Career Profile

I am a highly motivated and skilled cybersecurity professional. Currently, I am pursuing a Master's in Cybersecurity Engineering from the University of Maryland, College Park. My areas of expertise include application security, vulnerability management and analysis, penetration testing, secure coding, and threat modeling. I have work experience of more than 2+ years in the software and security industry. I have made impactful contributions and displayed leadership qualities in various projects at companies - Yahoo, HackerOne, Oracle, and Credit Suisse with a high user base. Bug bounty hunter and recognized by Fitbit, CloudWays, and Teemill. Advocate of community-driven security and a volunteer at OWASP. Develop security tools to be used by the community for automating various processes in threat hunting. Currently available for full-time roles starting from June 2024 and Spring 2024 internships.

Experiences

Paranoids Security Engineer Intern

Jun 2023 - Aug 2023
Yahoo, US

• Implemented ETL pipelines on Databricks for Yahoo bug bounty data, streamlining data processing and enhancing efficiency. Ensured robust security measures and proactive workflow alerting mechanisms.
• Expertly triaged security reports for Yahoo assets during the HackerOne Ambassador World Cup 2023, driving efficient vulnerability resolution. Assisted in severity analysis, asset owner identification and collaborated with developers for swift bug fixes
• Worked on PoC for automated validation of security risks from HackerOne reports using custom Nuclei templates • Gained a comprehensive understanding of security infrastructure specifications, as well as expertise in vulnerability management and incident response workflows

Security Analyst

Oct 2021 - July 2022
HackerOne

• Validated 2000+ security reports from researchers on the web, windows, and android platforms. Analyzed their impact through CVSS and shared the results with an extensive summary with the client
• Worked directly with the customers to mitigate high severity issues like SQL Injection, IDOR, subdomain and account takeovers, and ensuring the issue is not reproducible for any other codebase
• Developed security tools in bash and python to automate verification process of low-level bugs and got profound insights into tools like Burp Suite, Fiddler, MetaSploit, Wireshark

Application Engineer

Sep 2020 - Oct 2021
Oracle, Hyderabad

• Managed and developed distributed and fault-tolerant python applications that efficiently migrated billions of rows of data through hops between multiple relational databases.
• Successfully implemented a quality-check application on Flask that automated the data correctness process, leading to an increase in efficiency by 70%
• Automated code deployment in multiple environments by leveraging Gitlab CI/CD pipelines, Kubernetes and Docker

Software Developer (Intern)

May 2019 - July 2019
Credit Suisse India, Pune

Optimization of existing applications by implementing multi-threading in Java and working with Angular on the front-end side. Working with the team to develop monitoring systems for their services in Java 8. Experience with performance analysis, optimization, and benchmark evaluations.

Projects

IP Grep - • Developed a Python-based fast command line application that finds a specific IP from a huge load of Apache HTTP logs, helpful in analyzing traffic during any intrusion or attacks and also supports CIDR range mapping to the log
AllRecon - • Developed a bash tool to identify all valid directory routes of all the subdomains of the input domain. Fast and efficient service which leverages the functionalities of Subfinder and Dirsearch tools.

Skills & Proficiency

Python, Bash, C/C++, SQL, HTML/CSS, JavaScript

Databricks, Kubernetes, Docker, Git, AWS (EC2, SQS/SNS), Athenz, Oracle, Hashi Vault, Kibana, Django

Burp Suite, Nuclei, Nessus, Ghidra, Wireshark, OWASP tools, Nmap, ChatGPT/LLM, Threat Modeling