Security Analyst
CurrentSummaryHighly motivated penetration tester with expertise in web application security, mobile application assessment (Android), network security testing and hands-on experience in GraphQL testing. Skilled in utilizing various automated and manual tools to identify and exploit vulnerabilities across diverse attack surfaces, including web applications, APIs, external and internal networks. Possesses strong analytical skills and excels at reverse engineering, source code review, and business logic bypass techniques.Key AchievementsConducted comprehensive penetration testing engagements on web applications, Android applications, external networks, and internal networks.Successfully identified and exploited vulnerabilities leading to Remote Code Execution (RCE) and reverse shell capabilities.Utilized reverse engineering and source code review to uncover critical application flaws.Adept at API testing for security weaknesses.Demonstrated proficiency in bypassing common security controls like root detection, SSL pinning, and WAFs (Web Application Firewalls).Effectively communicated complex findings during client meetings and walkthroughs, fostering strong team collaboration.Conducted both black-box and grey-box testing engagements.Technical SkillsWeb Application Security: Burp Suite, Zap, MetasploitMobile Application Security: Static and Dynamic Analysis tools (mention specific tools if applicable)Network Security: Nmap, Gobuster, Nikto, Automated ScriptingAPI Testing: Burp Suite (Intruder module), Postman (with security extensions)Other Tools: WAF00f, CMS Exploiter, GraphQL testing tools (graphw00f,GraphiQL, Insomnia with GraphQL extension, InQL)