Summary
Overview
Work History
Education
Skills
Accomplishments
Key Achievements
Certification
Languages
Timeline
Manager
DIVYA PONNAPATI

DIVYA PONNAPATI

Bengaluru,KA

Summary

Results-oriented cybersecurity professional with 4.6 years of experience in penetration testing, application security, and network security across web, mobile, API, and infrastructure environments. Skilled in SAST/DAST, vulnerability assessment, and tools like Burp Suite, OWASP ZAP, and Metasploit. Experienced with PCI-DSS, ISO 27001, and NIST compliance. Proven track record of identifying risks, remediating vulnerabilities, and improving security posture. Seeking to leverage expertise in a dynamic security role

Overview

5
5
years of professional experience
1
1
Certification

Work History

Cybersecurity Senior Consultant

EY
06.2021 - Current
  • Led and coordinated penetration testing on critical Crown Jewels KFAS (Key Functionality Assets, and Services) systems, including 70 web applications, 25 SAP instances, and 50+ infrastructure components, identifying and remediating 430+ vulnerabilities, significantly enhancing security and safeguarding key business assets
  • Managed end-to-end bug bounty program (private and public) for a client, coordinating with multiple stakeholders to define the program scope, covering over 230 assets
  • Establishing engagement rules, resulting in enhanced vulnerability identification and improved security posture
  • Coordinated lifecycle of bug bounty program, leading efforts to resolve 300+ vulnerabilities reported by security researchers, prioritizing remediation actions to reduce security risks by
  • Performed security configuration review on different technologies e.g. SAP, HANA
  • Conducted penetration testing on a major e-commerce site, uncovering critical vulnerabilities like "Broken Access Control" and "Business Logic Bypass", leading to the identification and remediation of over 20 high-risk vulnerabilities
  • Streamlined the penetration testing demand management workflow by providing comprehensive technical insights and detailed specifications, enhancing process efficiency 75%

Consultant

Deloitte Touche Tohmatsu India,LLP
01.2021 - 05.2021

Banking & Financial Sector Projects

  • Led comprehensive security assessments for banking and financial institutions, identifying and mitigating 30+ security risks, and ensuring 100% compliance with regulatory standards, including PCI-DSS, resulting in a stronger security posture and minimized security threats.
  • Performed in-depth source code reviews, identifying critical vulnerabilities and providing actionable remediation recommendations to strengthen application security and reduce the risk of exploitation.
  • Conducted Vulnerability Assessments (VA), Card Data Discovery, and Compliance Audits for Windows and Unix servers, ensuring adherence to PCI-DSS and other industry standards, and improving system security and compliance.
  • Delivered detailed security reports with prioritized remediation strategies, enabling clients to address critical vulnerabilities and improve their overall security posture.

Cyber security Intern

Reliance Industries ltd
08.2019 - 06.2020

Key Qualifications & Responsibilities

  • Performed Grey-box and Black-box testing as part of BAU activities on 80+ web applications across industries, including Retail, E-commerce, and Portal applications. Utilized both automated and manual testing approaches to identify critical security vulnerabilities.
  • Identified and documented critical vulnerabilities, such as SQL Injection, Insecure Direct Object Reference (IDOR), OTP bypass, and Account Takeover, in 30+ high-priority applications, leading to the remediation of 20+ vulnerabilities, and improving overall security posture.
  • Led Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) on mobile applications, uncovering vulnerabilities across client-side and server-side components, enhancing mobile app security.
  • Performed security assessments for APIs, thick client applications, and web services, ensuring end-to-end security and minimizing risks related to data exposure and unauthorized access.
  • Managed vulnerability remediation cycles, coordinating with development teams and business stakeholders to address and resolve critical security defects, ensuring timely closure and risk reduction.
  • Contributed to DevSecOps initiatives, integrating security testing into the CI/CD pipeline to automate security checks, streamline vulnerability detection, and improve the efficiency of security controls in the software development lifecycle.

Education

Masters - CyberSecurity

Amrita School of Engineering
Coimbatore, India
04-2020

B.Tech - computer Science and Engineering

Andhra Loyola Institute of Engineering & Technology
Vijayawada, India
05-2018

Skills

  • Operating Systems: Windows, Linux
  • Penetration Testing Tools: Burp Suite, OWASP ZAP, Metasploit, SQLMap, WebInspect
  • Mobile & Reverse Engineering: Android Tamer, MobSF, Drozer, APKTool, dex2jar
  • Security Assessment Tools: Fortify, Nessus, Nmap, DirBuster
  • Networking & Protocols: TCP/IP, UDP, HTTP, HTTPS, SMTP, ICMP, Wireshark, Packet Tracer
  • Database & Data Security: SQL (MySQL, PostgreSQL), Card Data Discovery (Panhunt)
  • Security Frameworks & Standards: OWASP Top 10, IDS/IPS, SIEM, PCI-DSS

Accomplishments

    Web Application security

  • Tools Used : Burp suite, sqlmap, Postman, Kali Linux exploitation tools
  • Performed Vulnerability assessments on various applications integrated with SSO, Kerberos to identify a potential risk and action plan to resolve the risk before going to production
  • Brainstorming with my team to come up with an efficient methodology to find attack vectors and a check-list for default configuration settings in various frameworks
  • Mobile Application security

  • Tools Used : Android tamer, dex2jar, Jd-GUI, APK tool, Drozer
  • Performed Security assessments(SAST & DAST) on 30+ mobile in-house, External facing and third party applications
  • Disclosed vulnerabilities such as unwanted permissions, missing manifest file checks, weak encryption, and reverse engineering risks through static testing, identifying 30+vulnerabilities and significantly improving overall security by addressing these issues
  • VAPT

  • Tools Used : Metasploit, Kali Linux(OS)
  • Hands-on experience with HAK5 kits bash bunny and Lan turtle
  • Exploited Man-in-the middle attack using Lan turtle

Key Achievements

  • Awarded "I Am Exceptional" for outstanding contributions to security projects at Ernst & Young (EY), demonstrating leadership and excellence in cybersecurity initiatives.
  • Active member of the Vulnerability Assessment and Penetration Testing Lab team at Amrita University, contributing to lab operations and security research.
  • Organized and led the Hacking Village event at Amrita University, showcasing HAK5 kits for penetration testing and security auditing, enhancing awareness and skills within the security community.

Certification

  • Certified Ethical Hacker (CEH v11) – EC-Council
  • Cybersecurity Bronze Badge – Ernst & Young (EY)
  • Practical Ethical Hacking – Udemy (Certified)
  • Certified Network Security Specialist (CNSS) – ICSI

Languages

English
Advanced (C1)
Telugu
Bilingual or Proficient (C2)
Hindi
Intermediate (B1)

Timeline

Cybersecurity Senior Consultant

EY
06.2021 - Current

Consultant

Deloitte Touche Tohmatsu India,LLP
01.2021 - 05.2021

Cyber security Intern

Reliance Industries ltd
08.2019 - 06.2020

Masters - CyberSecurity

Amrita School of Engineering

B.Tech - computer Science and Engineering

Andhra Loyola Institute of Engineering & Technology
DIVYA PONNAPATI