Nandakishor Dakka

Computer Science — Georgia Tech

I'm a junior at Georgia Tech studying CS with a focus on security. I'm most interested in the intersection of AI and offensive/defensive security — building tools that actually do something. This past summer I was at Vanguard on their security engineering team; I'm joining Tesla's Industrial Security group in January. Outside of internships, I research power grid resilience and spent last year hunting AI-generated malware at GT's CyFi Lab.

Education

Georgia Institute of Technology
B.S. Computer Science · Cybersecurity & Intelligence · Atlanta, GA · 2025–2028

GPA: 4.0 / 4.0

Data Structures & Algorithms · Computer Systems I & II · Systems Design · Machine Learning

GreyHat (Cybersecurity) · Competitive Programming @ GT · Science & Technology Policy Connections (S&TPC)

Published in Journal of Science Policy & Governance (JSPG) · FBLA National Champion (Network Design/MIS) · National Cyber League (Top 1%) · GIAC Advisory Board · National Cyber Scholar with Honors · UNG Cyber Scholar with Honors

Experience

Tesla
Industrial Security Engineer Intern (Incoming) · Austin, TX · January 2027–April 2027
  • Starting January 2027 — working on AI tooling for OT/ICS systems and analyzing hardware, software, and network architecture across Tesla's industrial infrastructure.

Vanguard
Security Engineer Intern · AI/ML · Charlotte, NC · May 2026–July 2026
  • Built a RAG system in Python and TypeScript that lets the security team search 5,000+ internal documents in seconds instead of digging through wikis — cut retrieval time by 85%.
  • Wrote validation pipelines to catch IAM least-privilege violations across cloud services before they became real problems, covering 100+ developer and service accounts.
  • Wired Policy-as-Code checks into 50+ CI/CD pipelines so security misconfigurations get flagged before they hit production — reduced compliance incidents by 40%.

MGT Impact Solutions
Security Engineer Intern · Automation & Threat Intelligence · Norcross, GA · March 2025–April 2026
  • Automated most of the repetitive alert triage in Tines — 200+ monthly alerts, MTTR down 30%.
  • Wrote 15+ MITRE ATT&CK detection rules with automated validation tests, hitting 95%+ coverage across priority techniques.
  • Built a C# Windows Event Log forwarder for 40+ machines and integrated AWS and OCI telemetry into the SIEM pipeline — processing 500K+ events per day.

Research

GROWER — Grid Resilience, Outage, Weather, Emergency Response
Software Engineer · Data Infrastructure & Cloud Computing · Atlanta, GA · January 2026–Present
  • Building the data infrastructure layer — AWS pipelines that ingest and normalize outage records from 17 utilities across 12 states into a schema researchers can actually use.
  • Working on scraping and CloudWatch workflows to feed ML analysis of how outages affect different communities. Dataset is up to 2M+ historical records.

Georgia Institute of Technology — CyFi Lab
Undergraduate Malware Research Assistant · Atlanta, GA · August 2025–March 2026
  • Wrote YARA rules to hunt AI-generated malware in VirusTotal datasets — found 10+ malicious samples across 50,000+ binaries, staying under 2% false positives.
  • Reverse-engineered 5+ info-stealers with IDA Pro and Angr to map their behavior and IOCs. Mostly static analysis, with dynamic runs when samples were too obfuscated.

Projects

AI CTF LLM Agent
Python · LiteLLM · MCP · Sponsor: Georgia Tech SSLab
  • Wanted to see how far an LLM could get on real security challenges with the right tooling. Built an orchestration framework that gives the model access to GDB, Ghidra, and other tools via MCP — sponsored by GT's SSLab.
  • Benchmarked against 30+ CTF challenges across pwn, reversing, and web. It consistently solved them 5× faster than a human baseline.

AI-Driven IAM Auditing Agent
Python · Neo4j · Docker · Streamlit · OpenAI/Anthropic
  • IAM sprawl is one of those problems everyone knows about but nobody wants to untangle manually. Built a platform that ingests SailPoint and AWS IAM data into a Neo4j graph to surface zombie permissions and privilege escalation paths across 3,000+ assignments.
  • The LLM layer generates MITRE-mapped findings and Terraform remediation suggestions — cut estimated manual remediation effort by 60%.

Malware Analysis Sandbox
Go · Libvirt API
  • Wanted a sandbox I could control end-to-end — fast spin-up, clean VM isolation, real behavioral data. Built it in Go with the Libvirt API, under 30 seconds per environment.
  • Captures process activity, filesystem changes, and network connections post-execution. Analyzed 200+ samples, getting 15+ behavioral indicators each.

Skills

C++, C#, Go, Java, JavaScript, Python, TypeScript, .NET, Linux, Git/GitHub, IDA Pro, Angr

AWS (Lambda, API Gateway, CloudWatch, SSM) · Wireshark · Nessus · Tines · Kali Linux · OCI · Docker · CI/CD

GSEC · GFACT · CompTIA Security+ · IT Specialist (Java, Software Development, Network Security)