About Me
Application Security | Software Engineer | Open Source Enthusiast
I’m passionate about understanding how systems and technologies are built—and how they can be broken. I explore application architecture by breaking it, fixing it, and rebuilding it to be more secure.
What I Do
I specialize in application security engineering, with a strong focus on how systems are designed, abused, and secured in real-world environments.
- Security Testing — Manual black-box and gray-box testing of web, API, network, and Android applications
- Vulnerability Research — Everything that breaks applications, from broken access control and business logic flaws to unsafe input handling and excessive data exposure
- Secure Engineering — Translating findings into clean, developer-friendly fixes, mitigations, and security tooling
Education
Bachelor of Engineering in Computer Engineering
University of Mumbai • Mumbai
Certifications
- Certified Ethical Hacker (CEH) v13
- Certifeied Network Security Practitioner (CNSP)
Experience
Associate Consultant — Application Security — CyRAACS June 2025 — Present • Navi Mumbai
Performed gray-box security testing on 48+ Web, API, and Mobile-backed systems.
- Identified 50+ high-impact flaws — BAC, IDOR, auth bypass, logic abuse, race conditions, SQLi, XSS.
- Mapped attack paths via workflow abuse and backend logic exploitation.
- Delivered developer-friendly reports with PoCs and fixes.
Technologies:
Manual AppSec, Web Security Testing, API Security Testing, Android Security Testing, OWASP-Top 10, OSINT, BurpSuite, Nmap
Backend Developer — Credility November 2023 — March 2025 • Mumbai
Built backend services for digital lending platforms used by financial institutions.
- Engineered backend services for fintech lending platforms.
- Implemented secure REST APIs with auth, authorization, and RBAC.
- Integrated Aadhaar CKYC with regulated security controls.
- Strengthened foundations in secure data handling and trust boundaries.
Technologies:
PHP, Laravel, JavaScript, JQuery, JSON, Linux Admin, Git, MySQL, APIs, Secure Coding Practices
