Summary
Overview
Work History
Education
Skills
Websites
Software & Tools
Personal Information
Languages
Work Preference
Timeline
Generic

Shubham Nema

Senior Security Consultant
Bengaluru,KA

Summary

A dedicated and results-driven Cybersecurity Consultant with 3.9 years of experience in Vulnerability Assessment and Penetration Testing (VAPT) across banking, insurance, e-commerce, and fintech sectors. Skilled in identifying and mitigating security risks through network, web, and API penetration testing, ensuring compliance with industry standards. Proficient in using Burp Suite, Nessus, Nmap, and applying frameworks like OWASP Top 10, NIST, and MITRE ATT&CK. Strong analytical and project management skills, with a track record of delivering comprehensive security assessments, clear remediation strategies, and actionable reports. Adept at collaborative problem-solving and risk management, committed to enhancing security infrastructure and safeguarding digital assets.

Overview

4
4
years of professional experience

Work History

Senior Consultant

Black Duck
Bangalore
06.2021 - Current

Company Overview: formerly known as Synopsys

  • Conducted comprehensive penetration testing for 20+ clients, including leading financial institutions, health insurers, and e-commerce platforms, to identify and remediate security risks.
  • Led web and API penetration testing projects for clients, identifying critical vulnerabilities and delivering comprehensive remediation guidance to strengthen their security posture.
  • Network Penetration Testing – Internal & external testing, including CDE (Cardholder Data Environment) and non-CDE networks for PCI DSS compliance.
  • Performed segmentation testing and Attack Surface Mapping (ASM) to strengthen clients' security infrastructures and minimize attack exposure.
  • Delivered high-quality security assessments, technical reports, and client presentations, ensuring timely completion and alignment with project requirements
  • Conducted in-depth Web Application Security Assessments (DAST, PT) following OWASP guidelines, analyzing business logic flows using both manual and automated testing with proxy tools like Burp Suite.
  • Conducted penetration testing on APIs and web services, including RESTful APIs, SOAP, and GraphQL, to identify and remediate security vulnerabilities
  • Prioritized projects and project tasks depending upon key milestones and deadline dates.
  • Troubleshot issues by understanding issue, diagnosing root cause and coming up with effective solutions.
  • Built strong relationships with clients through consistent communication and proactive problem-solving efforts.

Education

PG Diploma - IT Infrastructure, Systems and Security

CDAC
02-2021

Bachelor of Engineering - Electrical And Electronics Engineering

Oriental Institute of Science & Technology

Skills

  • Web, API, and Network Penetration Testing
  • Vulnerability Assessment
  • Internal and External Security Assessments
  • Proficient in OWASP, NIST, and MITRE Standards
  • Proficient in Security Tools
  • Python Automation Skills
  • Linux and Windows System Administration
  • Technical Documentation

Software & Tools

Burp Suite Pro

Personal Information

Languages

English
Advanced (C1)
Hindi
Bilingual or Proficient (C2)

Work Preference

Work Type

Full Time

Work Location

Hybrid

Timeline

Senior Consultant

Black Duck
06.2021 - Current

PG Diploma - IT Infrastructure, Systems and Security

CDAC

Bachelor of Engineering - Electrical And Electronics Engineering

Oriental Institute of Science & Technology
Shubham NemaSenior Security Consultant