Cybersecurity expert with 6+ years of deep experience in Application Security, Penetration Testing (VAPT), and Risk/Threat Management. I specialize in
Skills
Application securityPentestingSecurity assessment
Bio
PROFILE SUMMARY
- Dynamic and results-driven professional with 6.2+ years of extensive experience in application security, vulnerability assessments, penetration testing (VAPT), and risk assessment, specializing in fortifying organizational security frameworks and securing enterprise environments and critical business applications.
- Proven expertise in managing, leading, and conducting comprehensive security assessments, and implementing effective risk mitigation strategies to safeguard critical assets and mitigate potential threats.
- Extensive experience in application security and performing comprehensive penetration testing on various platforms.
- Expertise in secure architecture reviews (network and cloud), and conducting baseline configuration reviews for operating systems, databases, Active Directory, and firewalls.
- Collaborated with CISO teams, Risk and Threat Management, and performed tabletop exercises.
- Strong background in creating and delivering phishing simulation campaigns, conducting security awareness training, and advising developers on secure coding practices to foster a culture of cybersecurity.
- Expertise in aligning security practices with leading frameworks such as ISO 27001, PCI DSS, OWASP, NIST, and CIS, ensuring compliance with industry regulations and enhancing organizational security posture.
- Expertise in report writing and executive communication, preparing and presenting Security Assessment Reports (SARs) and risk mitigation strategies to C-suite executives and stakeholders for informed decision-making.
CORE COMPETENCIES
- Application Security
- Penetration Testing (VAPT)
- Vulnerability Assessment & Management
- Secure Architecture Review
- API Security
- Network Security
- Mobile Security
- Security Controls Reviews
- Risk/Threat Management
CERTIFICATIONS
- ISO 27001:2022 Lead Auditor
- CCSK: Cloud Security Knowledge v4
- EWPTXv2: Web Application Penetration Tester eXtreme
- CMPEN: Certified Mobile Pentester - Android
- CRTP: Certified Red Team Professional
- AZ-900: Microsoft Azure Fundamentals
- CAP: Certified AppSec Practitioner
- CEH: Certified Ethical Hacker
- ECSA: Certified Security An
Location
Mumbai, Maharashtra, IN
5 Last updated about 5 days ago
Role interests
Application Security AnalystCyber Security Analyst
Mid-level / IntermediateSenior-level / Expert
Job type interests
Full Time
Regional interests