About Me


  • Over 9+ years of experience in Information Security, specializing in  Application Security, Secure Code Analysis, Threat modeling and Vulnerability Assessment and Penetration Testing (VPAT) . 

  • Currently working at Appsecure Security as Lead Security Engineer.

  • Strong Understanding and Experience of  Security Assessment into the entire SDLC process from stage of development, from planning and coding to testing and deployment including Architecture Design review , Threat modeling , CI/CD tooling automation and penetration testing.

  • Excellent knowledge of Web and Mobile Application vulnerabilities and Tools including OWASP Top 10, Burp Suite , Nuclei , Nmap and Amass etc. 

  • Experience in Developing and implementing Reconnaissance Automation workflow(In scripting Language Bash/Python) to continuously Monitor Organisation domains and IPs to Find and mitigate 0-Day Attacks , OWASP Top 10 Vulnerabilities , Web and some Network related vulnerabilities. 

  • AWS cloud security Certified with AWS Certified Security - Specialty certificate .

  • Identified 1000+ security Vulnerabilities in world’s leading Companies Like Apple , Google , Twitter , Amazon , Github , Gitlab , Salesforce , Amazon , AWS , Epic Games,  Yahoo , Uber , Shopify,Mozilla, Dropbox, Vimeo , Airbnb and 200+ Companies. 

  • Top 100 Researcher in world’s leading Bug bounty Platforms Hackerone and Bugcrowd. 

  • Top 10 Researcher in the Epicgames Bug Bounty Program.




Public Profile : 
Linkdin
Twitter

Hackerone Profile : 
hackerone.com/indoappsec

Bugcrowd Profile : 
https://bugcrowd.com/indoappsec


That's All from my side :) Please Feel free to contact me if you want to know more !!


Comments

Popular posts from this blog

Account Takeover Apple App Store Connect Account of Any user and Steal Developer API/Subscription Keys of any user(CORS+XSS) worth 8500$

Amazon Web Services : Takeover Workbook and delete the Owner on https://builder.honeycode.aws by collaborator user (IDOR) worth 7200$

UnAuth Access to Twitter Private Tweets and messages Media Content Access(IDOR)