it Vishrut Malhotra — Full‑stack engineer & security
DEV_MODE = ON press ESC to exit
Vishrut Malhotra
Resume
Available May 2026 · San Francisco, CA

Vishrut Malhotra.

Full‑stack engineer studying CS at San Francisco State. I build secure, performant systems — recently shipped a Flask + React platform syncing 10k+ records/min at Danieli Corus, and automated 70% of Level‑1 SOC analyst tasks.

Internships
03
Simulanis · Danieli · BEL
Projects shipped
05+
Full‑stack · ML · Security
Records / min
10k
w/ OAuth2 · RBAC
L1 SOC automated
70%
Python · Ansible · SIEM
Python · TypeScript · React · Next.js · GraphQL · Flask · FastAPI · Node.js · Prisma · PostgreSQL · Docker · Kubernetes · AWS · Linux · Twilio · scikit‑learn · NLTK · Python · TypeScript · React · Next.js · GraphQL · Flask · FastAPI · Node.js · Prisma · PostgreSQL · Docker · Kubernetes · AWS · Linux · Twilio · scikit‑learn · NLTK ·
01 — About

I care about systems that hold up under load, code that other people can read, and security that doesn't get in the way of users.

I'm a senior CS student at San Francisco State, graduating May 2026. I cut my teeth at Bharat Electronics building IoT monitoring pipelines, spent summer 2025 at Danieli Corus writing a Flask + React data‑sync platform with OAuth2, RBAC, and end‑to‑end encryption, and most recently at Simulanis building React + GraphQL frontends for AR/VR training reaching 5,000+ users.

Outside of internships I keep shipping — pro bono delivered T'chaka, a live restaurant platform for a Haitian restaurant in Oakland; CarbonWise, a CI‑carbon dev tool tracking 20k+ GitHub jobs; a Random Forest SOC triage bot; a Dockerized fake‑news API at 92% accuracy with LIME / SHAP explainability; and a local‑first password manager with proper KDF + AES‑GCM.

Selected as a Black Hat USA 2025 Scholar — full scholarship to attend the conference in Las Vegas. Currently on the job hunt — open to new‑grad software / security engineering roles starting summer 2026, or an interesting project to build.

02 — Selected Work

Things I've built.

A curated slice of recent work — full‑stack platforms, security tooling, ML, SaaS previews, and the odd JavaFX game. Tap any card for the project link.

// 01 · Featured · Live · Pro bono
T'
React · Flask · Twilio

T'chaka — Haitian Restaurant

A full‑stack restaurant management system built pro bono for a Haitian restaurant in Oakland — live menu, reservation booking, Twilio SMS confirmations, admin dashboard, CI/CD on Railway. Real customers, no fees, no SaaS middleman.

ReactTailwindFlask / FastAPIPostgreSQLTwilioRailway
Role
Full‑stack · Solo · Pro bono
Surface
Menu · Reservations · SMS · Admin
// 02 · Senior project
Node · MySQL · AWS

ClarityAI

Senior project — AI‑tool discovery engine for students. Built with a team of 4, full security stack, deployed to AWS, validated with a real usability study.

Expressbcryptcsurf
// 03 · OSS · ML
RF
Python · scikit‑learn

Autonomous SOC Bot

SOC automation with SIEM ingestion, threat enrichment, and a Random Forest triage classifier on 15+ engineered features. Flask dashboard for the metrics.

Random ForestFlaskSIEM
// 04 · In progress · Dev tool
C₂
Next.js · GitHub CI

CarbonWise

CI‑integrated dashboard estimating carbon output across 20k+ GitHub jobs — real‑time badges + AI insights for greener pipelines.

Next.jsPrismaOpenAI
// 05 · OSS
Python · AES‑GCM

SecurePass

Local‑first password manager — AES‑256‑GCM + PBKDF2, clipboard auto‑clear, password strength meter. Zero plaintext on disk, zero network.

PythonCryptographySQLite
// 06 · Live
12
Node · Render

Skip‑Bo (web)

Multiplayer web port of the card game with accounts, a lobby, and a real turn‑state engine. Shipped as my SFSU Web App Dev final.

Node.jsSessionsRender
// 07 · In progress · Research
GPT · Claude

AI Resume Eval

Research project comparing GPT vs. Claude on resume generation — testing whether ATS‑aware prompts actually beat baseline prompts, with a real rubric.

PythonJupyterOpenAIAnthropic
// 08 · OSS · API
≈92%
scikit · LIME · Docker

Fake News Detector

TF‑IDF + logistic regression behind a Dockerized Flask API with LIME / SHAP explainability. 92% accuracy, <200ms latency at 10k+ req/day.

scikit‑learnFlaskDocker
// 09
Java · JavaFX

JavaFX Arcade Game

Multi‑level desktop game built in JavaFX with Scene Builder. OO architecture, custom physics, and a leaderboard that actually scrolls.

JavaJavaFXScene Builder
// 10 · Live · Preview
Next.js · Prisma

Receptionist.ai

Next.js preview for local businesses — simulator, conversations, bookings, and a small owner dashboard. Prisma + Postgres (Supabase‑oriented), session auth, mock LLM / SMS / voice / calendar until real keys; honest preview, not production telephony.

Next.js 15TypeScriptTailwind v4PrismaPostgreSQL
03 — Experience

Where I've worked.

  1. 2025
    Dec — Jan '26

    Frontend Developer — React & GraphQL

    Simulanis · AR/VR · Remote
    • Built responsive React components from Figma for AR/VR training modules used by 5,000+ users.
    • Integrated GraphQL APIs and tuned the data layer — cut frontend load time by ~30% and enabled real‑time updates across training surfaces.
    ReactGraphQLTypeScriptFigmaAR/VR
  2. 2025
    Jun — Aug

    Full‑stack Engineering Intern

    Danieli Corus · Remote
    • Built a Flask + React data‑sync platform handling 10k+ records/min across services, integrating OAuth2, RBAC, and end‑to‑end encryption. Improved data accuracy by 35%.
    • Cut system downtime 25% by introducing exponential retry, layered caching, and graceful fault handling around flaky external APIs.
    FlaskReactOAuth2RBACPostgreSQL
  3. 2023
    Jun — Aug

    Software Development Intern

    Bharat Electronics Limited (BEL) · Ghaziabad, IN
    • Shipped a Flask + Shell dashboard monitoring 32+ IoT sensors in real time, with alerting, threshold tuning, and visual metrics.
    • Containerized services with Docker and stood up CI/CD pipelines, dropping deploy time from hours to minutes.
    FlaskShellDockerCI/CDIoT
03.5 — Honors
Cybersecurity · Full scholarship
Las Vegas · Aug 2025

Black Hat USA 2025 · Scholar

Selected to attend Black Hat USA 2025 on a full scholarship — recognition for sustained work in information security, with priority access to advanced training, briefings, and the wider security community. The shortest summary of a year of CTFs, papers read, and security side projects that didn't ship in a single line.

Information security Recognition 2025 cohort
04 — Toolkit

What I reach for.

Languages

04
PythonJavaJavaScriptTypeScriptC/C++SQLBashHTML/CSS

Frameworks & libraries

11
ReactNext.jsFlaskFastAPINode.jsExpressGraphQLTailwindPrismascikit‑learnNLTK

Data

04
PostgreSQLMongoDBMySQLSQLite

Cloud & DevOps

07
DockerKubernetesAWSRailwayGitHub ActionsAnsibleLinux

Security

05
OAuth2RBACAES‑GCMSIEMThreat triage

Relevant coursework

San Francisco State
Data Structures Algorithms Database Systems Operating Systems Software Engineering Computer Networks Linear Algebra Probability Human‑Computer Interaction Web Development
05 — Contact

Let's build
something good.

I'm looking for new‑grad software & security engineering roles starting summer 2026 — or a fun project to build. If you've got an interesting team, an annoying bug, or just want to chat — my inbox is open.