EXPERIENCE
- Real-world bug bounty engagements targeting web and API attack surfaces on the Bugcrowd platform.
- Identify and responsibly disclose access control flaws, SSRF, and business logic vulnerabilities.
- Web, API, and Mobile Application security testing using Burp Suite and Nuclei.
- In-depth API testing for BOPLA, BFLA, Mass Assignment, and Excessive Data Exposure.
- Android VAPT via static (apktool, jadx) and dynamic analysis — insecure storage, SSL, API leaks.
- Exploited SSRF, out-of-band SQLi, CORS misconfigurations against WAF-protected targets.
- Delivered structured reports with CVSS ratings and actionable remediation.
- Built multi-page conceptual websites using Framer for E-commerce and EV platforms.
- Created lightweight design systems and component libraries for visual consistency.
- SOC simulations covering incident response and enterprise threat management.
- Security monitoring principles in simulated enterprise environments.
TECHNICAL SKILLS
CERTIFICATIONS
Advanced red team operations certification covering offensive security management, threat simulation, and adversarial tactics.
Specialized certification in ransomware defense strategies, incident response, and organizational protection frameworks.
Information Security Management System (ISMS) certification aligned with ISO/IEC 27001:2022 international standard.
AWS Security Specialty domain review covering cloud security architecture, threat detection, and incident response on AWS.
Comprehensive ethical hacking certification covering penetration testing methodologies, vulnerability assessment, and exploitation techniques.
SOC operations simulation covering threat analysis, incident response workflows, and security monitoring in enterprise environments.
2-day hands-on workshop covering fake application awareness, TOR anonymity basics, encryption concepts, and attacker techniques.
Business fundamentals and entrepreneurship foundations certification from SkillFront's accredited learning program.
TOOLS & PLATFORMS
FEATURED PROJECTS
AI helmet violation detection system — real-time YOLOv8 edge-based detection with a secure PHP/MySQL backend. Features RBAC, strict data validation, and secure coding to prevent injection attacks.
Conceptual custom gaming PC e-commerce platform built entirely in 48 hours using Framer CMS. Features dynamic product configurator and responsive layout.
Responsive electric motorcycle concept website designed with Framer. Features smooth scroll animations, modern clean aesthetics, and a performance-focused UI.
Consolidated repository of all reconnaissance, penetration testing, and VAPT tasks completed during the CyberSapiens internship. Includes scripts, methodologies, and structured vulnerability reports.