priya kathroju
Cyber Security Analyst
About
Cyber Security Analyst with 4+ years of experience in Vulnerability Assessment and Penetration Testing (VAPT), Web Application Security Testing, and API Security Testing, aligned with OWASP Top 10 standards. Skilled in identifying, validating, and reporting critical vulnerabilities โ including SQL Injection, XSS, CSRF, IDOR, Broken Authentication, and Access Control flaws โ using Burp Suite Professional, OWASP ZAP, Nessus, and IBM App Scan. Experienced in API security testing with Postman and SoapUI, network scanning with Nmap and Wireshark, and Android mobile application penetration testing. Proven track record supporting banking and financial services clients, partnering with development teams to remediate vulnerabilities and strengthen secure SDLC practices.
Skills & Expertise (35)
Work Experience
Cyber Security Analyst
Capgemini
Mar 2024 - Present
Perform manual and tool-assisted web application penetration testing for internal and external banking applications using Burp Suite, SSLyze, and SoapUI, benchmarked against the OWASP Top 10. Conduct business logic testing to validate application functionality and ensure sensitive customer and financial data is properly protected. Identify and document high-severity vulnerabilities, including SQL Injection, XSS, CSRF, missing functional-level access control, and SSL/TLS misconfigurations. Author detailed vulnerability reports covering issue description, reproduction steps, risk rating, and remediation guidance for application stakeholders. Lead report-out calls with application managers to walk through findings and align on remediation timelines. Advise development teams on technology-specific, in-built security controls to resolve identified vulnerabilities. Partner with application teams throughout the assessment lifecycle, resolving technical blockers and promoting secure SDLC adoption to reduce release-related security risk.
Cyber Security Analyst
Wipro
Oct 2022 - Feb 2024
Conducted vulnerability assessments of internal and external-facing web applications using Burp Suite, Nessus, and OWASP ZAP. Performed Vulnerability Assessment and Penetration Testing (VAPT) using IBM App Scan across internal and external web applications. Executed API security testing with Postman, uncovering issues such as parameter tampering and unauthorized endpoint/method access. Carried out Android mobile application security testing to identify platform-specific vulnerabilities. Performed network scanning and packet analysis using Nmap and Wireshark to support infrastructure security assessments. Assessed applications against common attack vectors, including SQL Injection, XSS, CSRF, IDOR, and session management flaws per OWASP standards.
Education
Master of Computer Applications (MCA) - Osmania University
- ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (35)
Click a skill to find developers with the same skill