AVAILABLE FOR ENGAGEMENTS
Red Team Operator / Offensive Security

Abhijeet Kumar
Sarkar

Senior Red Team Specialist who breaks into banks, fintechs, and global platforms — legally — to prove what real attackers could do. Five-plus years of VAPT and adversary simulation, and a standing presence on the world's bug bounty programs.

// whoamioperator

The person behind the engagements.

operator@redteam: ~
$ whoami
abhijeet_kumar_sarkar
role : Associate Manager, SecOps
org  : EIC Limited
loc  : Dhaka, BD
exp  : 5+ years
focus : VAPT · Red Team · BugBounty
$ _
Abhijeet Kumar Sarkar
operator // dhaka, bd
// About Mebackground

A specialist who breaks financial systems before the wrong people do.

I'm a red team and penetration testing specialist with 5+ years delivering VAPT engagements for banks, NBFIs, PSPs, PSOs, and fintechs across local and international markets.

Currently Associate Manager at EIC Limited, I lead security assessments across web applications, APIs, mobile apps, networks, cloud environments, and external attack surfaces — having completed 40+ projects at EIC to date. I hold OSCP, OSCP+, eWPTX v2, and eCPPT v2.

Alongside client work, I'm an active researcher on HackerOne, Bugcrowd, and Yogosha, finding and validating real-world vulnerabilities in organizations like Google, Apple, Amazon, ING, and Deutsche Bank.

// My Skillscapabilities

Offensive testing across every layer of your attack surface.

Offensive Security Testing

Web Application TestingExpert
API Security TestingExpert
Red Team / Adversary SimulationExpert
Network / InfrastructureAdvanced
Mobile Application TestingAdvanced
Cloud SecurityAdvanced

Tooling & Methodologies

Burp SuiteMetasploitNmapSQLMapNiktoFFUFGobusterWireshark OWASP Top 10PTESOSSTMMCVSSv3CVSSv4

Areas of Expertise

Threat ModelingPrivilege EscalationLateral MovementPost-ExploitationPoC DevelopmentCVE ResearchActive DirectoryBusiness Logic FlawsAuth BypassResponsible DisclosureMisconfiguration AnalysisSecure Architecture Review
// Servicesengagements

Manual-first testing that proves real, exploitable risk.

[ red team ]

Red Team & Adversary Simulation

Real-world attack emulation, threat modeling, exploitation, privilege escalation, post-exploitation, and full attack-path analysis.

[ web · api ]

Web & API Penetration Testing

End-to-end testing of applications and APIs against OWASP and PTES, with validated findings and clear remediation.

[ network ]

Network & Infrastructure

Internal and external network assessments, Active Directory testing, and secure architecture review.

[ mobile ]

Mobile App Penetration Testing

iOS and Android assessments using manual and automated methods to surface vulnerabilities before release.

[ cloud ]

Cloud Security Review

Misconfiguration analysis and hardening across cloud environments and enterprise infrastructure.

[ finance ]

Financial Sector Assessments

Tailored engagements for banks, NBFIs, PSPs, PSOs, and fintech, with stakeholder coordination and remediation verification.

0+
Years Experience
0+
Engagements Delivered
0+
Global Orgs Acknowledged
0
Pro Certifications
// Acknowledgementsscope --resolved

Recognized by organizations across six sectors worldwide.

Financial rewards and formal recognition through bug bounty and coordinated vulnerability disclosure programs, for responsibly reporting real security flaws.

TechnologyFinancial ServicesE-commerceAutomotiveMediaEducation
// Experiencehistory -a

Where I've been operating.

Associate Manager, Security Operations · EIC Limited
Apr 2024 - Present
Dhaka, Bangladesh
  • Lead end-to-end VAPT across web apps, APIs, mobile apps, internal and external networks, cloud, and enterprise infrastructure.
  • Run advanced red team exercises: adversary simulation, threat modeling, exploitation, privilege escalation, and attack path analysis.
  • Assess financial-sector clients including banks, NBFIs, PSPs, PSOs, and fintech organizations.
  • Document findings with clear impact analysis and remediation aligned to OWASP and PTES.
  • Mentor junior analysts, review findings for quality, and improve internal methodology.
Security Researcher · HackerOne · Bugcrowd · Zerocopter · Yogosha
Jan 2016 - Present
Remote
  • Research and test web apps, APIs, and mobile apps through global bug bounty platforms and private programs.
  • Identify and responsibly disclose high and critical findings: business logic flaws, auth bypasses, and OWASP Top 10 issues.
  • Build detailed proof-of-concept exploits with comprehensive technical reports and remediation guidance.
  • Earn consistent recognition for high-quality submissions across diverse industries worldwide.
// Certificationsverified

Credentials, verifiable.

OSCP+OffSec Certified Professional+ID 168401423
OSCPOffSec Certified ProfessionalID 168401353
eWPTX v2Web Application Penetration Tester eXtremeID 94645663
eCPPT v2Certified Professional Penetration TesterID 105112297
CAPCertified AppSec Practitioner · The SecOps GroupID 7029942
// Contactopen a channel

You need to know something? Drop a line.