Status: Active & Securing

Shielding Systems. Leading Compliance.

A highly skilled Cybersecurity Professional specializing in **VAPT**, **IT Governance**, and enterprise security audits. Master of Science in Cybersecurity & Pen Testing, CEH certified, and ISO Lead Auditor (ISO 27001, 20000, 22301).

Er. Apurva Nepal Profile
CEH CERTIFIED
ISO 27001 AUDITOR
Er. Apurva Nepal Graduation
About Me

Vulnerability Specialist & Cybersecurity Academic

With a solid engineering background combined with a Master’s degree in **Cybersecurity and Pen Testing** from Middlesex University, I bridge the gap between academic theory, corporate security training, and rigorous compliance implementation.

Whether designing modern academic curricula, conducting Vulnerability Assessments and Penetration Testing (VAPT) for logistics companies, or steering e-commerce systems to absolute safety, my mandate is constant: proactive protection and robust IT governance.

MSc. Cybersecurity

Middlesex University (UK) – Majors: Networking, Pen Testing, Blockchain.

B.E. Electronics

SIT, VTU (India) – Electronics and Communication Engineering.

NEC Lic. 7763

Registered Professional Engineer with the Nepal Engineering Council.

Enterprise Trainer

Delivered cybersecurity training for corporate clients and academia.

Core Competencies

Professional services ensuring information security management systems, regulatory compliance, and resilient application defense.

Vulnerability Assessment & Pen Testing (VAPT)

Conducting active security analysis, mapping networks, simulating breaches, and compiling detailed remediation actions utilizing industry-standard frameworks and toolsets (NMAP, Burp Suite, Metasploit, Nessus).

IT Governance & ISO Auditing

Implementing and auditing Information Security Management Systems (ISMS) as a Lead Auditor certified in **ISO 27001:2013**, **ISO 20000:2018** (ITSM), and **ISO 22301:2019** (Business Continuity).

Academic Leadership & Training

Crafting forward-thinking cybersecurity syllabi, leading security workshops, and training engineers, developers, and university classes on threat analysis, malware, and secure systems design.

Secure E-Commerce Lifecycle

Overseeing system architectures from initialization to deployment. Ensuring bulletproof payment integration, strict encryption protocols, database sanitization, and cloud security compliance.

ISO 27001 Compliance Evaluator

Assess your organizational compliance posture. Toggle controls to evaluate risk severity and view recommended remediation steps instantly.

Implemented Security Controls

Regular Penetration Testing (VAPT)

Systems undergo full external and internal VAPT checks at least once a year.

Access Control & MFA

Structured role access (RBAC) with mandated multi-factor authentication.

Encryption (At-Rest & In-Transit)

Enforced database hashing (AES-256) and TLS 1.3 transport security.

Disaster Recovery & BCP

Daily offsite backups with tested recovery time objectives (RTO/RPO).

Staff Security Training

Formal security onboarding and active quarterly phishing training campaigns.

Audit Assessment Status

0% COMPLIANT
CRITICAL RISK

ISMS Status: Non-Compliant

Your network lacks basic protection frameworks. Vulnerable to data breaches, session hijacking, and severe compliance penalties.

Suggested Remediations:
  • Audit system databases for plaintext parameters.
  • Implement a firewall configuration and secure credential cache controls.

Technical Competencies

Direct exposure, hands-on operations, and compliance policies mapping.

VAPT Tools & Systems Active

NMAP Burp Suite Metasploit Nessus Snort IDS Wireshark Nikto Skipfish Wapiti Sqlmap Cisco Packet Tracer

Security Frameworks & Policies Compliance

ISO 27001 (Security) ISO 20000 (ITSM) ISO 22301 (BCMS) CIS Controls E-Governance Standards Local Governance SDGs Vulnerability Remediation IT Risk Management

Development & Logic Engineering

Python Bash Scripting SQL MATLAB Verilog VHDL Assembly Logic

Operating Systems Platform

Kali Linux Ubuntu Linux Raspbian (ARM) Windows Server Embedded Real-Time OS

Professional Experience

Steering education systems, corporate compliance, and digital security assets.

Roles Timeline

Cybersecurity Teacher @ King’s College

December 2024 - Present | Kathmandu, Nepal

Interactive Module Instruction

  • Deliver advanced educational modules covering network protection, penetration testing architectures, and governance structures.
  • Design and facilitate hands-on laboratories utilizing security environments, guiding students through practical attack and defense simulations.
  • Empower learners to tackle certifications and real-world security engineering challenges.
Er. Apurva Nepal

Cybersecurity Module Leader @ IIMS College

December 2022 - 2025 | Academic Leadership

Curriculum & Research Leadership

  • Formulated and implemented an forward-thinking curriculum integrating AI in defense, Cloud Security layers, and Distributed Ledger architectures.
  • Conducted security workshops and capacity-building seminars for both faculty and undergraduate majors.
  • Supervised research projects focused on threat modeling, cryptographic schemes, and secure e-governance systems.
Er. Apurva Nepal

Lead Auditor & Enterprise Trainer @ Pathivara Innovations

April 2023 - May 2024 | Part-Time Enterprise Security

ISO Compliance & E-Commerce Implementations

  • Led security implementations, risk management, and VAPT workflows for modern e-commerce sites: *Jetset Gleam*, *Pigs and Panda*, and *Atya Law Firm*.
  • Served as Lead Auditor for **Avalon Logistics**, conducting comprehensive security audits, network penetration checks, and ensuring alignment with **ISO 27001:2013** standards.
  • Delivered executive cybersecurity training on data protection, corporate governance, and threat posture.
  • Consulted on integrating Sustainable Development Goals (SDGs) into local municipalities via digital systems.

Cybersecurity Teacher @ Islington College

March 2022 - December 2022 | Academia

Case Study & Threat Analysis Methodologies

  • Introduced case study-based instructions on high-profile global cybersecurity breaches, analyzing system weaknesses.
  • Created real-world scenarios covering local government security challenges and e-governance vulnerabilities.
  • Managed core grading, practical assessments, and virtual lab environments.

Cybersecurity Teacher @ Softwarica College

June 2021 - March 2022 | Interactive Training

Hands-On Laboratory Guidance

  • Delivered hands-on modules in network engineering, defensive architectures, and VAPT tooling.
  • Trained students in conducting sniffing, spoofing, and SQL Injection mitigations.
  • Structured assessments based on real penetration metrics and report generation.

Unofficial Consultant @ CBI, Kalimati

Advisory / Forensic Cases

Digital Forensics & Threat Analysis

  • Provided security expertise, digital forensics, and threat analysis for cybersecurity incidents.
  • Assisted in analyzing logs, identifying attack patterns, and defining threat origin timelines.
  • Collaborated on security best practices for public sector departments.
Er. Apurva Nepal

Projects & Research

Innovative systems, security tools, and publications resolving cybersecurity dilemmas.

🐍
Active VAPT

Automated Vulnerability Detection Program

Developed a Python-based tool designed to automatically probe, map open ports, and identify vulnerabilities within Metasploitable targets.

🔗
Cryptography

Blockchain-Secured Health System

Architected a secure framework to store, encrypt, and validate clinical patient records utilizing private blockchain nodes to guarantee tamper-proof medical logs.

🧠
Publication

EEG-Based Brain-Computer Interface

A government-funded, published research project focused on creating BCI interfaces using EEG signals to assist disabled individuals with autonomous actions. Published in 3ICMRP-2016.

🔑
Exploits

Stored Passwords Extraction & Decryption

Created an automated script that securely extracts and decrypts credentials stored locally in Chrome database files, proving structural risks of client-side caching.

🤖
Robotics

Robotic Arm & Autonomous Vehicles

Supervised and engineered hardware prototypes of manual & autonomous robotic vehicular systems, focusing on path planning and servo feedback loop logic.

🪟
Automation

Autonomous Closing Window System

Designed an automated window mechanism that detects environmental changes (rain, heavy wind) via analog sensors and triggers stepper motors for closure.

Get in Touch

Initiate audits, consult on security postures, or request training services.

Contact Terminal

Let's Build Something Secure

Whether you need a full enterprise compliance review, a web system audit, or an expert cybersecurity instructor, send a message.

📞
Call Directly

+977-9802358943

✉️
Direct Mail

nepalapurva9@gmail.com

📍
Operating Location

Kathmandu, Nepal

root@nepal:~# contact_audit
$
$
$