Profile_Summary.txt

AppSec Engineer & Red Teamer with 3+ years of experience securing web, mobile, and cloud infrastructures. Expert in identifying critical vulnerabilities (IDOR, RCE, Business Logic) and integrating security into the SDLC via GitLab CI/CD. Proficient in automating security workflows using Python and custom tooling (Jira, Splunk, Endpoint Central). Proven track record of responsible disclosure, including a high-impact RCE finding on an Indian Government platform.

/var/log/experience

Application Security Engineer // Zoho Corporation Pvt Ltd
JULY 2022 - PRESENT
  • Executed comprehensive penetration tests on 20+ web and Android applications, adhering to OWASP MASVS and MITRE ATT&CK frameworks.
  • Conducted secure code reviews for Java, Python, and C++ codebases, identifying and remediating 100+ security flaws.
  • Led red team engagements focusing on lateral movement and privilege escalation, resulting in the hardening of internal network defenses.
  • Integrated automated security scans (SAST/DAST) into GitLab CI/CD pipelines, reducing vulnerability escape rate by 40%.
  • Collaborated with development teams to implement Secure SDLC practices, ensuring security is baked in from design to deployment.
Security Analyst Intern // Zoho Corporation Pvt Ltd
JAN 2022 - JUNE 2022
  • Assisted in the triage and remediation of security incidents using Splunk and Endpoint Central.
  • Developed Python scripts to automate log analysis, reducing manual triage time by 30%.
  • Participated in vulnerability assessments, contributing to the discovery of critical IDOR and AuthZ bypass issues.
Penetration Testing Intern // Abhedya Futuristic Pvt Ltd
MAY 2021 - SEPT 2021
  • Conducted vulnerability assessments on 50+ web/mobile apps, identifying critical flaws including SQLi and XSS.
  • Created 10+ custom CTF challenges to train internal teams on exploit development and secure coding.
  • Automated recon workflows using Python and Bash, streamlining the initial phase of assessments.

Loaded_Modules (Skills)

// Offensive Security

Red Teaming
Exploit Dev
IDOR Exploitation
Business Logic Flaws
Mobile Pentesting

// Application Security

Secure SDLC
Code Review (Java/Python/C++)
Threat Modeling
SAST/DAST
API Security

// Tooling & Frameworks

Burp Suite
ZAP
MobSF
Frida
Drozer
Splunk
GitLab CI
Endpoint Central

// Automation & Scripting

Python
Bash
Pipeline Scripting
Custom Tooling

// AI-Augmented Security

Prompt Engineering
LLM-Assisted Recon
AI Log Analysis
Pattern Detection

Certifications

  • CISSP // Cybrary
    Issued: 2022
  • CNSS // ICSI
    Certified Network Security Specialist

Achievements

  • Responsible Disclosure: Indian Govt
    Identified and reported a critical RCE vulnerability. Collaborated with NCIIPC for remediation.
  • 50+ Responsible Disclosures
    Reported security flaws in various platforms including ShopClues (Hall of Fame).

/usr/bin/projects

Malware Static Analysis Sandbox // Python, FastAPI, YARA
Private Tool

An offline, VM-contained platform for static analysis of suspicious files (PE, PDF, Office). Integrates YARA, capa, FLOSS, and oletools with a FastAPI backend to detect malicious patterns and extract IOCs without execution.

Subdomain Finder // Python & Tkinter
View Repo

A reconnaissance tool featuring a GUI to enumerate subdomains using wordlist-based brute-forcing. Optimized for speed with multi-threading to map attack surfaces efficiently.

Port Scanner // Python Socket
View Repo

A multi-threaded network scanner built to identify open ports and services. Used for initial internal network reconnaissance to identify potential entry points.

Mass URL Scanner // Python & Requests
View Repo

A bulk URL analysis tool to check status codes and reachability. Automates the validation of large asset lists during external infrastructure assessments.

Publications

Colonial Pipeline Attack (medium.com)

A comprehensive analysis of the Colonial Pipeline ransomware incident, dissecting the attack vector, impact on critical infrastructure, and lessons learned for industrial cybersecurity.