Pro-Active Cyber Security Analyst with 3 Years of experience in web application security. Skilled in conducting vulnerability assessment, penetration testing with expertise in OWASP Top 10 and API security, contributing to enhance organizational security, safe guard sensitive data & mitigating risks.
Client: Indamer Pvt. Ltd (Project: SkyTouch)
Project Overview:
SkyTouch is a web-based aircraft maintenance
management system, built to streamline operations
and documentation across aviation workflows.
Key Features:
1. Centralized tracking of Aircraft Maintenance
Programs (AMP), scheduling, modifications, and MEL
records.
2. Work order flow management for efficient
planning and execution.
3. Real-time reporting to support data-driven
decision-making.
4. Multi-user access enabling collaborative inventory
and maintenance tracking.
SkyTouch enhances operational visibility and
ensures regulatory compliance in aircraft
maintenance.
Project 1: Web VAPT
* Assessed web application security through
structured developer interactions and automated
scans using OWASP ZAP, Burp Suite, and Nessus.
* Identified critical vulnerabilities like Broken Access
Control, Injection flaws, and Authentication
weaknesses via manual testing.
* Delivered risk-based security reports with
remediation strategies & worked with developers to
implement fixes.
Project 2: API VAPT
* Evaluated RESTful and SOAP APIs for security risks
using Swagger, Postman, and Burp Suite.
* Identified vulnerabilities such as Broken Object
Level Authorization and Authentication flaws.
* Provided detailed reports with mitigation steps and
collaborated with developers to enhance API
security.
Project 3: Network VA
* Assessed network security using Nessus and NMap
to identify vulnerabilities.
* Prioritized risks based on severity and impact.
* Eliminated false positives and provided actionable
insights.
* Delivered detailed reports with remediation
recommendations.
Skilled in identifying & mitigating vulnerabilities (OWASP TOP 10 & API Security)
undefined