Open to Placements & Internships · 2027

Defend. Detect. Engineer.

Cloud Security Engineer building detection systems, hardened cloud infrastructure and AI-driven security tooling. Currently studying Computer Science with AI at Birmingham City University.

⦿ Profile

A practitioner first.
An engineer always.

I work where modern attacks actually land — in cloud control planes, CI pipelines, identity systems and AI agents. My focus is building detections that fire on real adversary behaviour, not noise; and shipping the tooling, dashboards and runbooks that turn alerts into outcomes.

1st
Innovation Fest 2026
Y2
BSc CS+AI, BCU
12+
Shipped Projects
MITRE
ATT&CK Mapped
⦿ Networking

Connect & Collaborate

Verified Member
Prem Lodhia

Prem Lodhia

Computer Science with AI @ BCU
🥇 Innovation Fest Winner | Technical Coordinator @BCUSCA | Building Secure Systems That Detect Attacks | CS with AI @BCU | Cloud Security & Security Software Engineering | Open to Placements
View LinkedIn Profile →
⦿ Biography

Who I Am

My long-term ambition is to work at the boundary of software engineering and cloud operations as a Cloud Security Engineer or Security Software Engineer. I am dedicated to designing robust detection architectures for cloud platforms and building intelligent tooling to automate security infrastructure.

Outside of core engineering, I read tech news daily, experiment with new developer tools, write native iOS applications in Swift, play cricket, and focus on physical conditioning.

Target Career
Cloud Security / SecDevOps
iOS & Dev Tools
Swift & custom utility builds
Sports & Fitness
Cricket & active conditioning
Continuous Learning
Daily tech news & tools audit
Suricata Splunk Wireshark Zero Trust OWASP Top 10 Threat Intel Cloud Security Application Security Detection Engineering
⦿ Portfolio — Selected Work

Featured Projects

KINORA
🏆 Innovation Fest 2026 · 1st Place

KINORA

An AI-powered elderly-care ecosystem featuring fall detection, a smart pendant, a family companion application, and a clinician telemetry dashboard. Combines custom hardware integration, real-time alerting software, and a complete viable business model.

IoT AI Hardware Full-stack
Featured Win
Cyber Security Toolkit
DETECTION · AUTOMATION

Cyber Security Toolkit

Cross-platform host hardening and security telemetry toolkit. Configures system logs, audits security baselines, and generates JSON alert feeds mapped to the MITRE ATT&CK matrix.

MITRE ATT&CK Matrix Mapping

Tactical Phase Technique ID Remediation Rule
Execution T1059.001 Constrained Language Mode
Persistence T1053.005 Scheduled Task Auditing
Defense Evasion T1562.001 Registry Tamper Block
PowerShell Bash Python
Hospital Management System
APPSEC

Hospital Management System

Secure-by-default healthcare platform featuring strict authentication/authorization (JWT, RBAC), encrypted SQL database backends, automated session expiry, and detailed audit logging pipelines to protect patient PII.

Node JWT RBAC SQL
AI Cybersecurity Interview
AI · CYBERSECURITY

AI Cybersecurity Interview

Retrieval-augmented security assistant that drafts cloud detection rules, conducts interactive, role-specific technical mock interviews, and provides comprehensive performance metrics.

LangChain Embeddings Tools AI Agent
Closed Source
Bridge (Local Guide)
MOBILE · FULL-STACK

Bridge (Local Guide)

A community-driven local guide platform connecting local guides and travellers. Features secure interactive mapping, events, and recommendations.

React Native Expo Node.js MongoDB
vulnshop-lab
WEB SECURITY · PEN TESTING

vulnshop-lab

Local-only web application security lab with a vulnerable build, remediated secure build, and pentest/remediation workflow for portfolio demonstration.

EJS Node.js Express SQLite AppSec
bluetrace-lab
DETECTION ENGINEERING · SIMULATION

bluetrace-lab

Local detection engineering lab for simulated log ingestion, rule-based alerting, triage, and tuning.

SIEM Alerting Rules

Rule ID Target Behavior Severity
SIG-2026-01 Web App Exploit (T1190) High
SIG-2026-02 Valid Account Hijack (T1078) Medium
Python JSON-RPC SIEM Log Ingestion
⦿ Detection Philosophy

Engineering Signals,
Not Noise.

Traditional security relies heavily on static, perimeter-focused telemetry that creates alert fatigue. My approach to operations is centered on **behavioral detection engineering** — modeling the actual techniques adversaries use at every phase of the lifecycle, as mapped by the MITRE ATT&CK framework.

By mapping telemetry pipelines in cloud control planes (AWS CloudTrail), build workflows (CI pipelines), and host processes directly to known behaviors, I write precise detection rules designed to identify post-exploitation activity while minimizing false-positive signals.

Through automation and structured alert runbooks, I help build systems that move security teams directly from detection to verified remediation outcomes in real time.

⦿ Professional Ledger

Work Experience

Cybersecurity Summer Intern

Birmingham City University

July 2026 – Present · Birmingham, UK
Current

Embedded within the Birmingham City University IT and security team, working on monitoring, analyzing, and safeguarding the university's enterprise infrastructure. Spearheading vulnerability assessment workflows, security monitoring, and endpoint protection schemes, while planning and executing proactive defensive measures to detect and mitigate active threats across university network boundaries.

Security Operations & Analysis

  • Conducts regular automated and manual vulnerability scans across university servers and internal subnets to identify CVE exposures and configuration gaps
  • Monitors and analyzes security logs via centralized SIEM dashboards to detect anomalous behavior, unauthorized login attempts, and potential insider threats
  • Participates in incident response playbooks, coordinating alerts triage, isolating compromised nodes, and documenting remediation actions for internal audits
  • Performs packet capture analysis to inspect suspicious network traffic flows and identify potential command-and-control (C2) beacons or data exfiltration

Infrastructure Hardening

  • Configures and audits firewall rulesets and ACLs to enforce least-privilege network segmentation across administrative and student subnets
  • Audits cloud access control policies and IAM roles within host environments to identify and eliminate privilege escalation risks and exposed secrets
  • Deploys security patches, updates server configurations, and hardens operating system baselines according to CIS Benchmarks
  • Enforces Endpoint Detection and Response (EDR) agent coverage and verifies policy compliance across active Windows and Linux server nodes

Tools & Technologies

  • Kali Linux, Nmap, Wireshark, Splunk, Active Directory, AWS, Firewalls & ACLs, EDR Agents, Vulnerability Scanners, CIS Benchmarks
Head of Cyber Division

BCU Student Computing Association (BCUSCA)

March 2026 – July 2026 · 5 months · Birmingham City University
Completed

Leading the Cyber Security Division of the BCU Student Computing Association, responsible for designing and delivering technical programmes, events, and learning experiences that give students hands-on experience in cloud security, penetration testing, and defensive security. Responsible for full curriculum design, session delivery, lab guide development, GitHub resource management, and end-to-end technical coordination across all division activities. Current flagship programme: Hack Your Own Cloud — an 8-week structured cloud security programme where student teams deploy, attack, and defend real AWS environments.

Division Leadership

  • Leads all technical programmes, workshops, and events within the Cyber Security Division from conception through to delivery
  • Designs and maintains curriculum, lab guides, and challenge resources across all division activities, hosted and managed via GitHub
  • Acts as primary technical mentor for all students in the division, supporting learning across all experience levels from complete beginners to advanced students
  • Liaises with the SCA VP Cyber Security on logistics, planning, and strategic direction of the division
  • Scouts and onboards new programme ideas, evaluating feasibility, technical requirements, and student impact before committing to delivery

Hack Your Own Cloud — Flagship Programme

  • Designed and owns the full 8-week cloud security curriculum where students deploy deliberately vulnerable environments on AWS, attack assigned peer environments, and harden their own infrastructure
  • Built a flag-based CTF system using AWS CLI bash scripts and deterministic hash generation to verify genuine exploitation rather than theoretical knowledge
  • Architected separate AWS sub-accounts per team with budget alerts, spending caps, and VPC-level containment to ensure safe, legal, and cost-controlled peer attack exercises
  • Developed weekly lab guides covering AWS EC2, S3 misconfiguration, IAM privilege escalation, insecure APIs, network security, and cloud-native monitoring tools
  • Introduced and runs a structured peer attack challenge functioning as the division's flagship CTF event each semester

Technical Delivery

  • Leads every weekly session using a guided learning approach — actively mentoring students through real vulnerabilities rather than delivering passive lectures
  • Implements monitoring and hardening workflows using Scout Suite, Prowler, CloudWatch, and Azure Monitor as part of the Week 7 remediation phase
  • Manages safety and containment protocols including rules of engagement, account isolation, and UK Computer Misuse Act compliance across all offensive security exercises

Tools and Technologies

  • AWS (EC2, S3, IAM, VPC, CloudWatch), Kali Linux, Nmap, Burp Suite Community, DVWA, WebGoat, Scout Suite, Prowler, AWS CLI, GitHub
Technical Coordinator — Software Engineering Division

BCU Student Computing Association (BCUSCA)

March 2026 – July 2026 · 5 months · Birmingham City University
Completed

Coordinating the Software Engineering Division of the BCU Student Computing Association, responsible for designing and delivering programmes, workshops, and events that build real technical skills in software development and engineering. Responsible for full curriculum design, session delivery, team structure, technical mentorship, and end-to-end coordination across all division activities. Current flagship programme: API Workshop Series — an 8-week full stack programme where student teams build and deploy real applications powered by live external APIs.

Division Coordination

  • Coordinates all technical programmes, workshops, and events within the Software Engineering Division from conception through to delivery
  • Designs and maintains curriculum, lab guides, and project resources across all division activities
  • Acts as primary technical mentor for all students in the division, supporting learning across beginner, intermediate, and advanced levels within the same sessions
  • Liaises with the SCA VP Software Engineering on logistics, planning, and strategic direction of the division
  • Evaluates and prioritises new programme ideas based on student impact, technical feasibility, and career relevance before committing to delivery

API Workshop Series — Flagship Programme

  • Designed the full 8-week API Workshop Series curriculum taking students from HTTP fundamentals to a deployed full stack application using real external APIs
  • Structured a two-path backend approach (Node.js/Express or Python/Flask) to support different skill levels while maintaining consistent guided support across sessions
  • Built in a progressive difficulty curve: foundations and authentication in Weeks 1-3, backend and frontend build in Weeks 4-6, multi-API integration and deployment in Weeks 7-8
  • Designed an optional React advanced path from Week 5 onwards with additional resources provided separately so advanced students are never held back and beginners are never overwhelmed
  • Coordinates industry guest speakers and mentors to drop into build-phase sessions to review projects and share real career experience with students

Technical Delivery

  • Leads weekly sessions using a guided learning approach — students learn by doing with active support throughout rather than passive instruction
  • Established GitHub Desktop as a core collaboration tool from Week 1, ensuring every team can manage shared codebases without conflicts from the very first session
  • Manages team formation and role assignment (frontend developer, backend developer, project lead) to give every student concrete, specific, CV-ready ownership of their contributions

Tools and Technologies

  • Node.js, Express, Python, Flask, HTML5, CSS3, JavaScript, React, Postman, GitHub Desktop, Vercel, Render, OpenWeatherMap API, GitHub API, NASA API, Spotify Web API, Open Library API
Full Stack Software Developer Intern

CivitasAccess

April 2026 – July 2026 · 3 months · Remote / UK
Completed

Embedded as a full stack developer on CivitasAccess — a civic guidance and opportunity navigation platform built for UK students and international students. Responsible for the complete front-end architecture and UI build across 24 pages, alongside back-end planning, admin system design, and direct client collaboration throughout the product lifecycle.

Front-End Development

  • Architected a single-file React/Babel application spanning 24 fully interactive wireframe pages including public pages, three content hubs, user account flows, and a complete admin panel
  • Built reusable component systems (navigation, card primitives, form inputs, pill labels, roadmap steps, journey nodes) maintaining consistent design tokens across the entire codebase
  • Developed an interactive Career GPS homepage flow — a multi-step guided widget allowing users to identify their current position, select a destination, and receive a personalised pathway recommendation
  • Implemented a visual journey timeline for the International Student Hub featuring clickable node-based navigation, animated progress tracking, and interactive checklists
  • Designed and built six full pathway detail pages with animated roadmap step sequences, connector lines, Career GPS sidebar panels, and linked opportunity cards
  • Built the Success Stories system — index page with category filtering, individual story pages with visual journey progression strips, and cross-linked sidebar panels

UI/UX & Design Systems

  • Worked directly with the client to translate written briefs and conversational feedback into functional, production-ready wireframes across multiple revision cycles
  • Established and enforced a consistent brand design system: teal (#1A5C6B), gold (#93632F), typography scale, spacing grid, and component hierarchy
  • Delivered iterative wireframe audits using structured pass/gap/defer reporting to track requirement coverage and communicate scope decisions clearly
  • Proposed and agreed scope boundaries between V1 (launch) and Phase 2 (post-launch dynamic features) to protect timeline while preserving the client's long-term vision

Back-End Planning & Admin Systems

  • Designed a full admin panel architecture covering: Opportunity CRUD management, Manage Pathways (step-by-step roadmap builder with no-code interface), Content & Stories management, User Manager, Category/Tag management, and Community Impact stats editor
  • Planned and documented the database tagging schema for opportunities, categories, and pathways to support future personalised recommendation logic
  • Structured the admin panel to allow non-technical content management — client can publish opportunities, guides, and success stories independently after handoff

Security Considerations

  • Specified SSL certificate implementation as a deployment requirement for all data in transit
  • Designed contact form architecture to route submissions through Google Workspace email — avoiding direct server-side email exposure
  • Anticipated XSS prevention in form input handlers by verifying text sanitation requirements in the front-end
  • Documented Google SSO as the primary authentication path (supplemented by email/password) to reduce credential-attack surface in user management drafts
  • Flagged GDPR-relevant data points (e.g., student location, career tracks) for inclusion in the platform's future Privacy Policy and Terms of Service drafts
  • Separated personally identifiable information (PII) from behavioral analytics fields in the database schema draft to protect user identity
  • Proposed full network separation between admin panels and public routes to limit administrative dashboard exposure

Client Communication

  • Authored structured client-facing update emails to summarize weekly wireframe progress, explain technical logic, and detail scope decisions
  • Created a shared "Phase 2 Deferral" document to log and agree on features that would be moved to post-launch milestones, preventing scope creep and protecting the delivery timeline

Technical Skills Used

React (JSX)

Built complex, interactive components with unified state management and modular front-end architecture.

HTML5/CSS3

Coded responsive layouts using semantic nodes and structured visual custom variables.

UI/UX Design

Designed clean component primitives, typography scales, and spacing grids with consistent design tokens.

Database Design

Structured tagging schemas, user profile structures, and relational models with strict separation of sensitive fields.

Security Awareness

Specified transport encryption, single sign-on flows, and separation of administration routes.

Admin Systems

Designed opportunities CRUD interfaces, stats management, and no-code builders for non-technical users.

API Integration

Mapped client payloads, designed REST API response patterns, and integrated external data nodes.

Client Communication

Delivered progress reports, wireframe audits, and led scope alignment calls.

Code Review

Evaluated pull requests, audited component layouts, and checked code syntax standards.

Security-first mindset at every layer.

Across this project I applied security thinking at every layer of the build — from specifying SSL enforcement and planning Google OAuth as the primary authentication path, to structuring user data fields with GDPR compliance in mind and designing admin routes with full separation from public-facing flows. I'm actively developing my expertise toward a career in cybersecurity, and this project has given me hands-on context for understanding how security decisions are made during the front-end and architecture phases of a product, not just after the fact.

⦿ Competency Map

Technical Skills

Security

Detection Engineering MITRE ATT&CK Incident Response OWASP Top 10 Risk Analysis AppSec Defence-in-Depth Hardening SIEM

Cloud & Infra

AWS Cloud-Native Serverless Docker Containers Hybrid Cloud IaaS DevOps Linux

AI / ML

Agentic Systems RAG LangChain Prompt Engineering Hugging Face PyTorch scikit-learn Embeddings

Engineering

Python TypeScript Node.js Bash PowerShell SQL Git REST APIs Secure Coding
⦿ Credentials & Honors

Credentials & Awards

Cybersecurity & Defense

Google Cybersecurity Professional Certificate In Progress
Google • Coursera Expected 2026
Cisco • Credly Earned 2025
Cisco • Credly Earned 2025
IBM Cybersecurity Analyst (Adding link soon) Earned
IBM Earned 2025

Cloud & Infrastructure

Cisco • Credly Earned 2025
AWS Certified Solutions Architect (SAA-C03) In Progress
Amazon Web Services Expected 2025
AWS Certified Cloud Support Associate In Progress
Amazon Web Services Expected 2025

AI & Emerging Tech

Google • Coursera Earned 2026
Vanderbilt • Coursera Earned 2025
IBM • Coursera Earned 2025
IBM SkillsBuild • Credly Earned 2025

Development & Simulations

JPMorgan Chase • Forage Completed 2025
Commonwealth Bank • Forage Completed 2025
Meta iOS Developer (Adding link soon) Earned
Meta • Coursera Earned 2025

Honors & Awards

Innovation Fest — First Place Winner
Birmingham City University May 2026
Unihack x Innovation Fest Hackathon Winner
Unihack • BCU May 2026
Most Inspirational Student of the Year Nominee
IAMBCU Awards April 2026
⦿ Recommendations

Endorsements

"An exceptional learner and an asset to our classes. He demonstrated excellent analytical, practical, and critical thinking skills, allowing him to quickly understand complex computing concepts and apply them effectively."

DR. HAMZA MUTAHER
Lecturer & Deputy Course Lead of Cyber Security · BCU
Verify Reference Letter (PDF) →

"An exceptionally bright student with a natural aptitude for software development and a genuine programmer's mindset. He possesses strong technical ability... I highly recommend him for any software engineering opportunity."

ABDUL QAYOOM HAMAL
Researcher, Lecturer & Software Engineer · BCU

"Prem consistently demonstrated strong technical ability, dedication, and enthusiasm for learning. He showed excellent problem-solving skills, quickly grasped programming concepts, and applied them effectively."

ASSOC. PROFESSOR OGERTA ELEZAJ
Associate Professor in AI & Turing Fellow · BCU
⦿ Side Project · Venture

Cyber Interview AI

Launching Soon

The AI interviewer built for cybersecurity.

Train smarter. Hire better. Secure the future.

We are building the ultimate simulation engine for cybersecurity professional development. Cyber Interview AI allows candidates to train on realistic scenarios and enables organizations to streamline recruitment with automated, job-role aligned assessments.

What is it?

An AI-powered interview platform tailored specifically for the cybersecurity industry. It conducts realistic, interactive mock interviews using a custom-trained model, evaluates responses in real time, and provides detailed feedback.

Supports 150+ Roles including:

  • SOC Analyst & Incident Responder
  • Cloud Security Engineer & DevSecOps
  • Penetration Tester & Application Security
  • GRC Specialist & Threat Intelligence Analyst

Why I'm building this

The Candidate Problem: Generic AI interview tools ask generic interview questions. Human interviewers are expensive and inconsistent, leaving security graduates and job seekers flying blind.

The Recruiter Problem: Organizations lack a reliable, scalable way to technically screen cybersecurity candidates before committing expensive engineering hours to live interviews.

Target Audience:

  • Students & Graduates looking to practice
  • Job Seekers wanting structured feedback
  • Recruiters & Security Teams screening at scale
  • Universities & Bootcamps embedding career tools

How it works

  • 1. Set Up: Choose a specific security role track (e.g., Cloud Security), select your topic, and configure the difficulty level.
  • 2. The Interview: The AI asks technical and scenario-based questions. The candidate responds via voice or text, and the AI dynamically follow up based on the answer.
  • 3. Instant Report: The candidate receives multi-dimension scores, actionable feedback on response gaps, and personalized improvement tips.

How we generate revenue

  • Individual Subscriptions: Candidates subscribe to unlock unlimited mock interviews, diagnostic performance dashboards, and resume builder integrations.
  • Academic Licensing: Bulk student seat licenses for universities and bootcamps, including cohort-level skill telemetry and custom syllabus mapping.
  • Enterprise Screening: Custom pre-screening portals for recruitment agencies and corporate HR teams with ATS integrations and technical evaluation APIs.

Built & Trained By Me

AI & Model Development

Custom AI model training NLP fine-tuning Answer evaluation logic Scoring algorithms Speech-to-text Real-time inference

Product & Engineering

React Node.js REST APIs JWT authentication Web Speech API SaaS architecture Analytics dashboards Subscription billing

💰 Invest

Seed round open. Reach out to discuss investment opportunities.

Discuss Investment

🖥️ Try the Demo

Join the early access waitlist to test the platform mock engine.

Request Demo Access

🤝 Partner

Universities, bootcamps and recruiting agencies welcome.

Discuss Partnership
⦿ Environment & Gear

Uses

Desktop & Laptop Setup

Primary Machine

"15.6" 2-in-1 convertible with a Super AMOLED 1080p touchscreen, Intel Core i7 (11th Gen) with Intel Iris Xe Graphics, 16GB LPDDR4x RAM, 512GB NVMe SSD, and a 360° hinge for tablet/laptop switching. Runs Windows 11 + Ubuntu dual-boot for cross-platform security testing. MIL-STD-810 military-grade rated.

  • VS Code • JetBrains
  • Docker Desktop • WSL2
  • Wireshark • Splunk • Burp Suite
  • S Pen for architectural diagramming
iPad Pro Setup

iPad Pro 13-inch (M5) — Max Configuration. Used as a high-performance secondary display, portable work environment, and digital architecture canvas. Paired with Apple Magic Keyboard (Aluminum) and Apple Pencil Pro.

  • Apple M5 chip (10-core CPU, 10-core GPU, 16-core Neural Engine)
  • 16GB Unified Memory / RAM
  • 2TB NVMe SSD storage
  • Ultra Retina XDR Tandem OLED display with Nano-texture glass
  • 5G Cellular + Wi-Fi 6E connectivity
Mobile & Responsive Testing

Browser developer tooling, custom responsive layouts, and lightweight device emulation targets to ensure fluid accessibility across viewports.

  • Chrome DevTools device emulation
  • Touch-friendly viewport controls
  • Graceful mobile layout fallbacks

Software Stack

Development Suite

Python, JavaScript, Node.js, Bash, PowerShell, SQL, HTML/CSS, and Git. Focused on rapid local iteration cycles: code, test, verify, and document.

Defensive & Audit Tools

Splunk SIEM, Suricata IDS, Wireshark packet capture, Docker containers, Burp Suite, Nmap scanner, and custom detection rule pipelines.

Cloud & Platform Workflow

I use a hybrid environment where local sandboxes and cloud resources complement each other. This entails building safe configurations locally before executing against enterprise-grade telemetry and cloud deployment baselines.

  • Local lab first: Docker and VM-based sandbox testing for BlueTrace, VulnShop, and software prototypes.
  • Cloud-aware design: AWS-style centralized logging, IAM policy audits, and detection engineering with realistic trails.
  • Documented processes: Every lab run is captured as a clear write-up to ensure findings are reproducible.
  • Continuous review: Threat modelling, MITRE mapping, and detection rule tuning are integrated into every run.

Workflow Methodology

  • Plan: Define the threat scenario, pick the target nodes, and select tools that match active real-world security stacks.
  • Build: Construct the lab target, deploy dependencies, and instrument logs so that alerts and data flows can be audited.
  • Test: Execute attack vectors, validate alerts telemetry, analyze logs, and tune rules to minimize false positives.
  • Document: Package findings into detailed write-ups, README guides, and project repositories for verification.
⦿ Contact

Let's build
something resilient.

I'm open to placement for 2027 and internship for 2027 in cybersecurity, cloud security, detection engineering and AI-adjacent security tooling — UK or remote.

Now: Year 2 BSc Computer Science with AI, Birmingham City University
Next: Cybersecurity, cloud security, and detection engineering placements/internships, 2027 cohort