Back to Developers
BhavyaSri Manduva

BhavyaSri Manduva

Security Engineer

Bengaluru, India 80 · Excellent

About

Security Engineer with 3.7+ years of experience in Vulnerability Assessment and Penetration Testing (VAPT) across web, mobile, API, network, and cloud environments. Proven ability to identify and remediate critical vulnerabilities including SQL Injection, IDOR, XSS, and authentication flaws across multiple enterprise applications. Skilled in manual and automated security testing, secure SDLC practices, and risk-based vulnerability management. Strong expertise in OWASP Top 10, application security testing, and stakeholder communication in fast-paced environments.

Skills & Expertise (33)

Web Application Security Testing Advanced
8.5/10
3.7
Years Exp
Burp Suite Advanced
8.5/10
3.7
Years Exp
API Security Testing Advanced
8.2/10
3.7
Years Exp
Vulnerability Assessment Advanced
8.0/10
3.7
Years Exp
Kali Linux Advanced
8.0/10
3.7
Years Exp
CloudWatch Advanced
8.0/10
3.7
Years Exp
CloudTrail Advanced
8.0/10
3.7
Years Exp
Security Groups Advanced
8.0/10
3.7
Years Exp
VPC Advanced
8.0/10
3.7
Years Exp
S3 Advanced
8.0/10
3.7
Years Exp
EC2 Advanced
8.0/10
3.7
Years Exp
IAM Advanced
8.0/10
3.7
Years Exp
AWS Advanced
8.0/10
3.7
Years Exp
mobile application security Advanced
7.8/10
3.7
Years Exp
Windows Advanced
7.5/10
3.7
Years Exp
WIRESHARK Advanced
7.5/10
3.7
Years Exp
Network Penetration Testing Advanced
7.5/10
3.7
Years Exp
OWASP ZAP Advanced
7.5/10
3.7
Years Exp
Nmap Advanced
7.5/10
3.7
Years Exp
Nessus Advanced
7.5/10
3.7
Years Exp
Metasploit Advanced
7.5/10
3.7
Years Exp
Secure SDLC Intermediate
7.2/10
3.7
Years Exp
MobSF Intermediate
7.0/10
3.7
Years Exp
Threat Modeling Intermediate
7.0/10
3.7
Years Exp
JADX Intermediate
7.0/10
3.7
Years Exp
Frida Intermediate
7.0/10
3.7
Years Exp
Microsoft Threat Modeling Tool Intermediate
7.0/10
3.7
Years Exp
Veracode Intermediate
7.0/10
3.7
Years Exp
Snyk Intermediate
7.0/10
3.7
Years Exp
OWASP Dependency-Check Intermediate
7.0/10
3.7
Years Exp
Objection Intermediate
7.0/10
3.7
Years Exp
Postman Intermediate
7.0/10
3.7
Years Exp
Risk Management Intermediate
6.8/10
3.7
Years Exp

Work Experience

Security Engineer – VAPT

DXC Technologies

Sep 2022 - Present

Conducted VAPT on 25+ web applications and APIs, identifying 150+ vulnerabilities including critical issues such as SQL Injection, IDOR, XSS, and Broken Authentication. Performed manual penetration testing using Burp Suite, validating vulnerabilities through request manipulation, session tampering, and business logic testing. Identified and exploited access control issues, improving authorization mechanisms and reducing risk exposure. Tested authentication workflows, session management, and token handling (JWT, Bearer tokens) for security flaws. Validated vulnerabilities through proof-of-concept (PoC) and provided actionable remediation recommendations to development teams. Performed security assessments on Android applications using MobSF, Frida, and JADX, identifying issues such as insecure data storage, hardcoded secrets, and weak encryption practices. Bypassed SSL pinning and root detection mechanisms to perform advanced runtime analysis. Intercepted and modified mobile traffic to identify insecure API communication and sensitive data exposure. Assessed local storage mechanisms (SharedPreferences, SQLite, logs) for data leakage risks. Conducted internal and external network penetration testing, identifying vulnerabilities related to misconfigurations, weak services, and insecure protocols. Performed reconnaissance and enumeration using Nmap, Masscan, Netdiscover, identifying exposed services and attack surfaces. Executed vulnerability scans using Nessus, followed by manual validation to eliminate false positives. Performed Man-in-the-Middle (MITM) attacks to analyze traffic and identify credential exposure risks. Assisted in cloud security assessments for applications hosted on AWS, identifying misconfigurations across IAM, S3, EC2, and VPC components. Reviewed IAM roles and policies to detect excessive privileges and enforce least privilege principles. Identified publicly exposed S3 buckets, weak security group rules, and improper network configurations. Evaluated logging and monitoring using CloudTrail and CloudWatch to improve audit visibility. Managed end-to-end vulnerability lifecycle including identification, reporting, remediation tracking, and retesting. Delivered detailed VAPT reports with risk ratings, PoC, impact analysis, and mitigation strategies. Collaborated with development and DevOps teams to ensure timely remediation of critical vulnerabilities. Built dashboards and reports for stakeholders, improving visibility into organizational security posture. Integrated security practices into Secure SDLC (SSDLC), enabling early detection of vulnerabilities. Participated in threat modeling (STRIDE) to identify risks during design phase and reduce attack surface.

Education

Bachelor of Engineering (Computer Science)

- · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 5/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 80/100

Profile Overview

Member sinceApr 2026