From: India
Location: Zirakpur, IN
On Useme since 18 September 2026
About me
Security engineer specialising in offensive and application security.
I work inside an enterprise AppSec programme, running vulnerability management across web apps, APIs, cloud and infrastructure: SAST and SCA via Checkmarx One, DAST via Invicti, infrastructure scanning via Tenable, with remediation tracked to closure rather than handed over as a PDF.
What I do for clients:
- Penetration testing for web apps and APIs. Manual testing with proof of concept, not scanner output - Cloudflare WAF, Zero Trust and bot protection configuration - Malware removal and recovery for compromised sites and servers - Server and website hardening, security audits, cloud assessments - Incident response
Recent work includes a seven domain audit analysing over 98,000 firewall events, which surfaced two active threat actors the client was unaware of.
Certifications: HTB CJCA and HTB COAE. Working toward HTB CPTS.
Every finding ships with a CVSS score, reproduction steps and a fix your developers can act on.
CV / Résumé
May 2022 - Now
Security Engineer
Monotype
Performing penetration testing and vulnerability assessments across web applications, APIs, and cloud infrastructure for an enterprise SaaS company. Identifying and remediating security risks using OWASP, STRIDE, Burp Suite, Checkmarx, and SonarQube.
Jan 2018 - Now
Freelance
Confidential Clients
Conducted penetration testing engagements across 3 enterprise clients - an ERP platform, a hospital network, and an e-commerce platform - 2 US-based and 1 India-based. All work performed under NDA.