Web & Application Security
- Burp Suite
- Repeater
- Intruder
- Proxy
- HTTP/S interception
- OWASP Top 10
- SQL Injection
- XSS
- IDOR
- Authentication testing
Available for VAPT / Penetration Testing roles
Junior Penetration Tester Web & Network VAPT
eJPTv2-, CRTA- and MCRTA-certified final-year B.Tech student who turns full-scope engagements into evidence — validated findings, CVSS v3.1 scoring, and remediation roadmaps that hold up under retest.
whoami
Junior penetration tester — web application & network VAPT.
B.Tech Electronics & Computer Science, KIIT Bhubaneswar · 2023–2027.
cat ./certifications
eJPTv2 · CRTA · MCRTA · ICCA · ISC2 CC
I am a final-year B.Tech (Electronics & Computer Science) student at KIIT Bhubaneswar and a junior penetration tester focused on web application and network VAPT. My work is methodology-driven — PTES and OWASP WSTG v4.2 for execution, CVSS v3.1 and CWE for scoring and classification, and structured reporting that a remediation team can actually act on.
Most recently I ran a complete grey-box engagement end to end against four in-scope assets: 19 validated findings including 2 Critical and 7 High, a 97-page report with business impact analysis and a prioritised remediation roadmap, and a full retest cycle verifying what was actually fixed. Of the 18 automated scanner findings, I rejected 39% as non-actionable and found 8 issues no scanner reported — 5 of them High severity.
Alongside that I build small offensive-security tools in Python, mentor 20–25 students in my college's cyber security society, and compete on TryHackMe (Top 2% global) and Hack The Box. I am looking for a VAPT / penetration testing role where I can keep doing hands-on assessment work and writing the reports that go with it.
Certified Red Team Analyst
CyberWarFare Labs
VerifyCertified Multi-Cloud Red Team Analyst
CyberWarFare Labs
VerifyJunior Penetration Tester
INE Security
VerifyINE Certified Cloud Associate
INE
VerifyCertified in Cybersecurity
ISC2
Introduction to Azure Red Teaming — course completion
Altered Security
Verifyfeatured engagement
Grey-box assessment of four in-scope assets: two Windows hosts, two web applications.
scope Isolated lab environment · authorised engagement · findings reproduced under defined rules of engagement.
Python MITM tool · Scapy
ARP-based host discovery · Python, Scapy
srp() — no external scanning tools required.Linux network utility · Python
AIR 12All India Rank · October 2024 Wall of Fame
Penetration testing, web exploitation, privilege escalation and network security rooms. Completed the Jr Penetration Tester, Cyber Security 101 and Complete Beginner paths.
tryhackme.com/p/G00dM4nGr1tCompeted as Team 7h3_UnKnw0n, placing third in the capture-the-flag competition.
Ongoing hands-on machine and challenge practice, plus collaborative vulnerability research and guided lab sessions run for the KIIT cyber security society.
Competed in the following CTF events:
A detailed penetration-testing walkthrough covering enumeration, web exploitation and privilege escalation — demonstrating end-to-end methodology and clear technical reporting.
Full archive of my technical write-ups and methodology notes, published on Medium.
// new write-ups published regularly
IoT Lab (Cyber Security Society), KIIT
The Red Users
KIIT, Bhubaneswar
Relevant coursework Computer Networks · Operating Systems · Network Security · Cybersecurity Fundamentals · Cryptography
C-DAC Kolkata · Ministry of Electronics & Information Technology
A 36-hour security assessment of BOSS OS covering static and dynamic analysis, fuzzing, reverse engineering, proof-of-concept development and CVSS-scored vulnerability reporting under a defined Rules of Engagement.
I am actively looking for penetration testing and security-assessment opportunities — internships or full-time. If you would like the full 97-page VAPT report, a walkthrough of my methodology, or just want to talk security, the fastest way to reach me is email.