Back to Developers
Sunny Bairwa

Sunny Bairwa

Cybersecurity Analyst

Gurgaon, Haryana, India 0+ yrs exp 81 · Excellent

About

Cybersecurity Analyst with hands-on experience across Vulnerability Assessment & Penetration Testing (VAPT), Web Application Security, API Security, Android Security Testing, and SOC Operations. Identified and validated critical vulnerabilities — OData Injection, Authentication Bypass, IDOR, Privilege Escalation, and Cloud Misconfigurations — across 7+ live production platforms, mapped to the OWASP Top 10 and OWASP API Top 10. Skilled in Wazuh SIEM monitoring, alert triage, log analysis, and incident investigation aligned with the MITRE ATT&CK framework. Experienced in end-to-end security assessments, CVSS-based risk scoring, Azure cloud security review, and remediation collaboration with development teams to support secure SDLC practices. Proficient in Python and SQL for security automation and data analysis.

Skills & Expertise (46)

API Security Testing Intermediate
7.4/10
1
Years Exp
Web Application VAPT Intermediate
7.4/10
1
Years Exp
OWASP Top 10 Intermediate
7.4/10
1
Years Exp
Burp Suite Intermediate
7.4/10
1
Years Exp
Network Scanning Intermediate
6.5/10
1
Years Exp
Python Intermediate
6.5/10
1
Years Exp
Kali Linux Intermediate
6.5/10
1
Years Exp
Security Event Monitoring LINUX Threat Detection Incident Investigation MITRE ATT&CK TTP Mapping JavaScript SQL C/C++ Java HTML CSS Metasploit OWASP ZAP MITRE ATT&CK Cyber Kill Chain CVSS scoring Risk Assessment Windows Frida Reconnaissance Post-Exploitation SQL Injection XSS CSRF IDOR Authentication Bypass Broken Access Control OWASP API Top 10 MobSF Log Analysis JADX apktool APK reverse engineering Nmap WIRESHARK Azure Security Google Cloud Wazuh SIEM Alert Triage

Work Experience

Cybersecurity Analyst Intern

JRS Innovation Pvt. Ltd.

Jan 2026 - Jun 2026

Performed Web Application Penetration Testing across 7+ live international production platforms; exploited an OData Injection flaw on Prime to achieve full database enumeration and critical Account Takeover (ATO). Identified and validated Authentication Bypass, Azure Blob Storage misconfigurations, IDOR on web applications and Android APKs, and Privilege Escalation vulnerabilities by exploiting missing server-side authorization checks. Conducted Android APK Security Testing using MobSF, Frida, JADX, and APKTool; uncovered JWT validation issues, insecure local data storage, unrestricted file upload, double-extension bypass, missing CSP headers, and absent rate-limiting controls. Deployed and monitored Wazuh SIEM across Linux and Windows endpoints; performed live alert triage, log analysis, and incident investigation using MITRE ATT&CK TTP mapping. Authored CVSS-scored vulnerability reports with clear reproduction steps and remediation guidance, enabling development teams to close findings efficiently.

Virtual Intern — Ethical Hacking & Penetration Testing

C-DAC Noida

May 2025 - Jul 2025

Executed vulnerability assessment and penetration testing exercises in controlled lab environments, applying structured VAPT methodology. Developed a Cyber Kill Chain research project mapping each attack lifecycle phase to corresponding detection and defense strategies.

Education

B.Tech in Cyber Security - Government Engineering College, Ajmer

2022 - 2026 · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 6/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 81/100

Profile Overview

Member sinceJul 2026