cat status.txt
Open to Offensive Security & Security Engineering roles
Available for offensive security projects & collaborations
Open to speaking & workshop opportunities
$ echo $LOCATION
Based in DC | Open to relocation & remote
$ echo $RESPONSE_TIME
Faster than a reverse shell callback ⚡
$


