You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Sunil KandeSK

Tiempo medio de respuesta: 1h

Acerca de Sunil

I’m a Pentester with over 6+ years of hands-on experience in application and infrastructure security. I’ve worked on a wide range of assessments including web apps, APIs, mobile applications (Android and iOS), thick clients, and network environments. I specialize in manually identifying critical issues like IDOR, RCE, SQL injection, authentication bypasses, and business logic flaws.

Alongside my full-time role as a Security Engineer at Funding Societies, I actively work as a freelance pentester on platforms like Cobalt, Synack (Level 4), and HackerOne,

I’m certified in:

eWPTXv2 – Web Application Penetration Tester eXtreme (eLearnSecurity)
eMAPT – Mobile Application Penetration Tester (eLearnSecurity)
CEH – Certified Ethical Hacker (EC-Council)
  • Inglés

    Bilingüe o nativo

Solo teletrabajo
Lleva a cabo sus proyectos principalmente en remoto

Experiencia

  • Security Innovation India Pvt Ltd,
    Security Engineer
    febrero de 2021 - septiembre de 2021 (7 meses)
    Pune, Maharashtra, India
    ➼ Worked as a Security Engineer; my responsibilities have expanded to include client engagement, project estimation, advanced VAPT, research, report preparation and review, managing security projects, mentoring team members, etc.

    Responsibilities:

    ➼ Working on reviewing application code against the secure coding baseline and practices.
    ➼ Provide required reports to management and client Handle the project as well as BAU operations
    ➼ Perform Web applications, Thick-client Applications, Mobile Applications, API and Network
    ➼ Penetration Testing with Automated Tools and Manually.
    ➼ Have Hands-on Experience in OWASP top 10 and Complete threat Modal.
    ➼ Analyze data, such as logs or packet captures, from various sources within the enterprise and conclude past and future security incidents
    ➼ Application Security - Threat modeling, Source Code Review and Delivering Report.
    ➼ Performed the static and dynamic analysis testing of Android and iOS application.
    ➼ Proficient in identifying various core Mobile vulnerabilities like Deep linking exploit, Local file stealing using LFI, Local SQL Injection, Abusing WebView XSS, Bypassing application workflow
    ➼ Developing security tools to automate (Using python and bash) the penetration testing process
    ➼ Mentoring junior colleagues in information security
    ➼ Network vulnerability assessment & manual penetration testing tools Nessus, Nmap, Nexpose, Metasploit and Armitage.
    ➼ Web Application Penetration Testing.
    ➼ Configuration Audit of Network Devices & Operating System
    ➼ Worked on cloud environments such as AWS, GCP, Azure and Ali Cloud;
    ➼ Worked on security risk management, security governance framework and compliance (IT Security Audit/log review), Vulnerability Assessment, Penetration Testing (Manually)
  • Synack Red Teamer
    Bug Bounty Hunter
    junio de 2020 - Hoy (6 años y 2 meses)
    ➼ Working as part-time bug bounty hunter. (Lx4)
    ➼Working as pentester and bugbounty hunter submitted more than 200 valid security issues
  • ArisGlobal Pvt Ltd
    Security Consultant
    octubre de 2021 - agosto de 2022 (10 meses)
    Worked as a Security Engineer; my responsibilities have expanded to include client engagement, project estimation, advanced VAPT, research, report preparation and review, managing security projects, mentoring team members, etc.

Recomendaciones

Sé el primero en recomendar a Sunil

Ayuda a este freelance a destacar compartiendo tu experiencia.

Estos perfiles de freelance también coinciden con tus criterios

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Formación

  • CEH (Certified Ethical Hacker)
    EC-Council.
    CEH (Certified Ethical Hacker)
  • eWPTXv2 (Web Applica1on Penetra1on Tester
    eXtreme)
    eWPTXv2 (Web Applica1on Penetra1on Tester

Certificados

Conjunto de habilidades profesionales

Categorías