Summary
Overview
Work History
Education
Skills
Certification
Languages
Penetration Testing Experience - Current
Honor Awards
Timeline
Generic

Divya G

Bangalore

Summary

Multi-faceted Senior Penetration Tester with comprehensive experience across application, mobile, network, container, and emerging technology security. Proven ability to lead security engagements, define testing strategies, and mentor teams, while consistently delivering high-quality assessments in agile, fast-paced environments to support organizational security and risk-reduction goals.

Overview

12
12
years of professional experience
1
1
Certification

Work History

Senior Penetration Tester

IBM India Pvt Ltd
Bangalore
10.2021 - Current
  • Extensive experience in Web, API, Thick Client, Mobile, Container, Network, LLM security testing
  • Lead penetration testing engagements with a strong focus on mobile application security (Android & iOS)
  • Actively involved in planning, execution, and reporting of complex security assessments
  • Mentor and guide team members during mobile security testing projects

Day-to-Day & Strategic Responsibilities

  • Perform end-to-end penetration testing: scoping, threat modeling, manual exploitation, validation, and retesting
  • Design test strategies and attack scenarios based on application architecture, business logic, and threat landscape
  • Conduct manual vulnerability research beyond automated tools to identify complex and chained exploits
  • Review the application architecture and provide security recommendations during the early development phases.
  • Collaborate with developers, DevOps, and product teams to explain findings, risks, and remediation approaches
  • Contribute to testing methodologies, checklists, and internal frameworks, especially for mobile security
  • Assist in tool selection, customization, and script development to improve testing efficiency
  • Ensure high-quality, actionable technical reports with clear risk impact and proof-of-concepts
  • Support continuous improvement of team processes, knowledge sharing, and skill development

Certifications & Training

  • Currently preparing for OSCP certification
  • Completed professional training in 7CMP Mobile Security Certification

Senior Project Engineer

Wipro Ltd
Bangalore
07.2019 - 10.2021
  • Conducted web application security testing, vulnerability assessments, and penetration testing using various tools.
  • Developed security solution designs and policies to enhance system integrity.
  • Performed manual penetration testing, effectively communicating findings to business units and developers.
  • Assisted system users with inquiries related to information systems security.
  • Collaborated with application developers to validate vulnerabilities and implement remediation strategies.
  • Reviewed application vulnerabilities, facilitating discussions with developers to address security concerns.
  • Demonstrated expertise in web protocols, common attack vectors, Linux, Windows, and cloud service architectures.
  • Provided web application training to developers and cross-functional teams for improved security awareness.

Associate consultant

Infosys limited
03.2019 - 07.2019
  • Maintained and enhanced vulnerability management platform and processes for optimal performance.
  • Automated vulnerability management processes to improve efficiency and accuracy.
  • Developed metrics and reports on vulnerability findings and remediation compliance.
  • Provided technical support to system owners, recommending effective mitigation solutions.
  • Demonstrated expertise in basic networking protocols including TCP/IP and UDP.
  • Utilized penetration testing concepts and tools, including PTES, Metasploit, and Nmap.
  • Classified and prioritized risks of new vulnerabilities based on operating environments.
  • Conducted infrastructure and cloud vulnerability scanning to identify security gaps.

Senior Security Analyst

IBM India Pvt Ltd
Bangalore
07.2014 - 03.2019
  • Acted as primary responder for security incidents involving client firewalls and network infrastructure.
  • Conducted source code reviews utilizing Veracode and Checkmarx tools.
  • Applied knowledge of software development lifecycle to enhance project outcomes.
  • Executed web application vulnerability scans using Burp Suite.
  • Configured Linux operating systems, utilities, and programming for optimal performance.
  • Leveraged extensive knowledge of hardware, software, and networking technologies for comprehensive analysis and support.
  • Managed project continuity cycle, reviewed technical work, and ensured high-quality service deliverables.
  • Facilitated customer relations by gathering business requirements and organizing meetings.

Education

B.E. - Bangalore

Bangalore Institute of Technology (VTU)
Bangalore
07.2014

12th - Bangalore

Bishop Cotton Women Christian College
Bangalore
06.2010

10th - Bangalore

Mitralaya Girls High School
Bangalore
06.2008

Skills

  • Network vulnerability scanning
  • Penetration testing
  • Web application testing
  • Mobile application testing
  • Source code analysis
  • IBM AppScan
  • Traffic analysis
  • Network intrusion detection
  • Packet analysis
  • Wireshark and Aircrack-ng
  • Hydra and Burp Suite
  • Metasploit framework
  • OWASP ZAP
  • Nmap and Sqlmap
  • John the Ripper
  • Nessus vulnerability scanner
  • Application software proficiency
  • Cybersecurity tools knowledge
  • Remote access support skills
  • Cloud security solutions
  • Python programming
  • Hack the Box experience

Certification

GDPR Completion Certificate, 04/2018
Qualys Vulnerability Management Certification, 04/2019
Certified Ethical Hacker, 06/2019
Completed Mobile Penetration Testing Training, 11/2020
Multi-Cloud Red Teaming Analyst, 05/2025
Kubernetes Red Team Analyst, 12/2025

Languages

  • English
  • Kannada

Penetration Testing Experience - Current

  • Container & Kubernetes Security
  • Performed container image security assessments (Docker) to identify vulnerable base images, hardcoded secrets, excessive permissions, and insecure configurations
  • Conducted Kubernetes penetration testing, including RBAC misconfigurations, exposed dashboards, insecure API server access, and privilege escalation paths
  • Tested container runtime security, secrets management mechanisms, and pod/container escape scenarios
  • Mapped findings to CIS Benchmarks and OWASP Kubernetes Top 10, providing actionable remediation guidance
  • Network Penetration Testing
  • Conducted internal and external network penetration testing using Nmap, Metasploit, Nessus, and manual exploitation techniques
  • Assessed security of firewalls, VPNs, routers, and IDS/IPS configurations
  • Identified lateral movement opportunities, weak authentication mechanisms, and misconfigured services
  • Performed packet capture and traffic analysis using Wireshark and tcpdump
  • Mobile Application Penetration Testing (Android & iOS)
  • Performed static and dynamic mobile application security testing using MobSF, Jadx, Frida, Objection, and Burp Suite
  • Identified vulnerabilities including insecure data storage, SSL pinning bypass, root/jailbreak detection bypass, deep link abuse, and runtime manipulation
  • Conducted advanced runtime analysis and instrumentation to validate client-side trust issues
  • Aligned findings with OWASP MSTG and OWASP MASVS (L1, L2, R)
  • Delivered security assessments for Banking, Fintech, Healthcare, and E-commerce applications
  • Web Application & API Penetration Testing
  • Conducted manual and automated web application penetration testing aligned with OWASP Top 10
  • Identified critical vulnerabilities including SQL Injection, XSS, CSRF, IDOR, authentication bypass, and business logic flaws
  • Performed REST and GraphQL API security testing, including authorization, rate limiting, and input validation issues
  • Provided clear remediation guidance, risk prioritization, and re-testing support
  • Thick Client Application Security
  • Performed thick client application security testing using reverse engineering and dynamic analysis techniques
  • Identified hardcoded credentials, insecure deserialization, weak cryptographic implementations, and client-side trust issues
  • Manipulated backend communication to exploit authorization and access control flaws
  • LLM and AI application security
  • Conducted security assessments of LLM-based and AI-driven applications
  • Identified risks including prompt injection, sensitive data leakage, insecure plugins, and excessive trust in model outputs
  • Tested jailbreak techniques, unauthorized model/API access, and abuse scenarios
  • Aligned testing methodology with OWASP Top 10 for LLM Applications

Honor Awards

  • Manager's Choice Award, 07/2018, IBM India Pvt Ltd
  • Certificate for outstanding dedication and commitment towards Client Success, 03/2016, IBM India Pvt Ltd

Timeline

Senior Penetration Tester

IBM India Pvt Ltd
10.2021 - Current

Senior Project Engineer

Wipro Ltd
07.2019 - 10.2021

Associate consultant

Infosys limited
03.2019 - 07.2019

Senior Security Analyst

IBM India Pvt Ltd
07.2014 - 03.2019

B.E. - Bangalore

Bangalore Institute of Technology (VTU)

12th - Bangalore

Bishop Cotton Women Christian College

10th - Bangalore

Mitralaya Girls High School
Divya G