At Deloitte, I lead end-to-end application security and VAPT engagements for banking and BFSI clients, testing business-critical applications through remediation validation.
I conduct black-box, grey-box, and thick-client penetration tests across web applications and APIs. My assessments identify issues such as IDOR, privilege escalation, OTP bypass, and business logic flaws.
I review code using Fortify SCA and Checkmarx, validate true positives, and eliminate false positives. I also retest after remediation to verify that critical and high-risk vulnerabilities have been resolved.
I produce client-ready reports with proof-of-concept evidence, impact-based severity ratings, and practical remediation guidance. I'm expanding my focus into AI security and the assessment of AI-enabled systems.

