Back to Developers
Deepu Muppidi

Deepu Muppidi

Cybersecurity professional

India 4+ yrs exp 88 ยท Excellent

About

Cybersecurity professional with 4 years of experience in penetration testing, vulnerability assessment, and application security. Proven expertise in conducting black-box, grey-box, and white-box security assessments of web applications, web services, APIs, and mobile applications. Skilled in manual and automated testing methodologies aligned with OWASP Top 10 and SANS CWE Top 25 frameworks. Experience delivering technical and executive-level vulnerability reports for global financial and enterprise clients including Citibank and Experian. Adept at integrating security into the Software Development Life Cycle (SDLC) and working cross-functionally with development and operations teams.

Skills & Expertise (34)

OWASP Top 10 Advanced
8.5/10
4
Years Exp
Web Application Pentesting Advanced
8.5/10
4
Years Exp
Burp Suite Pro Advanced
8.5/10
4
Years Exp
Network Pentesting Advanced
8.0/10
4
Years Exp
Mobile Application Security Testing Advanced
8.0/10
4
Years Exp
API Security Testing Advanced
8.0/10
4
Years Exp
Nessus Advanced
7.5/10
4
Years Exp
Threat Modeling Advanced
7.5/10
4
Years Exp
Risk Assessment Advanced
7.5/10
4
Years Exp
Vulnerability Reporting Advanced
7.0/10
4
Years Exp
CVSS scoring Ubuntu Kali Linux LINUX Windows SDLC Integration Security Code Review Privilege Escalation Session Management Testing OTP Bypass Remediation Guidance PTES DAST Grey-box Testing Veracode Nmap Black-Box Testing Acunetix IBM AppScan WebInspect SQLmap OWASP ZAP White-Box Testing SAST

Work Experience

Security Consultant

Deloitte

Nov 2023 - Present

Conduct end-to-end penetration testing engagements for enterprise clients including black-box, grey-box, and white-box assessments of web applications, APIs, and mobile applications. Identify and exploit vulnerabilities aligned with OWASP Top 10 and SANS CWE Top 25, including injection flaws, broken access control, authentication bypass, and cryptographic weaknesses. Perform MFA bypass attacks including OTP circumvention and CAPTCHA exploitation to demonstrate authentication control weaknesses. Execute automated vulnerability scans using Burp Suite Pro, AppScan, and Acunetix; triage results to eliminate false positives and confirm exploitable true-positive findings. Deliver risk-rated Technical and Executive vulnerability reports with CVSS scores, proof-of-concept evidence, and actionable remediation recommendations. Collaborate with development and engineering teams to embed security practices into the SDLC, providing remediation guidance and conducting retests to verified closure. Perform threat modeling on application architecture and technical design documents to identify security risks prior to development.

Security Engineer - Penetration Testing

Experian

Present - Present

Mapped the full attack surface of the Experian web application, classifying the assessment scope as grey-box in coordination with the development team. Identified vulnerabilities in key derivation functions and cryptographic implementations; created detailed vulnerability assessment reports with severity ratings and mitigation recommendations. Successfully bypassed Multi-Factor Authentication (MFA) mechanisms including OTP and CAPTCHA, exposing critical authentication control weaknesses. Reviewed automated AppScan reports, separated false positives from confirmed true-positive vulnerabilities, and escalated high and critical severity findings for immediate remediation. Focused assessment on high-risk entry points likely to yield high, medium, and critical severity vulnerabilities prior to initiating full testing.

Security Engineer - Web Application Security

Citibank

Present - Present

Performed dynamic application security testing (DAST) using Burp Suite on Citibank web applications, targeting all OWASP Top 10 vulnerability categories. Identified, risk-rated, and documented vulnerabilities; produced both technical vulnerability reports for developers and executive summary reports for management. Carried out grey-box and black-box security assessments and provided detailed remediation recommendations to mitigate discovered weaknesses. Coordinated with internal development and operations teams to track vulnerabilities from discovery through to verified remediation closure.

Security Consultant

Amazon Development Center India Pvt. Ltd.

Jun 2022 - Oct 2023

Executed dynamic application security testing (DAST) on web applications and REST APIs, identifying critical vulnerabilities including SQL injection, IDOR, XSS, and insecure deserialization. Conducted grey-box and black-box penetration testing of web applications using Burp Suite Pro, focusing on OWASP Top 10 attack categories. Identified, risk-rated, and documented vulnerabilities using CVSS scoring; tracked remediation with engineering teams through to validated closure. Performed mobile application security testing on iOS and Android platforms covering traffic interception, insecure data storage, and reverse engineering. Supported secure SDLC by reviewing security requirements, analyzing design documents for threats, and advising developers on security best practices. Effectively communicated findings and mitigation strategies to both technical teams and non-technical stakeholders through written reports and verbal briefings.

Education

Bachelor of Technology (B.Tech) - Mechanical Engineering - Sphoorthy Engineering College

- 2018 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 13/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 88/100

Profile Overview

Member sinceJul 2026