Skip to main content
HimalayasHimalayas logo
smit asherSA
Open to opportunities

smit asher

@smitasher

I’m an offensive security practitioner focused on end-to-end VAPT for web apps, APIs, and networks—finds issues and drives remediation.

India
Message

What I'm looking for

I’m looking for an offensive security role where I can run end-to-end VAPT on web apps, REST APIs, and networks, produce risk-rated reporting (CVSS), and work on remediation guidance with mentorship and real client walkthroughs.

I’m an Offensive Security Practitioner currently working as a Red Team Intern → Team Lead Intern with DeepCytes Cyber Labs (UK, Remote). I focus on vulnerability assessment and penetration testing (VAPT) across web applications, REST APIs, and network services using structured methodologies aligned with industry standards.

In my engagements, I run reconnaissance and attack surface mapping with tools like Nmap, WhatWeb, and WapW00f to identify exposed services and entry points before active testing. I then validate issues such as IDOR, XSS, SQL Injection, Broken Access Control, and security misconfigurations, correlating findings against OWASP Top 10.

I also carry out controlled exploitation using Metasploit, sqlmap, commix, and custom Python scripts to demonstrate exploitability and real-world business impact. Beyond web testing, I assess REST API endpoints and cloud-hosted platforms for IAM misconfigurations, over-permissive access policies, excessive data exposure, and missing authentication controls.

I’m careful about evidence quality and impact: I write vulnerability reports with CVSS v3.1 risk ratings, impact explanations, and remediation guidance. I use MitmProxy and Wireshark for traffic interception, deep packet inspection, and protocol-level analysis, and I support triage with VirusTotal IoC severity plus credential testing using Hydra and John the Ripper—while leading peer reviews and client walkthroughs as Team Lead Intern.

Experience

Work history, roles, and key accomplishments

DL
Current

Red Team Intern (Team Lead)

DeepCytes Cyber Labs

Jun 2024 - Present (2 years)

Performed VAPT on web applications, REST APIs, and network services, conducting reconnaissance and attack-surface mapping before controlled exploitation. Identified and validated IDOR, XSS, SQL injection, broken access control, and security misconfigurations, and authored CVSS v3.1 risk-rated reports with remediation guidance while coordinating peer reviews and client walkthroughs as Team Lead Int

Education

Degrees, certifications, and relevant coursework

DE

D.J. Sanghvi College of Engineering

Bachelor of Technology, Electronics & Telecommunication Engineering

2022 - 2026

Activities and societies: Relevant coursework: Network Security, Internet Engineering, Operating Systems, Data Compression & Encryption, Computer Networks, Digital Electronics.

B.Tech in Electronics & Telecommunication Engineering with coursework spanning network security, operating systems, computer networks, and digital electronics.

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan