Kumar Saksham
Cybersecurity - Red Team | Web, API, AI Models & Thick Client Penetration Testing
- Role
- Senior Analyst - Penetration Tester at EY
- Location
- Bengaluru, KA, IN
- LinkedIn followers
- 500 followers
About Kumar Saksham
Passionate individual committed to the ever-evolving landscape of Cybersecurity, Currently pursuing a Master\'s degree in Cybersecurity to solidify my knowledge and skills in this dynamic field. My journey in cybersecurity has been marked by a genuine curiosity for understanding and mitigating cyber threats, coupled with a relentless pursuit of excellence.
Experience
Senior Analyst - Penetration Tester
Jul 2025 — Present · Bengaluru, IN
Led and executed end-to-end Web Application and API Penetration Testing (WAPT/API-PT) engagements for large-scale manufacturing and transportation clients, including train and rail system manufacturers handling sensitive and proprietary engineering data.• Identified and exploited Broken Access Control vulnerabilities that allowed unauthorized access to proprietary design documents, engineering drawings, and internal project data, highlighting critical business risks.• Discovered complete authentication and authorization bypasses, enabling privilege escalation across user roles and exposure of restricted system functionalities.• Detected CSRF vulnerabilities in critical workflows, allowing unauthorized actions to be performed on behalf of authenticated users.• Identified hard-coded API keys leading to unauthorized access to the LLM Models.• Performed JWT security testing, including token tampering, weak signing algorithms, misconfigured token validation, and JWT cracking scenarios where improper key management was observed.• Assessed and exploited web cache issues, leading to sensitive data being cached and exposed to unauthorized users.• Tested authenticated, role-based, and multi-tenant applications, including admin panels, vendor portals, and internal enterprise systems.• Utilized both manual and automated techniques using tools such as Burp Suite Pro, Nmap, SQLmap, Postman, and custom test cases.• Worked closely with client development, product, and security teams to triage vulnerabilities, explain attack scenarios, and support remediation and re-testing.• Contributed to improving internal testing methodologies, vulnerability templates, and reporting standards for complex client environments.• Performed Thick Client PT, Identified DLL Hijacking vulnerabilities and other local privilege escalation issues by abusing paths, weak permissions, and improper dependency handling, leading to execution of malicious code and compromise of underlying systems.
Education
Doon Business School
BCA, Computer and Information Sciences and Support Services
2019 — 2022
National Forensic Sciences University (NFSU)
Master of Science - MS, Cyber/Computer Forensics and Counterterrorism
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.