Jay Shalwala
@jayshalwala
Junior penetration tester and red team researcher applying web, Active Directory, and CVE/CTF-focused security testing.
What I'm looking for
I’m a Junior Penetration Tester and Red Team Security Researcher with hands-on experience in web application security testing, Active Directory attack simulation, network analysis, and vulnerability assessment. I’m currently completing the TCM Security PNPT certification with a focus on Active Directory penetration testing and red team operations.
Through Hack The Box lab practice and my own home Active Directory lab, I’ve performed systematic enumeration, exploitation chaining, and privilege escalation to achieve full system compromise. I document findings with MITRE ATT&CK mapping and CVSS-scored vulnerability reporting, and I’ve simulated AD techniques like NTLM hash capture, NetNTLMv2 relay attacks, Kerberoasting, AS-REP Roasting, DCSync, and Golden Ticket forging.
I also run independent bug bounty and OSINT research, including discovering client-side exposed secrets in a production JavaScript bundle and mapping the issue to OWASP categories with practical remediation guidance. My goal is to join a professional team where I can apply offensive security skills to junior penetration testing or VAPT work and grow through real-world engagements.
Experience
Work history, roles, and key accomplishments
OSINT and Reconnaissance Researcher
Independent Research
Jan 2026 - Present (6 months)
Conducted OSINT research using Google Dorking and passive reconnaissance to identify exposed sensitive data from misconfigured web applications and insecure indexing. Built references for search operators mapped to OWASP vulnerability categories and performed attack surface mapping for web security engagements.
Bug Bounty Researcher
Independent Security Research
Mar 2025 - Present (1 year 4 months)
Performed independent bug bounty research focused on identifying information disclosure and access control issues. Discovered a valid production JavaScript bundle credential exposure and mapped it to OWASP Top 10 categories with remediation guidance.
Completed Hack The Box lab machines across Linux, Windows, web app, database, and cloud environments using systematic enumeration, exploitation chaining, and privilege escalation. Conducted network/service enumeration and Active Directory penetration testing simulations mapped to MITRE ATT&CK and documented with CVSS-scored findings and remediation guidance.
Education
Degrees, certifications, and relevant coursework
University of Mumbai
Bachelor of Science in Information Technology, Information Technology
2017 - 2020
Bachelor of Science in Information Technology from the University of Mumbai (June 2017 to May 2020).
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Portfolio
github.com/jayshalwalaJob categories
Skills
Interested in hiring Jay?
You can contact Jay and 90k+ other talented remote workers on Himalayas.
Message JayGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
