Dr. Arjun Mehta
PhD, OSCP, CISSP

Heads the offensive security faculty, with a career spanning red-team leadership and advanced penetration testing for global enterprises.
Dr. Arjun Mehta is a Professor and Head of Ethical Hacking and Penetration Testing at GICCT, where he leads the institute’s offensive security faculty. With a career built on finding the weaknesses that others miss, he has spent more than fifteen years thinking like an attacker so that the organisations he works with can defend like professionals.
Background and career
Dr. Mehta began in network administration before moving into security, where he discovered a talent for the adversarial mindset that defines great penetration testers. He went on to lead red-team operations for large enterprises, simulating the tactics of real-world attackers against banks, technology companies, and critical infrastructure. That work took him deep into the methods adversaries actually use — not the textbook versions, but the messy, creative, and persistent techniques that succeed against well-defended targets.
His doctoral work focused on exploit development and the economics of vulnerability discovery, examining why certain classes of flaw persist despite being well understood. Before joining GICCT he served as a principal security consultant, leading assessments for clients who needed to know not whether they could be breached, but exactly how, and what it would cost them. He holds the OSCP and CISSP certifications and remains an active practitioner alongside his teaching.
Areas of expertise
Dr. Mehta’s expertise spans the full offensive security spectrum: network and web application penetration testing, exploit development, privilege escalation, lateral movement, and red-team operations that test not just technology but people and processes. He is particularly known for his work in adversary simulation — engagements that replicate the behaviour of specific threat actors to test whether an organisation’s defences would actually detect and respond to a real campaign.
He also brings deep knowledge of the reporting side of the discipline, which he considers as important as the technical work itself. A penetration test is only valuable if its findings drive change, and he has spent years learning to translate technical risk into the language executives use to make decisions. This focus on impact over theatrics is something he works hard to instil in his students.
Teaching philosophy
Dr. Mehta teaches offensive security the only way he believes it can be learned: by doing it. His courses put students in the attacker’s seat against deliberately vulnerable environments, where they must find their own way in, escalate their access, and document everything they touch. He believes the gap between understanding a technique and being able to execute it under realistic conditions is enormous, and only hands-on practice closes it.
He is equally insistent on ethics and discipline. Offensive skills carry real responsibility, and he frames every technique within the rules of engagement, legal boundaries, and professional standards that separate an ethical hacker from a criminal. His students leave not just with technical capability but with the judgement to wield it responsibly.
A practitioner’s perspective
What sets Dr. Mehta’s teaching apart is that he still works in the field. He has seen how the threat landscape shifts year to year — how techniques that were cutting-edge become commodity, how defenders adapt, and how attackers innovate around new controls. This currency matters enormously in offensive security, where knowledge ages quickly and last year’s playbook may no longer work. He brings fresh, relevant examples into every cohort, drawn from the kinds of engagements his students will eventually run themselves.
He is also candid about the realities of the profession: the long hours of reconnaissance that precede a single successful exploit, the discipline required to stay within scope, and the professional maturity needed to deliver difficult findings to clients who may not want to hear them. He believes preparing students for these realities is as important as teaching them any specific tool or technique, and that honesty about the work is part of respecting the people who choose to enter it.
At GICCT
At the institute, Dr. Mehta leads the flagship Advanced Penetration Testing program and oversees the broader offensive security curriculum, mentoring students as they prepare for demanding certifications such as the OSCP. He sees his role as producing not certificate-holders but capable operators — professionals who can walk into a real engagement and deliver work that genuinely improves their client’s security. For students serious about a career in offensive security, learning from someone who has led real red-team operations against hard targets is the closest thing to apprenticeship the field offers.