Mandru Tirumala Kishore
Senior Analyst
About
Results-driven Information Security professional with 4 years of experience in Vulnerability Assessment & Penetration Testing (VAPT), PCI DSS assessments, and Network Segmentation Testing. Proven expertise in identifying, validating, and mitigating security vulnerabilities across web applications, servers, and network infrastructure. Skilled in using industry-standard tools such as Tenable Nessus, Metasploit, and Wireshark, with strong knowledge of OWASP Top 10, vulnerability remediation, and compliance frameworks. Adept at delivering actionable security insights and collaborating with cross-functional teams to strengthen organizational security posture.
Skills & Expertise (19)
Work Experience
Senior Analyst
HCL Technologies
Aug 2022 - Jul 2026
Led and completed 30+ cybersecurity projects, maintaining a 100% on-time delivery record. Uncovered and documented 10+ critical, 30+ high, and 40+ medium severity vulnerabilities, surpassing automated tools' capabilities. Led comprehensive VAPT activities for web applications and internal assets, improving security resilience by 50%. Achieved a 25% reduction in security risks within Active Directory environments through detailed risk assessments. Led VAPT engagements for internal and external applications, servers, and network infrastructure. Conducted PCI DSS security assessments, identified compliance gaps, and verified remediation activities. Executed PCI network segmentation testing to ensure isolation between PCI and non-PCI environments. Validated exploitable vulnerabilities using Metasploit to assess business impact and risk. Performed manual validation and revalidation of vulnerabilities identified through Nessus scans. Conducted web application security assessments against OWASP Top 10 vulnerabilities. Delivered detailed technical reports with risk ratings, proof of concept, business impact, and remediation recommendations. Collaborated with application, infrastructure, and network teams to support remediation and vulnerability closure. Supported internal security assessments, compliance audits, and client security validation activities. Executed network security assessments to identify open ports, insecure services, weak configurations, and potential attack vectors across internal and external environments. Utilized industry-standard tools such as Nessus Professional and Burp Suite Professional for automated vulnerability scanning, manual validation, and exploitation. Identified, validated, and safely exploited critical server-side and client-side vulnerabilities, ensuring accurate risk assessment and effective remediation support. Conducted detailed security configuration reviews on Windows and Linux servers and prepared comprehensive vulnerability assessment reports with remediation recommendations.
Education
SSC - Veda the school of learning
- 2011 ยท Afghanistan
Intermediate - Chaitanya junior college
- 2013 ยท Afghanistan
B-Tech - Narasaraopet engineering college
- 2017 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (19)
Click a skill to find developers with the same skill