BSc (Hons) Computing Systems · Final Year · London, UK
Final-year Computing Systems student passionate about building privacy-first, secure systems. I combine engineering rigour with a security-first mindset — and always document the why behind every decision, not just the what.
Full Stack Development
Security Architecture
ML & Anomaly Detection
2 active builds264+ tests tracked84% peak coverage
In Progress
IoTSentinel
ML-powered network security monitor for Raspberry Pi. Zeek for deep packet inspection + River ML for online anomaly detection, with an educational dashboard explaining every alert.
Business value: Cuts SOC-style alert fatigue in small/home networks by filtering noise while keeping high-risk events visible and explainable.
Processes 24/7 network flows on Raspberry Pi 5
84% anomaly detection accuracy via Half-Space Trees algorithm
Full-stack cyber threat intelligence platform. Tracks dark web data breaches, maps global cyber-attacks with geo-visualisation, and monitors compromised assets via automated alert pipelines.
Business value: Compresses analyst triage time by centralizing breach telemetry, geo-context, and automated alerts in one decision surface.
Aggregates breach events from 50+ OSINT sources
Geo-attack map with animated D3.js connection paths
Zero-trust API — JWT auth + Redis rate limiting on all endpoints
Production marketplace connecting users with verified local tradespeople — plumbers, electricians, and more. Stripe payments, Google Maps, full AWS CI/CD.
Business value: Improves booking conversion with secure payments and trust controls while minimizing PCI burden and deployment risk.
OWASP Top 10 mitigations applied across the full stack from day one
PCI-compliant Stripe Checkout + webhooks — card data never touches the server
Zero-downtime AWS EB deploys via GitHub Actions with test gates
bcrypt (cost 12) + JWT refresh-rotation auth — tokens in httpOnly cookies
No daemon overhead and safer write behavior for SD-card storage.
SSE for live dashboard
Lower CPU and RAM overhead than WebSocket keepalive traffic.
Zeek log rotation (100MB)
Prevents disk exhaustion on constrained local storage.
Runtime Envelope
Target RAM profile< 1.2GB
Storage policyWAL + rotation
Expected throughput24/7 home traffic
Security Mindset
// what separates security thinking from regular engineering
Zero Trust default stanceDefense in Depth layered controlsResidual Risk always documented
Philosophy
I design systems assuming breach by default. The question is never "will we be attacked?" — it's "what is the blast radius when we are?" Every architectural decision I make is shaped by this adversarial lens.
Good security is also understandable security. A perfectly hardened system that nobody knows how to operate is a liability. I document the "why" behind every control so anyone can reason about trust boundaries — that's why IoTSentinel explains its alerts in plain English rather than raw anomaly scores.
Privacy is a first-class architectural constraint — not a feature bolted on at launch. I apply data minimisation from the first API endpoint, because retrofitting privacy is 10x harder than designing it in.
Core Principles
Zero Trust
Verify every request regardless of network origin. No implicit trust.
Least Privilege
Components receive only the minimum permissions needed — nothing more.
Observability-First
Full audit trails from day one. You can't defend what you can't see.
Defence in Depth
Layered controls — no single failure leads to total compromise.
Journey
// from curiosity to production-grade security engineering
2023-2026 focused build period6+ major projects1 security specialization
2026 — Present
BreachLens — Cyber Threat Intelligence Platform
Full-stack threat intel platform: dark web breach tracking, geo-attack mapping, automated asset monitoring. Flask + Angular + MongoDB + Docker.
2025 — Present
IoTSentinel — ML Network Security on Raspberry Pi
Deployed River ML anomaly detection on-device. 84% accuracy, 24/7 flows, 180+ automated tests, explainable alert dashboard.
2025
Botium Toys — Formal Security Audit
End-to-end compliance audit (PCI DSS, GDPR, SOC). Identified 12 critical control gaps, produced CVSS-weighted remediation roadmap with Python risk tooling.
2024
Local Services Directory — Production Full Stack Platform
React + Node + PostgreSQL marketplace with Stripe, AWS deployment, CI/CD via GitHub Actions. OWASP Top 10 mitigations and JWT auth from day one.
2023
BSc (Hons) Computing Systems — Started
Began university with a focus on networks, operating systems, and security. Started applying concepts immediately through hands-on projects and CTF challenges.
Tech Stack
// 35+ technologies across security, backend, frontend & DevOps
35+ technologiesFull-stack dev to deploySecurity-first by default
// hover or scroll in this panel to traverse stack clusters
I'm Ritik Sah — a final-year BSc (Hons) Computing Systems student in London, with a deep focus on cybersecurity. My core strengths are problem-solving, analytical thinking, and technical adaptability.
Whether it's tracing how an ICMP flood propagates through a network, designing a threat model for an API, or optimising a streaming ML pipeline for constrained hardware — I approach every challenge with structured, first-principles thinking.
I believe the best security engineers are also great communicators. Every project I build is documented to explain the "why" — so non-technical stakeholders can understand trust boundaries and make informed decisions. IoTSentinel's plain-English alert explanations are a direct expression of this belief.
Adversarial ML
Threat Intelligence
Network Forensics
Open Source
Education
BSc (Hons) Computing Systems
Final Year · London, UK · 2023 – Present
Focus Areas
Network Security & Intrusion Detection
Zeek IDS · Packet Analysis · Anomaly Detection
Threat Intelligence & Security Auditing
NIST CSF · PCI DSS · GDPR Compliance
Full Stack Security Engineering
OWASP Top 10 · Zero-Trust APIs · CI/CD Security
Let's Build Secure Systems Together
Open to internships, placement years, and graduate roles in cybersecurity engineering. If you need someone who can design secure systems and explain the tradeoffs clearly, let's talk.