About
Cybersecurity Analyst with hands-on experience across Vulnerability Assessment & Penetration Testing (VAPT), Web Application Security, API Security, Android Security Testing, and SOC Operations. Identified and validated critical vulnerabilities — OData Injection, Authentication Bypass, IDOR, Privilege Escalation, and Cloud Misconfigurations — across 7+ live production platforms, mapped to the OWASP Top 10 and OWASP API Top 10. Skilled in Wazuh SIEM monitoring, alert triage, log analysis, and incident investigation aligned with the MITRE ATT&CK framework. Experienced in end-to-end security assessments, CVSS-based risk scoring, Azure cloud security review, and remediation collaboration with development teams to support secure SDLC practices. Proficient in Python and SQL for security automation and data analysis.
Skills & Expertise (46)
Work Experience
Cybersecurity Analyst Intern
JRS Innovation Pvt. Ltd.
Jan 2026 - Jun 2026
Performed Web Application Penetration Testing across 7+ live international production platforms; exploited an OData Injection flaw on Prime to achieve full database enumeration and critical Account Takeover (ATO). Identified and validated Authentication Bypass, Azure Blob Storage misconfigurations, IDOR on web applications and Android APKs, and Privilege Escalation vulnerabilities by exploiting missing server-side authorization checks. Conducted Android APK Security Testing using MobSF, Frida, JADX, and APKTool; uncovered JWT validation issues, insecure local data storage, unrestricted file upload, double-extension bypass, missing CSP headers, and absent rate-limiting controls. Deployed and monitored Wazuh SIEM across Linux and Windows endpoints; performed live alert triage, log analysis, and incident investigation using MITRE ATT&CK TTP mapping. Authored CVSS-scored vulnerability reports with clear reproduction steps and remediation guidance, enabling development teams to close findings efficiently.
Virtual Intern — Ethical Hacking & Penetration Testing
C-DAC Noida
May 2025 - Jul 2025
Executed vulnerability assessment and penetration testing exercises in controlled lab environments, applying structured VAPT methodology. Developed a Cyber Kill Chain research project mapping each attack lifecycle phase to corresponding detection and defense strategies.
Education
B.Tech in Cyber Security - Government Engineering College, Ajmer
2022 - 2026 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (46)
Click a skill to find developers with the same skill