Summary
Overview
Work History
Education
Skills
Tools & Frameworks
Declaration: 
Timeline
Generic

SUMANTH CHUNCHULA

Bangalore

Summary

Cybersecurity professional with 2.5 years of experience in Vulnerability Assessment and Penetration Testing (VAPT). Skilled in identifying security risks and conducting thorough threat analyses. Expertise in utilizing industry-standard tools and delivering clear reports for diverse audiences. Proven ability to recommend effective mitigation strategies to enhance security posture.

Overview

3
3
years of professional experience

Work History

VAPT Analyst

Axa
Bangalore
10.2024 - Current

Analyst

Star Health Allied Insurance
Bangalore
10.2022 - 11.2024
  • Performed a comprehensive Vulnerability Assessment and Penetration Testing (VAPT) across 20+ web applications and network environments, identifying critical vulnerabilities aligned with the OWASP Top 10 and industry standards.
  • Conducted manual and automated Dynamic Application Security Testing (DAST) using tools including Burp Suite Professional, OWASP ZAP, Nessus, Postman, and Kali Linux, improving testing coverage and detection accuracy.
  • Designed and configured authenticated scanning workflows (Basic Auth, form-based authentication, session handling, token-based authentication) to increase scan success rates and minimize false negatives.
  • Identified and validated complex vulnerabilities, including:
  • Cross-Site Scripting (Stored, Reflected, DOM-based)
  • SQL injection and injection flaws.
  • Broken Access Control / IDOR.
  • Authentication and session management weaknesses.
  • SSRF, CSRF, Open Redirect
  • Security misconfigurations and business logic flaws.

Education

MBA -

Narayana MBA Collage
01-2023

B.COM -

Acharya Nagarjuna University
01-2021

PUC -

Vivekananda Jr College
01-2017

SSC -

Bhyashyam EM High School
01-2015

Skills

Vulnerability Assessment & Penetration Testing

Web Application Penetration Testing

API Penetration Testing

Mobile Penetration Testing

Network Penetration Testing

Manual Testing aligned with OWASP Top 10

False Positive Validation & Reduction

Risk Assessment and mitigation strategies

Tools & Frameworks

  • Web Security Tools: Burp Suite Pro, OWASP ZAP, Postman, Nikto
  • Network Scanning: Nmap, Netcat, Wireshark, Nessus, OpenVAS
  • Exploitation: Metasploit Framework, SQLMap, Hydra
  • Mobile Testing: MobSF, Apktool, Dex2Jar, Frida, Android Studio
  • Fuzzing Tools: wfuzz, Dirb, Gobuster
  • SAST/DAST: Veracode, AppScan Standard, SonarQube
  • OS Platforms: Kali Linux, Windows, Ubuntu

Declaration: 

I, C. Sumanth Kumar, do hereby confirm that the information given above is true to the best of my knowledge
Place: Bangalore

Timeline

VAPT Analyst

Axa
10.2024 - Current

Analyst

Star Health Allied Insurance
10.2022 - 11.2024

MBA -

Narayana MBA Collage

B.COM -

Acharya Nagarjuna University

PUC -

Vivekananda Jr College

SSC -

Bhyashyam EM High School
SUMANTH CHUNCHULA