000
About Experience Capabilities Approach Credentials Contact

Cyber Security Consultant · Bengaluru, India

Breaking systems to protect them.

4 years · VAPT · Web · Mobile · API

Penetration Testing Burp Suite OWASP Mobile Security
Scroll

01 — About

Srirammanan S

Cyber Security Consultant
@ Synopsys Software Integrity

Bengaluru, Karnataka, India

Consultant with 4 years in cybersecurity — specializing in penetration testing, vulnerability assessment, and security strategy. Skilled in VAPT, manual and automated testing, and tools such as Burp Suite, Nmap, and OWASP frameworks. Experienced in identifying and mitigating vulnerabilities across web, mobile, and API ecosystems.

0Years Active
0Critical Vulnerabilities
Identified & Patched
0Risk Exposure
Reduced
0Industry
Certifications

02 — Experience

Where I've worked

May 2024 — Present

Synopsys
Software Integrity

Cyber Security Consultant

Leading security assessments across web applications, APIs, and mobile platforms for enterprise clients. Delivering end-to-end VAPT engagements with detailed remediation guidance and risk-prioritized findings.

Web AppAPIMobile Burp SuiteOWASPVAPT

Dec 2021 — May 2024

Paladion
(an Eviden business)

Digital Security Testing

Performed Web, Mobile, and VAPT engagements — identified 15+ critical vulnerabilities including SQLi and IDOR, reducing client risk exposure by 40%. Executed both manual and automated testing across internal, web, and mobile attack surfaces.

SQLiIDORNmap NiktoAndroidiOS Internal Networks

03 — Capabilities

A full-spectrum offensive toolkit.

01

Web App Security

Comprehensive web VAPT covering OWASP Top 10 — injection, auth flaws, misconfigurations, and business logic vulnerabilities.

Burp SuiteSQLMapNiktoOWASP

02

Mobile Security

Android & iOS assessments — static/dynamic analysis, insecure data storage, SSL pinning bypass, and runtime manipulation.

FridaMobSFADBObjection

03

API Security

REST and GraphQL API testing — broken object-level auth, excessive data exposure, rate limiting, and mass assignment flaws.

PostmanBurpOWASP API Top 10

04

Network & AD

Internal network pentesting, Active Directory enumeration, privilege escalation, and lateral movement in enterprise environments.

NmapActive DirectoryBloodHound

05

Cloud & Red Team

Multi-cloud attack surface analysis across AWS, Azure, and GCP. Threat modeling and red team exercise planning.

AWSAzureGCPMulti-Cloud

06

AI Security

Testing LLMs and ML pipelines for prompt injection, model inversion, adversarial inputs, and data poisoning risks.

LLM SecurityPrompt InjectionOWASP LLM Top 10

07

Threat Modeling

Structured identification of attack surfaces using STRIDE and DREAD frameworks — before a line of code ships.

STRIDEDREADAttack TreesMITRE ATT&CK

08

Product Security

Embedding security into the SDL — requirements, risk assessment, and cross-team security ownership across the product lifecycle.

SDLRisk AssessmentCVSS v4.0

09

Architecture Review

Deep-dive security assessment of system designs — trust boundaries, data flows, auth models, and infrastructure exposure.

Trust BoundariesData Flow DiagramsZero Trust

10

Design Review

Early-stage security engagement on feature designs — catching insecure patterns before implementation locks them in.

Secure SDLCSecure by DesignDesign Patterns

The Approach

Attack surface,
mapped in every dimension.

Every system is a structure of trust boundaries and data flows. I rotate it, probe each face, and find the edge where assumptions break — then prove it, and hand back a path to fix it.

Impact in Practice

Security that
shows results.

01Dashboard overview
02Key metric identified
03Results delivered
Security Assessment — Q2 2024
15+Critical
Vulnerabilities
40%Risk Reduction
3Systems Tested
SQL InjectionWeb AppCritical
IDORAPIHigh
SSL Pinning BypassMobileHigh
Broken AuthWeb AppHigh
Excess Data ExposureAPIMedium

Findings & Impact

15+Critical Vulnerabilities
Identified
40%Risk Exposure Reduced
100%Remediation Guidance

04 — Certifications

Credentials

CVSS

FIRST CVSS v4.0 Certificate

AppSec

Certified AppSec Practitioner (CAP)

Cloud

Multi-Cloud Red Teaming Analyst

Pentest

Penetration Tester

Data

SQL & Relational Databases 101

05 — Education

Pursuing

M.Sc. Cyber Forensics
& Information Security

University of Madras
Currently Pursuing

B.Tech, Computer Science & Engineering

Achariya College of Engineering Technology
August 2017 – September 2021

Spot Recognition Award

Initiatives

Creativity

Exceptional Skills

06 — Get in touch

Have a security
challenge? Let's talk.

srirammanansri@gmail.com LinkedIn