Available for AppSec internships & roles

Chetan Biranje
breaks things so others don't have to.

Application Security · Web & API VAPT · Bug Bounty Researcher

I test web applications, APIs, and CI/CD pipelines for the flaws that matter — authorization bugs, SSRF, JWT misconfigurations, and business logic breaks. Currently building AppSec fundamentals through hands-on testing, active bug bounty programs, and DevSecOps tooling, based in Pune, India.

01About

I'm an aspiring Application Security Engineer currently pursuing a BCA at D. Y. Patil University, with hands-on security work running alongside my studies. My focus is Web and API penetration testing — finding and documenting real, reproducible vulnerabilities rather than theoretical ones.

I work through bug bounty platforms including HackerOne, Bugcrowd, and Intigriti, testing production applications for OWASP Top 10 issues, authentication and authorization flaws, and API-level weaknesses. On the DevSecOps side, I build CI/CD pipelines with integrated SAST, DAST, and SCA tooling, and work with AWS, Terraform, and Kubernetes to understand how security holds up in real infrastructure.

My core toolkit: Burp Suite, Nuclei, ffuf, sqlmap, Semgrep, and Gitleaks — used together to move from recon to a documented, defensible finding.

HIGH  WAF Bypass — staging.valmo.in

Discovered and reported a WAF bypass on Meesho's staging infrastructure, acknowledged by the Meesho Security Team. Found through manual testing after subdomain enumeration and JS-file analysis.

Status: Acknowledged · Platform: HackerOne
02Experience
Jun 2023 — Present
Bug Bounty Researcher
HackerOne · Bugcrowd · Intigriti
  • Manual web and API security testing across live bug bounty programs, with focus on authorization flaws, JWT misconfigurations, and SSRF.
  • Findings documented with CVSS v3.1 scoring and reproducible proof-of-concept steps for engineering remediation.
  • Reported and acknowledged: WAF bypass on Meesho staging infrastructure (staging.valmo.in).
Dec 2025 — 2026
Security-Focused Full Stack Developer (Internship)
AI4SEE Private Ltd
  • Built a GitHub Actions CI/CD pipeline with integrated SAST, SCA, secret scanning, and DAST stages.
  • Applied OWASP API Top 10 controls to REST APIs, with least-privilege IAM and Docker/Terraform/Ansible hardening.
03Projects
DevSecOps Learning Lab
An 8-stage CI/CD pipeline hardening a Flask application — SAST, SCA, secrets, DAST, container and IaC scanning — with EKS provisioned via Terraform and CIS Level 2 hardening via Ansible.
GitHub Actions · Flask · Kubernetes · Terraform · Ansible · ZAP
github.com/Chetan-Biranje/devsecops-learning-lab ↗
Security Recon Toolkit
A 7-module CLI recon tool covering enumeration, scanning, JS secret extraction, fuzzing, and CVE lookup, with threaded execution and HTML reporting.
Python 3.10+ · Subfinder · ffuf · Nuclei
github.com/Chetan-Biranje/security-recon-toolkit ↗
Python Security Utilities (pysecutils)
A PyPI-ready Python security package with 17 modules and 40+ automated tests, covering AES-256-GCM encryption and JWT handling for secure application development.
Python · AES-256-GCM · JWT
github.com/Chetan-Biranje/python-security-utilities ↗
Secure CI/CD Pipeline
A least-privilege CI/CD pipeline with SAST, SCA, and secrets-detection gates that block insecure builds before they ship.
GitHub Actions · Bandit · Semgrep · Gitleaks
github.com/Chetan-Biranje/secure-pipeline ↗
04Skills
Application Security
OWASP Top 10OWASP API Top 10 IDORSSRFJWT Attacks Auth BypassCVSS v3.1Threat Modeling
DevSecOps & Cloud
GitHub ActionsSASTDAST SCAAWS (EKS/IAM/S3)Terraform AnsibleDockerKubernetes
Mobile & Tools
Burp SuiteNucleiffuf sqlmapNmapJADX MobSFFrida
Programming
PythonBashJavaScript
05Education & Certifications
Bachelor of Computer Applications (BCA)
D. Y. Patil University · Expected 2028 · Mumbai, MH
Diploma — Electronics & Telecommunication
Sant Gajanan Maharaj Polytechnic · 2020 – 2022 · Kolhapur, MH
Linux FundamentalsTCM Security
SOC Analyst TrainingUSLA
Application Security TrainingDevTown
Open to internships & entry-level AppSec roles

Let's talk security.

Based in Pune, India — open to remote and on-site opportunities.