Passionate Application Security Professional with 3.6 years of experience eager to secure VAPT role to build secure applications.
Hands-on with DAST,SAST and manual penetration testing.
Experience in vulnerability assessment and penetration testing using various tools like Burp Suite Professional, OWASP ZAP proxy, HCL Appscan, NMAP.
In-depth knowledge of penetration testing Methodology.
In-depth knowledge of threat modelling frameworks.
Have a good understanding of Web Application based attacks.
Security assessment based on OWASP framework.
Working knowledge of OWASP Top 10.
Adaptive to business needs and upskill on demand. Recognized for upskilling on adhoc basis to support thick client application penetration testing.
Overview
8
8
years of professional experience
Work History
Security Engineer
Evoke Technologies
12.2021 - Current
VAPT on consulting web application.
VAPT on GPS Tracking APIs.
VAPT for internal thick client application.
VAPT for AI chatbot web application.
VAPT for oil and gas management web application which is developed using Outsystems.
VAPT for university web application.
VAPT for manufacturing web application.
Detailed documentation of vulnerabilities identified, along with respective remediation techniques. Also perform peer review of security assessment reports.
Work with application developers to validate, assess, understand root cause and mitigate vulnerabilities.
Conducted threat modelling on application architecture diagrams to identify and mitigate potential security vulnerabilities.
Conducted OWASP Top 10 web application security sessions for new joiners as part of the induction program.
Developed PHP banking application internally to establish developer's mindset and gain understanding of how applications function and remediated all application's vulnerabilities.
Programmer Analyst
Cognizant Technology Solutions
11.2017 - 04.2019
Performed functional testing to ensure smooth running of application.
Delivered code changes and development across multifaceted team to meet client needs for functionality, timeline and performance.
Experience with MySQL database system.
Education
B.Tech - Electronics And Communication Engineering.
SVSVMV University
Kanchipuram
04.2017
Board of Intermediate Education - M.P.C
Narayana Junior College
Vijayawada
04.2013
Board of Secondary Education -
Hamsavahini Vidyalaya
Kakinada
04.2011
Skills
Security Assessment: Web application(Manual + DAST + SAST + SCA).