bash — rishabkharidhi.com

$ whoami

Rishab Kharidhi

$ cat role.txt

$ ./status --now

Security Engineer @ Riot Games · Product Security · Los Angeles, CA

view side projects → get in touch
~/about

Securing the products that millions play.

I’m a Security Engineer on the Product Security team at Riot Games, where I help keep the products and platforms behind the games secure.

My work lives in application security and privacy: threat modeling, breaking things on purpose, and fixing what breaks. Before Riot I built cloud security controls at AWS Security Hub. Outside of work you’ll find me deep in a CTF (top 7% on TryHackMe), taking apart a binary in IDA, or building small things for fun.

~/experience

Where I’ve worked

Riot Games

Jun 2023 → Present

Security Engineer · Product Security · Los Angeles, CA

  • Security engineering on the Product Security team, hardening the products and platforms behind Riot's games.
  • Threat modeling, security reviews, and building controls that keep player-facing systems safe at scale.

Amazon Web Services

Apr 2022 → Jun 2023

Security Engineer I · Security Hub · New York, NY

  • Built and maintained security controls in Python, backed by AWS Config rules that evaluate services against AWS Best Practices, PCI DSS, CIS, and NIST.
  • Wrote unit tests with MagicMock and ran thorough code reviews to keep controls compliant with industry standards.
  • Handled on-call support, partnering with cross-functional teams to ship fixes and public-facing documentation.
  • Ran region testing with CloudFormation to deploy infrastructure and config rules at scale.

Securonix

Aug 2020 → Apr 2022

Security Engineer / SIEM Consultant · SIEM & UEBA · New York, NY

  • Worked with SOC/CSIRT client teams to implement Securonix SIEM and UEBA, running analysis on aggregated logs.
  • Led high-pressure POCs that lifted team revenue 20% by building end-to-end MITRE ATT&CK threat models and policies.
  • Designed 800+ use cases per POC surfacing beaconing, enumeration, insider threat, account misuse, and endpoint malware.

Webroot

May 2019 → Dec 2019

Threat Research & Development Intern · An OpenText company · Broomfield, CO

  • Reverse-engineered malware with static and dynamic analysis.
  • Built modules for PE file disassembly, YARA scanning, and containerized dependencies — cutting build effort 30%.
// education

University of Colorado Boulder

M.S. Cybersecurity

Aug 2018 – May 2020 · Boulder, CO

GPA 3.9/4.0 · Graduate TA for Digital Forensics & Penetration Testing · William E. Rapp Fellowship

PES University

B.Tech, Electronics & Communication

Aug 2014 – May 2018 · Bangalore, India

Minor in Computer Science Engineering

~/side_projects

Things I built for fun

./run live

Wordle Opener

Optimal starting-word solver

A tool that ranks Wordle opening guesses by expected information gain — entropy scoring over the full answer set to find the words that carve the search space fastest.

PythonInformation TheoryWeb
open /wordle-opener ↗
./run live

Mahjong

Tile game in the browser

A playable Mahjong build — tile matching, layouts, and scoring, running entirely client-side.

JavaScriptGameWeb
open /mahjong ↗
// security & systems work

Software Exploits & Anti-RE Mitigation

Analyzed Windows and Linux binaries for vulnerabilities; wrote C exploits for overflow attacks and used IDA + IDA Python to detect and mitigate anti-reverse-engineering techniques.

CIDA ProReverse Engineering

Forensic Data Carver

Python tool that recovers and extracts files directly from a raw filesystem dump for forensic analysis.

PythonForensics

Web App Security — Independent Study

Threat analysis of a lab web app with hands-on XSS, SQL injection, and CSRF. Ongoing CTF work — top 7% worldwide on TryHackMe.

OWASPCTFPentesting

Linux Systems Administration

Stood up a corporate network for 20 employees on Linux — DHCP, DNS, and web servers configured end to end.

LinuxNetworking
~/skills

The toolkit

App Security
Threat ModelingSTRIDEOWASP Top 10NISTMITRE ATT&CK
Cryptography
Symmetric & AsymmetricPKIDigital CertsHashingBlock & Stream Ciphers
Networking
TCP/IPTLSIPSecDHCPDNSVPNFirewallsSnort
Languages
PythonCC++GoSQLBashPowerShellx86
Tooling
IDA ProWinDbgGDBBurp SuiteMetasploitWiresharkDockerSplunk
AWS
Security HubConfigLambdaCloudFormationIAMEC2S3CloudWatch
~/contact

Let’s connect.

Open to conversations on application security, reverse engineering, or a good CTF. Hiring for AppSec? My resume’s a click away.