Skip to main content
Aawart KCAK
Open to opportunities

Aawart KC

@aawartkc

I uncover and remediate web, API, and application security vulnerabilities.

Nepal
Message

I've responsibly disclosed 400+ validated security vulnerabilities to organizations including NASA, Cisco, Sony, Red Hat, PayPal, Lenovo, WHO, Anthropic, and PortSwigger. I ranked #1 globally on HackerOne's Vulnerability Disclosure Program leaderboard in 2026.

As a Security Researcher on HackerOne and Bugcrowd, I investigate web applications, mobile applications, and APIs for access control, authentication, business logic, injection, privilege escalation, and remote code execution issues. I work directly with security teams and engineers through validation and remediation.

At Yeti Cyber Operations, I led web application and API assessments, combining manual offensive techniques with AI-assisted analysis to improve discovery and validation. I prepare penetration-testing reports with proof-of-concept demonstrations, risk assessments, and remediation recommendations.

I've also delivered freelance penetration testing across source code, cloud configurations, and third-party integrations, including remediation retesting. Outside client work, I compete in CTFs and penetration-testing challenges, earning wins at NCHL Penetration Testing Competition 2025 and HackQuest 2026.

Experience

Work history, roles, and key accomplishments

Education

Degrees, certifications, and relevant coursework

SC

Samriddhi College

Bachelor of Science in Computer Science and Information Technology, Computer Science and Information Technology

2024 -

Pursuing a Bachelor of Science in Computer Science and Information Technology (BSc CSIT) at Samriddhi College, ongoing since 2024.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan