Back to Developers
Ganesh babu

Ganesh babu

Cyber Security Consultant (VAPT)

Hyderabad, India 3+ yrs exp 86 · Excellent

About

Cybersecurity Consultant with 3+ years of experience delivering end-to-end VAPT across Web, Mobile (Android/iOS), API, Network, and Cloud environments. I am skilled in adversary simulation, vulnerability enumeration, and manual exploitation to demonstrate real-world business impact. Strong knowledge of OWASP Top 10, SANS Top 25, CWE, and NIST SP 800-115, with experience mapping exploited techniques to the MITRE ATT&CK framework. Experienced in preparing PoC-driven reports, impact analysis, CVSS scoring, and collaborating with development/infrastructure teams for remediation and security hardening.

Skills & Expertise (46)

Web Application Security Advanced
8.4/10
3
Years Exp
Burp Suite Advanced
8.3/10
3
Years Exp
API Security Testing Advanced
8.2/10
3
Years Exp
Network VAPT Advanced
8.1/10
3
Years Exp
Nessus Advanced
8.1/10
3
Years Exp
Android Security Testing Advanced
8.0/10
3
Years Exp
OWASP ZAP Advanced
7.9/10
3
Years Exp
Postman Advanced
7.8/10
3
Years Exp
IDOR RCE Broken Authentication Session Hijacking JWT Attacks CORS Host Header Injection File Upload Command Injection MITRE ATT&CK framework Privilege Escalation Rate Limiting Clickjacking SPF OWASP Top 10 SANS Top 25 CWE NIST SP 800-115 CIS Benchmarks Qualys Nuclei Rapid7 Acunetix SQL map Nmap Metasploit WIRESHARK Hydra John the Ripper Lfi MobSF Android Studio Frida ADB AWS APK Tool SQLI XSS

Work Experience

Cyber Security Consultant (VAPT)

RHYM Technologies LLP

Mar 2025 - Present

Performed end-to-end VAPT across Web, Mobile (Android/iOS), API, Network, and Cloud environments, identifying critical vulnerabilities and demonstrating business impact through manual exploitation, aligned with OWASP Top 10 and NIST SP 800-115. Performed SAST & DAST using SonarQube, MobSF, and Burp Suite to identify code-level and runtime vulnerabilities. Conducted AWS/GCP cloud security assessments including IAM privilege escalation, storage exposure, metadata service abuse, and security group/firewall misconfigurations aligned with CIS Benchmarks. Executed advanced Android/iOS testing using Frida for SSL pinning bypass and API interception to detect insecure data handling and authentication flaws. Delivered PoC-driven reports with CVSS scoring, risk analysis, and collaborated with engineering teams for remediation support, retesting, and continuous security improvement.

Cyber Security Analyst

HKIT Security Solutions

Mar 2023 - Feb 2025

Performed VAPT across Web, Mobile (Android/iOS), API, and Network environments aligned with OWASP Top 10 testing standards. Conducted reconnaissance, vulnerability enumeration, and manual exploitation to simulate real-world attack scenarios on applications and critical CERT platforms, creating detailed PoCs to demonstrate business impact, while mapping exploited techniques to the MITRE ATT&CK framework. Performed onsite Web and Network assessments using Burp Suite, Nessus, and Nmap to identify exposed services, misconfigurations, and missing patches across critical client infrastructure. Performed SAST/DAST using SonarQube, MobSF, and Burp Suite to identify insecure code patterns and runtime vulnerabilities. Delivered comprehensive assessment reports including PoCs, CVSS scoring, business impact analysis, and collaborated with development teams for remediation and patch validation.

Education

B. Tech – Mechanical Engineering - Narasaraopet Engineering College

2018 - 2021 · Afghanistan

Diploma – Mechanical Engineering - Divi Seema Polytechnic

2014 - 2017 · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 11/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 86/100

Profile Overview

Member sinceMay 2026

Availability Details

Visa Status

Citizen

Relocation

Open to Relocation