Cybersecurity expert with 6+ years of deep experience in Application Security, Penetration Testing (VAPT), and Risk/Threat Management. I specialize in

Skills

Application securityPentestingSecurity assessment

Bio

 

PROFILE SUMMARY

  • Dynamic and results-driven professional with 6.2+ years of extensive experience in application security, vulnerability assessments, penetration testing (VAPT), and risk assessment, specializing in fortifying organizational security frameworks and securing enterprise environments and critical business applications.
  • Proven expertise in managing, leading, and conducting comprehensive security assessments, and implementing effective risk mitigation strategies to safeguard critical assets and mitigate potential threats.
  • Extensive experience in application security and performing comprehensive penetration testing on various platforms.
  • Expertise in secure architecture reviews (network and cloud), and conducting baseline configuration reviews for operating systems, databases, Active Directory, and firewalls.
  • Collaborated with CISO teams, Risk and Threat Management, and performed tabletop exercises.
  • Strong background in creating and delivering phishing simulation campaigns, conducting security awareness training, and advising developers on secure coding practices to foster a culture of cybersecurity.
  • Expertise in aligning security practices with leading frameworks such as ISO 27001, PCI DSS, OWASP, NIST, and CIS, ensuring compliance with industry regulations and enhancing organizational security posture.
  • Expertise in report writing and executive communication, preparing and presenting Security Assessment Reports (SARs) and risk mitigation strategies to C-suite executives and stakeholders for informed decision-making.

CORE COMPETENCIES

  • Application Security
  • Penetration Testing (VAPT)
  • Vulnerability Assessment & Management
  • Secure Architecture Review
  • API Security
  • Network Security
  • Mobile Security
  • Security Controls Reviews
  • Risk/Threat Management

 CERTIFICATIONS

  • ISO 27001:2022 Lead Auditor
  • CCSK: Cloud Security Knowledge v4
  • EWPTXv2: Web Application Penetration Tester eXtreme
  • CMPEN: Certified Mobile Pentester - Android
  • CRTP: Certified Red Team Professional
  • AZ-900: Microsoft Azure Fundamentals
  • CAP: Certified AppSec Practitioner
  • CEH: Certified Ethical Hacker
  • ECSA: Certified Security An

 

Location

Mumbai, Maharashtra, IN Flag of

 5 Last updated about 5 days ago