Index finger pointing up icon

From: India

Location: Zirakpur, IN

On Useme since 18 September 2026

About me

Security engineer specialising in offensive and application security.

I work inside an enterprise AppSec programme, running vulnerability management across web apps, APIs, cloud and infrastructure: SAST and SCA via Checkmarx One, DAST via Invicti, infrastructure scanning via Tenable, with remediation tracked to closure rather than handed over as a PDF.

What I do for clients:

- Penetration testing for web apps and APIs. Manual testing with proof of concept, not scanner output - Cloudflare WAF, Zero Trust and bot protection configuration - Malware removal and recovery for compromised sites and servers - Server and website hardening, security audits, cloud assessments - Incident response

Recent work includes a seven domain audit analysing over 98,000 firewall events, which surfaced two active threat actors the client was unaware of.

Certifications: HTB CJCA and HTB COAE. Working toward HTB CPTS.

Every finding ships with a CVSS score, reproduction steps and a fix your developers can act on.

CV / Résumé

May 2022 - Now

Security Engineer

Monotype

Performing penetration testing and vulnerability assessments across web applications, APIs, and cloud infrastructure for an enterprise SaaS company. Identifying and remediating security risks using OWASP, STRIDE, Burp Suite, Checkmarx, and SonarQube.

Jan 2018 - Now

Freelance

Confidential Clients

Conducted penetration testing engagements across 3 enterprise clients - an ERP platform, a hospital network, and an e-commerce platform - 2 US-based and 1 India-based. All work performed under NDA.