Bug Bounty & Security Research at HackerOne & Personal Projects (2024-01 – Present)
Self-driven security research and bug bounty hunting
- Identified and reported multiple high-impact vulnerabilities including Subdomain Takeover, DOM-Based XSS, and sensitive data exposure.
- Conducted responsible disclosure and coordinated with organizations to remediate security issues.
- Performed penetration testing on web applications and APIs, strengthening security posture for target organizations.
- Enhanced knowledge of OWASP Top 10 threats, cloud security, and real-world attack scenarios.
Cybersecurity Specialist Intern at Infosec4TC (2022-07 – 2023-01)
- Configured and optimized Kaspersky Endpoint Security across multiple systems to ensure real-time protection and compliance.
- Secured Windows Server environments by enforcing strong password policies, audit settings, and access control through Group Policy Objects (GPOs).
- Managed user accounts, roles, and permissions in Active Directory, improving access control and reducing unauthorized access risks.
- Conducted regular vulnerability assessments using Nessus, identifying and remediating critical vulnerabilities across IT assets.
- Utilized Splunk for proactive log monitoring, detecting and reporting suspicious activity for incident response teams.
- Deployed and maintained ManageEngine Data Loss Prevention (DLP) to monitor and block unauthorized data transfers, ensuring regulatory compliance.