About
M.Tech Cybersecurity qualified Security Analyst with ~2 years of experience securing SEBI/RBI-regulated financial systems. Specializing in offensive security, I lead VAPT across Web, Mobile, and RESTful APIs using OWASP Top 10 methodology to uncover high-impact vulnerabilities including Account Takeover, IDOR, and BOLA across 50+ production applications. Proficient in manual exploitation, paired with automated vulnerability assessment. Experienced in supporting SEBI/RBI audit cycles and ISO/IEC 27001:2022 compliance validation. Backed by a SOC foundation in threat detection, CTI and with an early edge in AI/LLM security (prompt injection, OWASP LLM Top 10). Skilled at translating technical findings into risk-rated, actionable reports for clients and audit teams. Currently building AWS cloud security expertise to extend offensive testing into cloud-native environments.
Skills & Expertise (30)
Work Experience
Senior Security Analyst
Computer Age Management Systems (CAMS)
Sep 2024 - Present
Delivered high-impact findings across 50+ web applications by identifying and exploiting critical-risk vulnerabilities including Account Takeover (ATO), IDOR, and complex business logic flaws, enabling effective risk prioritization and remediation. Uncovered critical API-layer vulnerabilities including Broken Object Level Authorization (BOLA), excessive data exposure, and authentication flaws through targeted REST API penetration testing. Performed assessments on internally developed applications under SEBI, RBI-mandated audit cycles, delivering CVSS-scored reports with PoCs and remediation guidance, while validating outputs against ISO/IEC 27001:2022 controls like tracking NC closure status, testing cadence, and audit report completeness for regulatory readiness. Executed jailbreak detection bypass and SSL pinning bypass for dynamic analysis on Android/iOS using Frida, Objection, MobSF, and JADX-GUI, identifying insecure data storage and authentication bypass flaws. Referenced infrastructure security findings from CloudGuard CSPM and Microsoft Defender for Cloud to supplement on-premises and cloud-hosted vulnerability assessments, correlating gaps across hybrid environments. Operated SOC tooling Qualys, SentinelOne, Splunk, Wazuh. Designed, executed, and led an organization-wide phishing simulation campaign, tracking click-through and credential-submission rates and delivering security awareness recommendations to leadership.
Automotive Security Intern
Bosch
Jul 2023 - Jul 2024
Analyzed AUTOSAR SecOC protocol for ECU communication design weaknesses, identifying spoofing/replay attack vectors and proposing mitigation's aligned with ISO/SAE 21434.
Education
Master of Technology in Cybersecurity - Amrita Vishwa Vidyapeetham
2022 - 2024 ยท Afghanistan
Bachelor of Technology in Computer Science Engineering - University College of Engineering Kakinada(A), JNTU Kakinada
2017 - 2022 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (30)
Click a skill to find developers with the same skill