about
(legally... mostly)
Application Security / Cyber Security Engineer focused on web, API, Android, and iOS VAPT. I spend most days doing gray-box testing, runtime analysis, vulnerability validation, and writing the kind of remediation notes that developers pretend not to hate.
Right now that means shipping AppSec work at MoveInSync, building internal automation, and making sure rooted phones, weak WebViews, or exposed endpoints don't quietly ruin everyone's week. Before that, I was hunting bugs on Bugcrowd, building weird tools, and collecting Hall of Fames from companies that definitely would have preferred a quieter email.
link bunker
everything public, in one place, so nobody has to go treasure hunting.
$ whoami --everywhere
Top 1%
TryHackMe global
20+
NCIIPC acks
#44
merged upstream PR
experience
(on purpose, I mean)
Cyber Security Engineer
MoveInSync -- Bengaluru, Karnataka, India
(the one where I actually get paid to break things)
Jun, 2025 -- Present
- Conduct end-to-end VAPT across web, API, Android, iOS, and infrastructure surfaces using gray-box testing, manual validation, static and dynamic analysis, Burp Suite, Postman, Frida, MobSF, JADX, apktool, and Nessus
- Turn vulnerabilities into developer-usable Jira tickets with evidence, reproduction steps, exploitability context, affected assets, remediation guidance, and closure validation
- Built internal AppSec automation for API inventory, external exposure review, endpoint risk detection, SQLite-backed result tracking, and repeatable validation
- Hardened Android flows against rooted-device abuse and Frida runtime attacks by integrating Google Play Integrity API and revalidating SSL pinning, WebView, and API-header controls
- Coordinate external VAPT work with vendors like Rudra and Coforge across test accounts, builds, finding triage, duplicate cleanup, fix validation, and stakeholder alignment
- Run Nessus AMI and compliance scans, tune plugins and checks, and cut down noisy findings before developer handoff
Application Security Intern
MoveInSync -- Bengaluru, Karnataka, India
(they liked me enough to keep me)
Jan, 2025 -- May, 2025
- Supported API, web, and mobile testing through endpoint enumeration, manual validation, evidence capture, and reproducible ticket creation
- Performed pre-assessment sanity testing for Android and iOS builds before external VAPT engagements
- Prototyped API discovery and exposure checks that later fed reusable internal security automation
- Assisted with Nessus review, API triage, reporting, documentation, and developer follow-through to remediation closure
Cyber Security R&D Intern
Securaeon Initiative -- Remote/Kolkata, West Bengal
(writing walkthroughs at 2 AM)
Feb, 2022 -- Jul, 2022
- Created security walkthroughs, proof-of-concept material, and practical lab content for upcoming cybersecurity products and courses
Security Researcher
Bugcrowd -- Freelance
(legally breaking into things for strangers)
Oct, 2021 -- Dec, 2021
- Reported web security vulnerabilities through open bug bounty programs, including findings later recognized in Hall of Fame listings and responsible-disclosure acknowledgments
- Communicated impact, proof of concept, and remediation context to program security teams to support timely validation and closure
projects
(fueled by questionable decisions and instant noodles)
Burp AI Agent
Merged upstream contribution to a Burp Suite extension for AI-assisted analysis, MCP tooling, privacy controls, and passive or active scanning. I added NVIDIA NIM backend support, settings persistence, and cleaner HTTP 429 handling.
TrashDroid
Terminal-first Android DAST framework that orchestrates ADB, drozer, apktool, sqlite3, logcat, screenshots, and filesystem analysis across 9 mobile assessment phases with AI-ready reporting.
TrashiOS
Terminal-first iOS SAST/DAST framework, the iOS counterpart to TrashDroid. Drives libimobiledevice, SSH-over-USB, Frida/objection, and otool/class-dump across 13 phases on a jailbroken iPhone with keychain dumps, Mach-O hardening checks, and AI-ready OWASP MASVS reporting.
TrashRecon
Dockerized recon framework chaining 17 tools across 10 phases for attack-surface mapping, screenshots, takeover checks, endpoint crawling, exposed-key checks, nuclei scans, and resumable output.
TrashFrame
Turns any Spotify album or song into a printable poster: 14 theme presets across 13 layouts, album-art and typography controls, canvas palette extraction, QR / Spotify codes, and PNG/PDF export at configurable DPI.
skills
(or at least what I claim on LinkedIn)
Application Security
Mobile Security
Security Tools
Automation & Dev
certifications
CompTIA Security+ (SY0-701)
CompTIA
Dec 2024
eWPTXv2
eLearnSecurity
Jan 2023
hall of fame & achievements