Back to Developers
Ajoy Sarkar

Ajoy Sarkar

Cybersecurity professional

India
80
Profile Score

About

Cybersecurity professional with experience in Vulnerability Assessment & Penetration Testing, Red Team operations and Web Application Testing. Currently part of the Cyber Defense and Resilience department at Deloitte Touched Tohmatsu India LLP. Skilled in vulnerability assessment, Web Application (thick/thin client) testing, and manual testing across web apps, APIs, networks, and Wi-Fi environments. Proven track record in identifying critical security flaws, providing remediation guidance, and validating fixes. Strong understanding of offensive security methodologies and IT audit processes.

Skills & Expertise (24)

Penetration Testing Advanced
8.5/10
2
Years Exp
Kali Linux Advanced
8.5/10
2
Years Exp
Metasploit Advanced
8.5/10
2
Years Exp
Nmap Advanced
8.5/10
2
Years Exp
Burp Suite Advanced
8.5/10
2
Years Exp
VAPT Advanced
8.3/10
2
Years Exp
Vulnerability Assessment Advanced
8.3/10
2
Years Exp
Web App Security Advanced
8.3/10
2
Years Exp
Web Application Testing Advanced
8.3/10
2
Years Exp
API Security Advanced
8.0/10
2
Years Exp
SQL map Advanced
8.0/10
2
Years Exp
Nessus Advanced
8.0/10
2
Years Exp
Qualys Advanced
8.0/10
2
Years Exp
Red Team Operations Advanced
8.0/10
2
Years Exp
Network PT Advanced
8.0/10
2
Years Exp
WIFI PT Advanced
7.8/10
2
Years Exp
Python Intermediate
7.5/10
2
Years Exp
Cymulate Intermediate
7.0/10
1
Years Exp
Pentera Intermediate
7.0/10
1
Years Exp
Harvester Intermediate
7.0/10
1
Years Exp
Katana Intermediate
7.0/10
1
Years Exp
GXSS Intermediate
7.0/10
1
Years Exp
C++ Intermediate
5.8/10
2
Years Exp
Assembly Language Beginner
4.5/10
1
Years Exp

Work Experience

Penetration Tester / Offensive Security Engineer

Deloitte India

Sep 2024 - Present

Conducted comprehensive penetration testing and vulnerability assessments across web applications, APIs, and Android platforms for clients, primarily in the banking and BFSI sector, identifying and mitigating critical security risks. Executed Red Teaming engagements, uncovering high-impact vulnerabilities including NAC Bypass, phishing site discovery, and CMD/PowerShell restriction bypass. Performed Black Box and Grey Box security testing, exploiting vulnerabilities such as SQL Injection (SQLi), Cross-Site Scripting (XSS), Account Takeover, Remote Code Execution (RCE), Privilege Escalation, Insecure Direct Object References (IDOR), and various authentication/authorization bypasses (OTP, CAPTCHA, login), CSRF etc. Perform Malware Simulation Exercises for a top-tier BFSI organization in India, improving incident response readiness by demonstrating realistic attack scenarios. Automated security processes including reconnaissance, patch management, and evidence gathering via Python scripting and CI/CD integration. Delivered detailed remediation guidance and collaborated with development and infrastructure teams to address vulnerabilities; presented findings to both technical and non-technical stakeholders. Conducted in-depth security audits and ATM/Branch security assessments ensuring compliance with regulatory and organizational standards. Utilized a wide range of security tools including Burp Suite, Qualys, Nmap, Metasploit, SQL Map, and various Linux distributions for daily offensive security tasks.

Technical Project Management Intern

TEN Consulting Pvt Ltd

Jun 2021 - Nov 2021

Managed onboarding and task allocation for new hires, tracked project progress and deliverables to ensure timely completion, and implemented workflow automation to streamline processes, improve team efficiency, and reduce operational bottlenecks.

Cyber Security Intern

Deloitte India

Feb 2024 - Aug 2024

Selected as 1 of 25 from 80,000+ applicants for a competitive national program, worked on a live client project performing vulnerability assessments and exploitation (SQLi, XSS, IDOR, Privilege Escalation), developed custom testing scripts, conducted penetration testing using Nmap, Burp Suite, and Metasploit on Kali Linux and Windows, and participated in bug bounty programs to identify and report high-impact security flaws.

Business Development Intern

Coincent.ai Pvt Ltd

Feb 2022 - Jul 2022

Prepared detailed project proposals for clients on immersive learning platforms, delivered real-time support during implementation, and provided post-delivery assistance to ensure client satisfaction and long-term engagement.

Education

Bachelor of Technology in Electronics and Communication Engineering - Techno College of Engineering Agartala

2020 - 2023 · Afghanistan

Diploma in Electronica and Telecommunication Engineering - Dhalai District Polytechnic Institute Ambassa

2017 - 2020 · Afghanistan

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 5/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 80/100

Profile Overview

Member sinceFeb 2026

Skills (24)

Penetration Testing Kali Linux Metasploit Nmap Burp Suite VAPT Vulnerability Assessment Web App Security Web Application Testing API Security +14 more