I conduct web, API, and mobile security assessments at Indusface, identifying IDOR, SQL injection, authentication, authorization, and business logic flaws through deep manual testing.
I support remediation by demonstrating real-world exploitation techniques and develop custom WAF rules to mitigate application-layer threats. I also collaborate with engineering teams to improve application security across the SDLC.
Previously, I validated vulnerabilities, performed manual penetration testing, analyzed traffic, responded to incidents, and helped secure customer environments through proactive threat detection and bug bounty work.

