
Subhadeep Karmakar
@subhadeepkarmakar
I uncover web and infrastructure vulnerabilities through penetration testing, bug bounty research, and SOC investigation workflows.
What I'm looking for
I've conducted vulnerability research across HackerOne, Intigriti, and Bugcrowd, testing web, mobile, API, and cloud environments for vulnerabilities including XSS, IDOR, SQLi, SSRF, CSRF, and privilege escalation.
My work combines structured reconnaissance, asset enumeration, exploitation, and CVSS-scored reporting with proof-of-concept evidence, business-impact analysis, and remediation guidance. I build Bash and Python scripts to automate reconnaissance, asset discovery, and fuzzing workflows.
During internships with Deltaware Solutions and Redynox, I performed vulnerability scanning, basic exploitation, SOC log monitoring, alert triage, network-traffic analysis, web security testing, and system-hardening support.
As a freelance security researcher, I've investigated 50+ simulated security alerts and assessed 10+ hosts and web applications. I'm a CEH v12-certified practitioner continuing to strengthen my penetration testing and SOC capabilities through hands-on research, CTFs, and security communities.
Experience
Work history, roles, and key accomplishments
Conducts manual and automated penetration testing across web applications, APIs, cloud platforms, and mobile environments. Submits detailed, CVSS-scored vulnerability reports with proof-of-concept and remediation guidance.
Performs manual and automated security testing on web, mobile, and API-based applications, identifying OWASP Top 10 vulnerabilities and business logic flaws. Participates in Live Hacking Events and CTFs.
Conducts security assessments and penetration testing on web, mobile, and API applications in line with OWASP Top 10 and industry standards. Collaborates with security triage teams to ensure accurate vulnerability prioritization.
Freelance Security Researcher
Self Employed
Investigated 50+ security alerts and events across lab and simulation environments, including phishing, malware, brute-force, and suspicious authentication scenarios. Conducted vulnerability assessments on 10+ hosts and web applications using Nessus and OpenVAS.
Penetration Testing Intern
Deltaware Solutions
Jun 2025 - Aug 2025 (2 months)
Performed vulnerability scans and basic exploitation using Burp Suite, Nmap, and Metasploit across assigned target environments. Prepared technical reports with detailed findings and remediation steps.
Cybersecurity Intern
Redynox
Jun 2025 - Jul 2025 (1 month)
Assisted in SOC operations including log monitoring, alert triage, and basic threat detection. Analyzed network traffic using Wireshark and performed web vulnerability scanning using OWASP ZAP.
Education
Degrees, certifications, and relevant coursework
Indian School of Ethical Hacking (ISOEH)
Advanced Diploma, Cybersecurity
2024 -
Ongoing Advanced Diploma in Cybersecurity, expected to complete in December 2026.
Lovely Professional University
B.Tech, Computer Science (Cybersecurity)
2018 - 2022
Grade: 6.69 CGPA
Pursued a Bachelor of Technology in Computer Science with a focus on Cybersecurity, achieving a CGPA of 6.69.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Salary expectations
Job categories
Skills
Interested in hiring Subhadeep?
You can contact Subhadeep and 90k+ other talented remote workers on Himalayas.
Message SubhadeepGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
