Technical Skills
01TESTING TYPES
SECURITY & ENGINEERING
TOOLS
STANDARDS & FRAMEWORKS
Professional Experience
02
Cyber Security Analyst — Penetration Tester
JAN 2023 – PRESENT
Experion Technologies (India) Private Limited · Kochi, India
- Executed end-to-end penetration tests and vulnerability assessments across applications and infrastructure, identifying and validating vulnerabilities including authentication bypasses, IDOR, SQL injection, XSS, OTP bypasses, and privilege escalation; assessed business impact and provided remediation guidance to technical teams.
- Supported presales activities including technical scoping, effort estimation, and proposal development; managed engagements end-to-end, coordinating timelines, requirements, testing, stakeholder communication, and remediation follow-ups.
- Evaluated security configurations and compliance across 10+ AWS and Azure environments, identifying misconfigurations and compliance deviations, and recommending improvements to cloud security posture.
- Organised and executed large-scale phishing simulation campaigns across multiple departments to assess security awareness and improve organisational response effectiveness.
- Investigated and responded to security incidents by analysing alerts, identifying threats, and coordinating containment and remediation with relevant technical teams.
- Collaborated with technical and business stakeholders to communicate findings, explain business impact, and prioritise remediation through to resolution.
Selected Security Assessments
03
FEATURED
Global Automotive Manufacturer
FEB 2026 – JUL 2026
- Conducted penetration testing across web, API, and Windows thick client applications, identifying critical vulnerabilities including authorisation bypasses, Broken Function Level Authorisation (BFLA), and authentication bypasses.
- Assessed business impact and prepared prioritised remediation strategies to support secure product release.
- Supported the customer through remediation validation and reporting, contributing to CISO approval for product release.
US-Based EdTech Platform
JUL – SEP 2025
- Conducted penetration testing on web and mobile applications, identifying authentication bypass, sensitive information exposure, and privilege escalation; assessed impact and recommended remediation strategies.
- Performed source code review to identify critical vulnerabilities and prepared vulnerability reports with remediation strategies, supporting FedRAMP-aligned implementation.
Healthcare Application
APR – MAY 2025
- Conducted HIPAA-focused penetration testing on web and mobile applications, identifying critical vulnerabilities including IDORs, PHI exposure, and XSS. Assessed impact and recommended remediation strategies.
- Performed source code review to pinpoint critical vulnerabilities and provide actionable insights supporting HIPAA compliance.
- Prepared comprehensive vulnerability reports with detailed remediation strategies and supported implementation across all systems.
Multiple Banking Applications
JUN – NOV 2024
- Conducted end-to-end penetration testing on multiple high-value banking web applications, identifying critical vulnerabilities including SQL injection, XSS, and OTP bypasses, and assessing potential impact on core business operations and risk exposure.
- Collaborated with development and security teams to ensure effective implementation of fixes, reducing organisational risk and aligning with regulatory requirements.
Certifications, Education & Awards
04Let’s build something secure.
Open to penetration testing and application security roles. Happy to walk through methodology, past findings, or a specific engagement.