Summary
Overview
Work History
Education
Skills
Cyber security tools
Projects
Certification
Accomplishments
Timeline
Generic

K SURYA SAI HARSHA

Summary

A skilled Red Team Security Analyst with hands-on experience in strengthening web and network security. Adept at assessing complex environments, identifying exploitable vulnerabilities, and delivering impactful security improvements. Consulted closely with clients to understand their technology landscape and operational needs, recommending targeted remediation steps, configuration hardening, and strategic security enhancements to reduce the risk of compromise. Proven ability to translate technical findings into actionable guidance that elevates an organization’s overall security posture.

Overview

2
2
years of professional experience
1
1
Certification

Work History

Red Team Security Analyst

Firecompass Technologies Pvt Ltd
Bengaluru
09.2023 - Current
  • Conducted extensive active scans and Red Teaming exercises, uncovering over 700 critical vulnerabilities across diverse client environments, including SQL Injection, Remote Code Execution (RCE), unauthorized database access, and exposure of more than 60,000 sensitive files.
  • Implemented sophisticated pentesting methodologies and workflow to ease continuous monitoring of attack surface.
  • Provided detailed reports and actionable recommendations to clients, helping to remediate vulnerabilities and strengthen their overall security posture. Also, conducted phishing simulations to test employee awareness.
  • Performed comprehensive product testing, conducting intricate analysis of results using a variety of tools to optimize outcomes, and ensure product reliability.

Education

Bachelor of Computer Science and Engineering - Phagwara, Punjab

Lovely Professional University
Phagwara, Punjab
09-2024

Skills

  • Red Teaming
  • Web application VAPT
  • Network VAPT
  • Attack surface management
  • OSINT
  • Bug hunting
  • Phishing simulations
  • Mobile application pentesting
  • Computer networks
  • Linux
  • Python scripting

Cyber security tools

NMAP, Burp Suite, Nessus, Metasploit, Nuclei, SQLMap, Acunetix, OWASP ZAP, Nikto, WPScan, Recon tools, Fuzzing tools, JADX GUI, Genymotion

Projects

Sharanga - Static web crawler (Sep 2025-Present)

• Developed a static web crawler that performs structured URL discovery with deduplication, normalization, scope checks, and depth-controlled traversal.
• Extracts links, forms, and core web components from source codes and JS files to expand the application attack surface, generating clean, actionable output for security testing.
• Provides configurable settings (start URL, headers, depth, scope) with detailed logging and error handling, making it suitable for red-team and AppSec workflows.

• Currently building dynamic crawling capabilities to evolve into a fully functional web vulnerability scanner with deeper coverage and automated analysis.

SQLi Hunter (Jul 2024)

• Developed an automated script to streamline the identification of SQL injection vulnerabilities across multiple web applications, integrating various tools and finding the vulnerability in one go.

• Enhanced the efficiency of vulnerability assessment processes by automating every process including targeted security testing.

ReconRadar (Jan 2024-Present)

• A comprehensive reconnaissance tool that automates the discovery and mapping of domains, subdomains, IPs, and web applications.

• Identifies and enumerates the complete external attack surface, enhancing penetration testing efficiency. With user-integrated APIs, the tool extends its capabilities further enhancing its reconnaissance capabilities.

SubTakeover Sniper (Mar 2024)

• Engineered a command-line utility integrating dig and grep for automated detection of subdomain takeover vulnerabilities, enhancing security posture.

• Scans and analyzes DNS records, achieving a 95% accuracy rate in identifying vulnerable subdomains.

Certification

  • ELearning Junior Penetration Tester (eJPT)
  • Certified AppSec Practitioner (CAP)
  • Certified Red Team Professional (CRTP)

Accomplishments

  • CVE Research & Disclosure: Successfully reported and published two Common Vulnerabilities and Exposures — CVE-2025-62597 and CVE-2025-62598 — recognized for enhancing application and network security.

Timeline

Red Team Security Analyst

Firecompass Technologies Pvt Ltd
09.2023 - Current

Bachelor of Computer Science and Engineering - Phagwara, Punjab

Lovely Professional University
K SURYA SAI HARSHA