// 07. content creation
> Hello, World!
Security Consultant @ Deloitte USI · Penetration Tester · Bug Bounty Hunter · Synack Red Teamer · YouTuber (26K) · Instagram (52K) · Speaker
// 02. about
I'm a passionate Cyber Security professional with 5+ years of professional experience as a Security Consultant at Deloitte USI. I specialise in Web Application, API, Mobile (Android & iOS), Network, and Thick Client penetration testing — delivering end-to-end security assessments for global enterprise clients.
I conduct Architectural Reviews and Secure Code Reviews, and produce clear, risk-rated vulnerability reports (CVSS/OWASP) for executive and technical audiences. My toolkit includes Burp Suite, Metasploit, Nmap, Nessus, Fortify, WebInspect, HCL AppScan, Frida, MobSF, and Kali Linux.
As an active Bug Bounty Hunter, I'm a member of the elite Synack Red Team, ranked Top 250 on Bugcrowd, Top 50 on Yogosha, and Top 100 on YesWeHack. I've responsibly disclosed vulnerabilities across 100+ organisations and earned Hall of Fame recognitions from Microsoft, Apple, Google, Nokia, Intel, Pinterest, and more.
Download Resume// 02b. skills
// 03. experience
Lead end-to-end penetration testing engagements across Web Applications, APIs, Mobile (Android/iOS), Network, and Thick Client environments for global enterprise clients. Conduct Architectural & Secure Code Reviews. Deliver risk-rated reports (CVSS/OWASP) for executive and technical audiences; drive remediation verification and client engagement throughout the lifecycle.
Performed manual & automated penetration tests on Web Applications and APIs; identified injection flaws, authentication bypasses, and business logic vulnerabilities. Conducted Secure Code Reviews; collaborated closely with client teams on risk prioritisation and remediation.
Web Application & API Penetration Testing with structured vulnerability reporting and PoC documentation.
Selected member of Synack's elite private programme — conducting high-impact security assessments across curated enterprise targets worldwide.
Top 250 Bugcrowd
Top 50 Yogosha
Top 100 YesWeHack
Responsibly disclosed critical vulnerabilities (Account Takeover, IDOR, Privilege
Escalation, XSS, LFI) across 100+ organisations globally. Hall of Fame recognitions from
Microsoft, Apple, Google, Nokia, Intel, Pinterest, Dell Technologies, and more.
Cyber security summer internship under Mr. Rakshit Tandon — Cyber Security Expert & Consultant, Internet and Mobile Association of India.
Web Application Penetration Testing under guidance of Mr. Vikas Choudhary.
// 04. hall of fame
Recognised by the following organisations for responsibly disclosing security vulnerabilities:
// 05. certifications
// 06. talks & sessions
Delivered a talk on Penetration Testing and Bug Bounty Hunting to students and faculty.
Delivered a talk on Penetration Testing and Bug Bounty at the Hackers Meetup organised by Comexpo Cyber Security.
Online talk on getting started in Bug Bounty Hunting for the security community.
Watch TalkOnline session on Bug Bounty Hunting fundamentals for aspiring security researchers.
Watch Talk// 07. content creation
// 08. education
// 09. blogs
Read all writeups on Medium ↗






// 10. contact