At LETS NOTIFY, I conducted VAPT on web applications and APIs using OWASP Top 10 as a guide. I combined automated SAST/DAST scanning with manual testing to find security flaws.
I assessed access controls for IDOR and privilege-boundary issues, and demonstrated attacks including Web Cache Deception and Password Reset Poisoning. I also tested for race conditions that could bypass business logic limits.
At 6D TECHNOLOGIES, I tested web, API, and Android application security, including JWT handling, SSL pinning, and authentication controls. I also performed functional and regression testing, developed test cases, and supported deployment and post-deployment issue analysis.

