Senior Red Team Specialist who breaks into banks, fintechs, and global platforms — legally — to prove what real attackers could do. Five-plus years of VAPT and adversary simulation, and a standing presence on the world's bug bounty programs.
I'm a red team and penetration testing specialist with 5+ years delivering VAPT engagements for banks, NBFIs, PSPs, PSOs, and fintechs across local and international markets.
Currently Associate Manager at EIC Limited, I lead security assessments across web applications, APIs, mobile apps, networks, cloud environments, and external attack surfaces — having completed 40+ projects at EIC to date. I hold OSCP, OSCP+, eWPTX v2, and eCPPT v2.
Alongside client work, I'm an active researcher on HackerOne, Bugcrowd, and Yogosha, finding and validating real-world vulnerabilities in organizations like Google, Apple, Amazon, ING, and Deutsche Bank.
Real-world attack emulation, threat modeling, exploitation, privilege escalation, post-exploitation, and full attack-path analysis.
End-to-end testing of applications and APIs against OWASP and PTES, with validated findings and clear remediation.
Internal and external network assessments, Active Directory testing, and secure architecture review.
iOS and Android assessments using manual and automated methods to surface vulnerabilities before release.
Misconfiguration analysis and hardening across cloud environments and enterprise infrastructure.
Tailored engagements for banks, NBFIs, PSPs, PSOs, and fintech, with stakeholder coordination and remediation verification.
Financial rewards and formal recognition through bug bounty and coordinated vulnerability disclosure programs, for responsibly reporting real security flaws.