I test web applications, APIs, and CI/CD pipelines for the flaws that matter — authorization bugs, SSRF, JWT misconfigurations, and business logic breaks. Currently building AppSec fundamentals through hands-on testing, active bug bounty programs, and DevSecOps tooling, based in Pune, India.
I'm an aspiring Application Security Engineer currently pursuing a BCA at D. Y. Patil University, with hands-on security work running alongside my studies. My focus is Web and API penetration testing — finding and documenting real, reproducible vulnerabilities rather than theoretical ones.
I work through bug bounty platforms including HackerOne, Bugcrowd, and Intigriti, testing production applications for OWASP Top 10 issues, authentication and authorization flaws, and API-level weaknesses. On the DevSecOps side, I build CI/CD pipelines with integrated SAST, DAST, and SCA tooling, and work with AWS, Terraform, and Kubernetes to understand how security holds up in real infrastructure.
My core toolkit: Burp Suite, Nuclei, ffuf, sqlmap, Semgrep, and Gitleaks — used together to move from recon to a documented, defensible finding.
Discovered and reported a WAF bypass on Meesho's staging infrastructure, acknowledged by the Meesho Security Team. Found through manual testing after subdomain enumeration and JS-file analysis.
Based in Pune, India — open to remote and on-site opportunities.