At Infosys, I assess web application security using manual and automated testing with Burp Suite Pro and Checkmarx. I perform SAST, DAST, penetration testing, and secure code reviews.
I review vulnerabilities, triage false positives, and recommend remediation. I also prepare assessment reports and work with development teams to explain findings and their potential impact.
On the SAST & DAST for Client (LAM, TMHE) project, I tested applications against OWASP checklist categories and found vulnerabilities including authentication bypass, privilege escalation, and XSS. I participated in client calls to assist with mitigation and handled reporting and remediation.

