Vandan Pathak
Lead Offensive Security Engineer - Red Team @Kyndryl
Signup · Get unlimited contacts
WORK HISTORY
Lead Offensive Security Engineer - Red Team @Kyndryl
Toronto, ON, CA
EDUCATION
Shree P.M Patel College Of Computer Application & Technology
Bachelor's Of Computer Application, Programming & Security
Fleming College
Computer Security And Investigation, Security and research
SKILLS
ABOUT VANDAN PATHAK
Experienced and adroit application and network security consultant with an abundant knowledge of diverse security technologies such as Web and API application security testing, network penetration testing, mobile (iOS and Android) and Cloud (AWS) security assessments along with firewalls, SIEM, Intrusion detection & prevention systems of an IT infrastructure. Some of the technical ingenuities are- Operate a hands-on role involving penetration testing and vulnerability assessment activities of complex web and mobile applications. Actively involved in various Capture the flag activities and experienced with tools such as metasploit, Frida, objection, Nessus, Hydra, Sqlmap, Frida, MobSF, OWASP and versatile exploit researcher of various zero days vulnerabilities- Proficient experience at performing independent security testing for web applications, mobile (Android & iOS) applications, API and Cloud (AWS) infrastructure assessments along with network security penetration testing- Reverse engineered android or iOS mobile applications to perform in-depth lookup at the source code to identify the vulnerabilities and ability to use Frida Framework to hook the process. Abilities to identify weak application authentication & authorization components, evaluating local storage or writing a custom Frida scripts as per the given scenario- Using Burp Suite or Fiddler, understand the web application and API requests, responses and identify the faulty header injection points. In addition to that, extensively performed static code analysis for the complex codebase applications to understand inadequate functions implemented within the code- Discovery and Reconnaissance for vulnerable on-prim or cloud targets through live and virtual host identifications, Open-source intelligence, mapping the targets to identify potential entry points in the networks. Investigate each ports/services to trigger a vulnerabilities and identify ways of privilege escalation within the network systems
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.