At Capgemini, I manage security testing across 250+ enterprise web applications, covering web, API, and network layers. I combine automated testing with manual penetration testing to find issues scanners miss.
I test authentication, authorization, sessions, access control, input validation, APIs, and business workflows against OWASP risks. I triage findings, work with developers on fixes, retest changes, and track closure.
At Capgemini, I validate bug-bounty submissions through Intigriti and strengthened internal testing processes, reducing external vendor testing costs by 30%.
Previously, at Tata Consultancy Services, I performed VAPT and manual security testing for enterprise applications and APIs. I also prepared reports with risk ratings, reproducible proof of concept, business impact, and practical remediation steps; my security work includes finding IDOR, authentication bypass, stored XSS, and business-logic flaws before release.

