Senior Consultant Ultraviolet Cyber
I lead end-to-end VAPT engagements for more than 25 complex enterprise web, API, and mobile applications using black-box, gray-box, and white-box methodologies. I perform root-cause analysis, remediation retesting, and business-risk communication using CVSS 3.1 and NIST SP 800-30.
I reproduce vulnerabilities related to open-source components and third-party dependencies in isolated local environments to assess supply-chain risk. I also conduct network security testing with Nmap, Metasploit, and Nessus, and support Shift-Left DevSecOps through SAST/SCA security-gating frameworks using Black Duck.
My testing has included critical and high-severity issues such as account takeover, BOLA, JWT manipulation, XSS, SSRF, and token abuse. I am also developing expertise in AI/LLM security, including prompt injection testing and guardrail validation.