Back to Developers
Uma Trivedi

Uma Trivedi

Junior Cybersecurity Engineer

Pune, Maharashtra 1+ yrs exp 83 · Excellent

About

Detail-oriented cybersecurity professional specializing in offensive security testing, with a Master's degree in Computer Science and hands-on experience gained through a structured internship and full-time role at CyberSecurist Technologies Pvt. Ltd. Skilled in manual web application, API, and mobile application penetration testing, vulnerability assessment, and security validation using industry-standard tools including Burp Suite, Nmap, OWASP ZAP, Acunetix, and SQLMap. Experienced in analyzing authentication and authorization mechanisms, business logic, HTTP traffic, and application workflows to identify exploitable security weaknesses. Track record of independently discovering high-impact vulnerabilities such as Account Takeover, Remote Code Execution (RCE), and Broken Access Control (BAC), and 1st-place winner of an in-house bug-bounty program. Combines strong analytical thinking, clear reporting, and effective teamwork to deliver secure, high-quality outcomes.

Skills & Expertise (25)

Web Application Penetration Testing Advanced
8.0/10
1
Years Exp
Burp Suite Advanced
8.0/10
1
Years Exp
OWASP ZAP Advanced
8.0/10
1
Years Exp
Nmap Advanced
8.0/10
1
Years Exp
Mobile Application Security Testing Intermediate
7.5/10
1
Years Exp
Communication Intermediate
7.5/10
1
Years Exp
Python Intermediate
6.5/10
1
Years Exp
Java Intermediate
5.5/10
1
Years Exp
WIRESHARK Authorization Testing Leadership Presentation MobSF SQLmap Acunetix Business Logic Testing Dirbuster HTML5 Nessus LINUX Windows MongoDb Postgresql MySql CSS3

Work Experience

Junior Cybersecurity Engineer

CyberSecurist Technologies Pvt. Ltd.

Oct 2025 - Present

Performed manual penetration testing for real-world client web applications and APIs, identifying security vulnerabilities through reconnaissance, attack surface analysis, business logic testing, authentication testing, authorization testing, and controlled exploitation. Conducted manual and tool-assisted web application security assessments using Burp Suite, Nmap, Gobuster, SQLMap, Acunetix, and OWASP ZAP to identify application security weaknesses. Identified, validated, and exploited critical vulnerabilities including Account Takeover, Remote Code Execution (RCE), Broken Access Control (BAC), Cross-Site Scripting (XSS), Server-Side Template Injection (SSTI), SQL Injection, Host Header Injection, HTTP Verb Tampering, HTML Injection, and CORS misconfigurations.

Trainee Cybersecurity Engineer

CyberSecurist Technologies Pvt. Ltd.

Jul 2025 - Oct 2025

Worked on real-time client penetration testing projects under senior security consultants. Conducted reconnaissance and scanning using Nmap, Burp Suite, OWASP ZAP, and Gobuster. Performed injection-based attacks and logic testing to uncover critical vulnerabilities. Discovered Broken Access Control issues, one of the most severe OWASP Top 10 risks within client applications. Assisted in vulnerability reporting, impact assessment, and remediation recommendations.

Software Security Engineer Intern

CyberSecurist Technologies Pvt. Ltd.

Jan 2025 - May 2025

Completed a structured cybersecurity internship focusing on Linux systems, web security, OS fundamentals, and network protocols. Gained hands-on experience with Linux environments: shell commands, file systems, mounting/unmounting, cron jobs, and memory/process management. Explored OSI & TCP/IP models, HTTP/HTTPS, FTP, SSH, SSL/TLS protocols, and web architecture, including APIs and MVC. Performed vulnerability assessments, penetration testing, and ethical hacking using Nmap, Nessus, Nikto, SQLMap, OWASP ZAP, and Burp Suite to identify misconfigurations and exploit paths. Solved 15+ PortSwigger labs related to Access Control and Authentication vulnerabilities including IDOR, broken access control, 2FA bypass, and password reset poisoning. Executed 20+ vulnerability scans and documented remediation steps, reducing critical vulnerabilities by 30% in internal testing environments. Contributed to an internal project by integrating backend functionalities, working on API integration, debugging, and managing data flow. Documented security findings, analyzed HTTP payloads, and studied exploitation techniques to better understand real-world attack surfaces.

Education

Master of Science in Computer Science (MSc CS) - Dr. Vishwanath Karad MIT World Peace University

2023 - 2025 · Afghanistan

Bachelor of Science in Computer Science (BSc CS) - H.P.T. ARTS & R.Y.K. Science College

2020 - 2023 · Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

📷 Photo 10/10
📄 Resume 10/10
💼 Job Title 10/10
✍️ Bio 10/10
🛠️ Skills 20/20
🎓 Education 10/10
⏱️ Experience 8/15
💰 Rate 0/5
🏆 Certs 0/5
Verified 5/5
Total Score 83/100

Profile Overview

Member sinceAug 2026