Deepu Muppidi
Cybersecurity professional
About
Cybersecurity professional with 4 years of experience in penetration testing, vulnerability assessment, and application security. Proven expertise in conducting black-box, grey-box, and white-box security assessments of web applications, web services, APIs, and mobile applications. Skilled in manual and automated testing methodologies aligned with OWASP Top 10 and SANS CWE Top 25 frameworks. Experience delivering technical and executive-level vulnerability reports for global financial and enterprise clients including Citibank and Experian. Adept at integrating security into the Software Development Life Cycle (SDLC) and working cross-functionally with development and operations teams.
Skills & Expertise (34)
Work Experience
Security Consultant
Deloitte
Nov 2023 - Present
Conduct end-to-end penetration testing engagements for enterprise clients including black-box, grey-box, and white-box assessments of web applications, APIs, and mobile applications. Identify and exploit vulnerabilities aligned with OWASP Top 10 and SANS CWE Top 25, including injection flaws, broken access control, authentication bypass, and cryptographic weaknesses. Perform MFA bypass attacks including OTP circumvention and CAPTCHA exploitation to demonstrate authentication control weaknesses. Execute automated vulnerability scans using Burp Suite Pro, AppScan, and Acunetix; triage results to eliminate false positives and confirm exploitable true-positive findings. Deliver risk-rated Technical and Executive vulnerability reports with CVSS scores, proof-of-concept evidence, and actionable remediation recommendations. Collaborate with development and engineering teams to embed security practices into the SDLC, providing remediation guidance and conducting retests to verified closure. Perform threat modeling on application architecture and technical design documents to identify security risks prior to development.
Security Engineer - Penetration Testing
Experian
Present - Present
Mapped the full attack surface of the Experian web application, classifying the assessment scope as grey-box in coordination with the development team. Identified vulnerabilities in key derivation functions and cryptographic implementations; created detailed vulnerability assessment reports with severity ratings and mitigation recommendations. Successfully bypassed Multi-Factor Authentication (MFA) mechanisms including OTP and CAPTCHA, exposing critical authentication control weaknesses. Reviewed automated AppScan reports, separated false positives from confirmed true-positive vulnerabilities, and escalated high and critical severity findings for immediate remediation. Focused assessment on high-risk entry points likely to yield high, medium, and critical severity vulnerabilities prior to initiating full testing.
Security Engineer - Web Application Security
Citibank
Present - Present
Performed dynamic application security testing (DAST) using Burp Suite on Citibank web applications, targeting all OWASP Top 10 vulnerability categories. Identified, risk-rated, and documented vulnerabilities; produced both technical vulnerability reports for developers and executive summary reports for management. Carried out grey-box and black-box security assessments and provided detailed remediation recommendations to mitigate discovered weaknesses. Coordinated with internal development and operations teams to track vulnerabilities from discovery through to verified remediation closure.
Security Consultant
Amazon Development Center India Pvt. Ltd.
Jun 2022 - Oct 2023
Executed dynamic application security testing (DAST) on web applications and REST APIs, identifying critical vulnerabilities including SQL injection, IDOR, XSS, and insecure deserialization. Conducted grey-box and black-box penetration testing of web applications using Burp Suite Pro, focusing on OWASP Top 10 attack categories. Identified, risk-rated, and documented vulnerabilities using CVSS scoring; tracked remediation with engineering teams through to validated closure. Performed mobile application security testing on iOS and Android platforms covering traffic interception, insecure data storage, and reverse engineering. Supported secure SDLC by reviewing security requirements, analyzing design documents for threats, and advising developers on security best practices. Effectively communicated findings and mitigation strategies to both technical teams and non-technical stakeholders through written reports and verbal briefings.
Education
Bachelor of Technology (B.Tech) - Mechanical Engineering - Sphoorthy Engineering College
- 2018 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (34)
Click a skill to find developers with the same skill