Post

About Me

About Me

πŸ‘€ About Harsh Srivastava

IoT/OT Penetration TesterEmbedded SecurityHardware SecurityFirmware Analysis
πŸ“§ harsh01200@gmail.com Β Β  πŸ”— LinkedIn Β Β  🌐 harshsecurity.com

🧭 Professional Summary

I’m an IoT/OT Penetration Tester with hands-on experience in embedded device security, industrial control systems, firmware analysis, and hardware penetration testing. I specialize in assessing industrial and IoT communication protocols, firmware extraction, UART/JTAG analysis, protocol fuzzing, packet manipulation, replay testing, and industrial network traffic analysis β€” with additional experience in embedded device assessment, firmware upgrade validation, and hardware interface analysis within OT environments.


πŸ› οΈ Technical Skills

Protocols: Modbus, BACnet, DNP3, Profinet, Ethernet/IP, CAN Bus, MQTT, BLE, Zigbee, SNMP

Hardware Security: Firmware Extraction, UART, JTAG, SPI Flash Dumping, Hardware Interface Analysis

Tools: Nmap, YABE, Ubertooth, Bus Pirate, JTAGulator, Wireshark, Binwalk, Custom Scripts


πŸ’Ό Experience

IoT/OT Penetration Tester β€” Tata Consultancy Services (TCS), Kolkata, India July 2024 – Present

  • Conduct security assessments and penetration testing of embedded systems, industrial devices, HMIs, gateways, and IoT products used in industrial automation and energy management solutions for a leading global industrial technology company.
  • Perform security assessments of industrial and IoT communication protocols including Modbus TCP/RTU, BACnet, DNP3, Profinet, Ethernet/IP, CAN Bus, MQTT, BLE, Zigbee, and SNMP across OT and embedded environments.
  • Execute firmware extraction and analysis using UART, JTAG, SPI flash dumping, bootloader interaction, and filesystem extraction techniques.
  • Conduct hardware penetration testing through UART console access, JTAG enumeration, memory dumping, and low-level embedded interface analysis.
  • Perform protocol fuzzing, packet manipulation, replay testing, and network traffic analysis using Wireshark, Scapy, tcpdump, and embedded security testing methodologies.
  • Assess security posture of industrial communication environments by identifying weak authentication, insecure protocol configurations, exposed services, and potential attack paths.
  • Collaborate with engineering and product teams to reproduce security findings, validate fixes, and provide remediation recommendations aligned with OT security best practices.

πŸŽ“ Education

B.Tech, Computer Science & Engineering (IoT, Cyber Security & Blockchain) Institute of Engineering and Management, Kolkata, India β€” GPA: 9.12 August 2021 – August 2024

Diploma, Computer Science & Technology Elitte Institute of Engineering and Management, Kolkata, India β€” GPA: 8.60 August 2018 – August 2021


πŸ“œ Certifications

  • Certified Ethical Hacker (CEH)
  • IBM Cybersecurity Analyst (Professional Certificate, Authorized by IBM)
  • Ethical Hacking (NPTEL, IIT Kharagpur)

πŸ† Honors & Awards

  • Certificate of Appreciation – Beyond Excellence, Tata Consultancy Services (TCS) β€” for outstanding contribution and commitment in the Schneider Electric Penetration Testing engagement (2026)
  • Star of the Quarter Award, Tata Consultancy Services (TCS) β€” for outstanding contribution and performance in OT security assessment activities

🀝 Let’s Connect

If you’re passionate about IoT/OT security, embedded systems, or industrial penetration testing, feel free to reach out or connect with me on LinkedIn.

β€” Harsh Srivastava

This post is licensed under CC BY 4.0 by the author.