Cybersecurity Engineer at Priceline.com Technology India LLP (Booking Holdings) (2021-02 – Present)
- Performed VAPT on 50+ web and mobile applications, identifying and triaging vulnerabilities against defined SLAs (72 hours for exploitable critical, 15 days for critical, 30 days for high) and coordinating remediation with engineering teams.
- Owned Priceline's external attack surface program end-to-end — managed Recorded Future ASI across 3,500+ live assets, triaging 95 unique exposures down to actionable findings by filtering noise (non-owned assets, false positives) and coordinating remediation across 10+ teams.
- Served as sole point of contact for HackerOne bug bounty, processing 200+ researcher submissions/year, filtering 80%+ noise (duplicates and informational) to surface actionable vulnerabilities for engineering teams. Leveraged HackerOne Hai for AI-assisted initial triage, cross-validating assessments before escalation — approach praised by HackerOne team during inter-brand meetings.
- Built and deployed an AI-powered triage automation (Python/FastAPI) integrating Wiz and Recorded Future ASI findings with Claude and Gemini APIs — auto-classifies exposures, generates reproduction steps and remediation guidance, and delivers interactive Slack notifications for engineer validation and one-click Jira ticket creation. Reduced manual triage time from ~2 hours to under 40 minutes per finding.
- Conducted bi-annual network segmentation and cloud VPC validation, verifying isolation between PCI and non-PCI zones and ensuring all open ports have documented business justification.
- Performed credential security audits using Hashcat, cracking 10-20% of sampled password hashes per exercise (100-200 out of 1,000+), directly driving enforcement of stricter password complexity policies and enhanced MFA controls (e.g., consecutive character restrictions).
- Identified 100+ exposed secrets across Git repositories and public Slack channels using TruffleHog, Gitleaks, and Slack Watchman, driving immediate credential rotation and repo remediation. Detected 7 blind XSS vulnerabilities in production applications using ezXSS.
- Ran quarterly phishing simulations across 700+ employees via KnowBe4, creating 25+ custom templates. Reduced clickthrough rate from 27.2% to 15.3% over successive campaigns while increasing employee reporting of suspicious emails.
- Managed and configured DAST scanning using Burp Suite DAST, Detectify, and InsightAppSec — running weekly scans across 10 applications, identifying 2 critical and 3 high-severity vulnerabilities and driving remediation with engineering teams.
- Investigated IOCs and performed threat hunting using CrowdStrike and Splunk, writing custom SPL queries and mapping findings to MITRE ATT&CK techniques.
- Monitored for compromised credentials using Recorded Future Identity module — identified 6 exposed employee accounts (root cause analysis, forced resets, endpoint remediation) and 100+ compromised user accounts (forced password resets).
Information Security Analyst at Invesics Cyber Forensics, LLP (2020-01 – 2021-02)
- Delivered VAPT engagements for 5 clients across web, mobile, and infrastructure environments, producing detailed technical reports with remediation recommendations.
- Provided hardening guidance across encryption, access control, and secure configurations based on assessment findings.
- Mentored 6 interns in web and network security testing methodologies.
DevOps Engineer at nuFuture Digital India Ltd (2018-07 – 2020-01)
- Automated CI/CD pipelines using Jenkins and Docker to improve deployment efficiency and reduce release errors.
- Evaluated and deployed Zabbix for infrastructure monitoring and alerting across production environments.
- Integrated Keycloak (open-source IAM) and API management systems into production environments.