Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Sandesh Hegde

Bangalore, India

Summary

Dynamic cybersecurity professional with 3+ years of experience in vulnerability assessments and penetration testing. Proven track record of enhancing security posture through innovative solutions and effective mentoring. Skilled in web application security and risk assessment, consistently delivering actionable insights to strengthen defenses and ensure compliance with industry standards

Overview

3
3
years of professional experience
2
2
Certification

Work History

Senior Consultant

Black Duck(formerly Synopsys)
Bangalore
03.2023 - Current
  • Conducted VAPT assessments for web apps and APIs, enhancing security posture.
  • Led end-to-end web app penetration testing, ensuring robust security.
  • Conducted DAST and SAST, identifying and mitigating critical vulnerabilities.
  • Conducted penetration testing on thick-client applications to identify security vulnerabilities and assess overall application resilience.
  • Conducted penetration testing on iOS applications to identify vulnerabilities and strengthen mobile security.
  • Trained and mentored interns on application security concepts, tools, and best practices.
  • Directed and coordinated work completed by junior consultants and other consultants.
  • Created reports, presentations and other documents to share findings with management team.
  • Optimized vulnerability detection processes, providing actionable security solutions.

Jr. Cybersecurity Analyst

Secure Logic
Bangalore
11.2022 - 02.2023
  • Responsible for handling web and network VAPT for PCI DSS compliance.
  • Responsible for handling Qualys and Nessus ASV scans for clients.

Associate Cyber Security Engineer

Rhibhus
Bangalore
10.2021 - 11.2022
  • Conducted comprehensive security assessments of web applications and APIs to identify vulnerabilities, and ensure secure implementations.
  • Conducted Software Composition Analysis (SCA) to identify and remediate vulnerabilities in third-party and open-source components.
  • Conducted Static Application Security Testing (SAST) on Android applications to detect security vulnerabilities in source code and binaries.
  • Performed external and internal assessments against corporate policies, standards, procedures, and regulations.
  • Documented findings from vulnerability assessment activities including recommendations for remediation efforts.
  • Worked closely with the client teams to ensure the remediation of the findings.

Cyber Security Engineer Intern

Virtually Testing Foundation
Remote
05.2022 - 07.2022

Cyber Security Engineer Intern

Rhibhus
Bangalore
08.2021 - 10.2021

Education

Bachelor of Engineering - Electrical And Electronics Engineering

Rajiv Gandhi Institute of Technology
Bangalore
01-2020

Skills

  • Vulnerability assessment
  • Penetration testing
  • Web application security
  • Security compliance
  • Risk assessment
  • Mentoring interns
  • IOS Application Testing
  • Software Composition Analysis
  • Burp Suite
  • Web Services Testing

Certification

  • CEH (Certified Ethical Hacker)
  • CAP (Certified AppSec Practitioner)
  • ISC² CC (Certified in Cybersecurity)
  • Qualys Web Application Scanning
  • Open Source Intelligence from the Basel Institute of Governance
  • Experienced in bug bounty hunting

Timeline

Senior Consultant

Black Duck(formerly Synopsys)
03.2023 - Current

Jr. Cybersecurity Analyst

Secure Logic
11.2022 - 02.2023

Cyber Security Engineer Intern

Virtually Testing Foundation
05.2022 - 07.2022

Associate Cyber Security Engineer

Rhibhus
10.2021 - 11.2022

Cyber Security Engineer Intern

Rhibhus
08.2021 - 10.2021

Bachelor of Engineering - Electrical And Electronics Engineering

Rajiv Gandhi Institute of Technology
Sandesh Hegde