Pandurang Chidrawar
Immediate joiner || Penetration testing || VAPT || CDAC Certified || Actively looking
- Role
- Security Analyst Consultant at Intel
- Location
- Mumbai, MH, IN
- LinkedIn followers
- 500 followers
About Pandurang Chidrawar
Experienced in VAPT, Understanding application-level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, weak cryptography, authentication flaws, etc. Experience in different network and web application security testing tools like Acunetix, Metasploit, Burp Suite, Sqlmap, OWASP ZAP Proxy, Nessus, Nmap, etc. Capable of identifying flaws like Injection, XSS, Insecure direct object reference, Security Misconfiguration, Sensitive data exposure, Functional level access control, CSRF, and Invalidated redirects. Performed vulnerability assessment and penetration testing on various client infrastructuresI have completed the C-DAC certification in PG-DITISS (Diploma in IT Infrastructure System and Security). I have good knowledge of network security and monitoring tools Wireshark. vulnerability assessment tools Nmap, and BurpSuit. Hands-on Ethical Hacking tools vulnerability assessment. Also strong knowledge of Windows Server 2016 and Linux Administration. Configuration of firewall, DHCP server, Network Defence countermeasures, and basic knowledge of VMWare, Windows Server, Active Directory, PKI, VPN, Proxy Sewer, WDS, DNS, IDS and IPS, and Shell scripting.
Experience
Security Analyst Consultant
Aug 2022 — Present · Hyderabad, IN
Conducted thorough penetration tests on Web Applications, APIs, and Cloud environments to identify security vulnerabilities and weaknesses.Utilized a range of tools and techniques, including- API Testing: Postman for comprehensive API testing, including endpoint discovery, parameter manipulation, and authentication bypass testing- Web Application Testing: Utilized Burp Suite for dynamic application security testing (DAST), identifying and exploiting common web application vulnerabilities such as SQL injection, XSS, CSRF, and authentication flaws- Network Analysis: Leveraged Nmap and Wireshark for network scanning and packet analysis to identify open ports, services, and potential network security risks- Cloud Security: Conducted container security assessments using Trivy for Docker image scanning and vulnerability management. Assessed Kubernetes clusters using Kubebench and KubeHunter to identify security risks and best practices violations- Windows Binary Analysis: Utilized PEsecurity, Sysinternals Suite, WinCheckSec, and PEStudio for security assessments of Windows binaries, identifying security weaknesses and potential malware indicators.
Education
DPCOE
BE - Electronics and Telecommunications Engineering ( E & TC )
Institute for Advanced Computing and Software Development (IACSD)
CDAC - PG Diploma in IT Infrastructure, Systems and Security (PG-DITISS)
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.