Hyderabad, Telangana, India
Security Analyst@Intercontinental Exchange (NYSE: ICE) | Penetration Tester | Security Operations | 21x CVEs Current Role – Security Analyst @ ICE - Perform SAST, DAST, and SCA across enterprise applications - Conduct end-to-end penetration testing (Web, API, Mobile, Thick clients) - Execute security compliance audits aligned with industry standards - Produce detailed, risk-based security reports - Contribute to threat hunting based on: Newly disclosed CVEs, Emerging attacker techniques / APT activity - Creating my AI powered MCP agents to automate & reduce manual security workflows and improving my work efficiency A Human (not alien 👾) wiith a strong focus on offensive and defensive security, driven by curiosity to understand how attacks are executed, and how they are detected, logged, and mitigated in production grade system. My approach to security is practical: If I simulate an attack, i'll also analyze: - What gets logged on the defensive side - How detection systems respond - What controls block or alert the activity - How attackers attempt evasion This dual mindset helps me perform more realistic and effective penetration testing while staying aligned with compliance and authorized testing boundaries. Certifications: 1. CEH (Certified Ethical Hacker – v11) 2. CWES (HTB Certified Web Exploitation Specialist) & More.. Achievements - 20+ CVEs discovered - Found vulnerabilities in 50+ organizations, including: Dell, Motorola, Adidas, HP, Silicon Labs, Hitachi, NCIIPC, etc. - Winner – NCIIPC Pentathon 2024 (AIR 1) - Active Bug Bounty Hunter & CTF Player Projects & Technical Strength - Developed custom subdomain enumeration & attack surface tools (subgen) - Developed Custom GitHub Security Scanner (GhReconX) - Built ML-based Ethereum block reward prediction system (During Academics) - Built an Open-Source SOAR platform (during academics) - Strong in Bash & Python scripting for automation and tooling Actively working on: - AI security automation - Cloud penetration testing - Custom offensive/defensive security agents Beyond my professional work, I’m a continuous learner, constantly exploring: - AI in cybersecurity - Cloud security & attack paths - Automation of security operations Thanks for Reading!
During my internship at Carrier, I contributed to improving the organization’s security posture by developing vulnerability assessment policies and creating detailed security checklists for web and mobile application penetration testing. I was actively involved in conducting 20+ penetration tests across web, mobile, API, and thick client applications, identifying multiple critical security vulnerabilities during the engagements. Additionally, I gained hands-on exposure to the CNA (CVE Numbering Authority) process, where I worked with the CVE assignment workflow, including understanding how CVEs are reviewed and assigned to security researchers as part of the organization’s participation in the CVE program.