Security | Hacking
Gaurav Sharma

Penetration Tester | VAPT | SOC |
Network Security | Threat Hunter |
Red Teamer | Python Enthusiast |

About Me

Currently Working as Manager, Information Security at Care Health Insurance Ltd.

Security Researcher Developing With a Passion .

I am passionately pursuing a career in Cybersecurity with a focus on Web/Mobile/API/Infra/Network/Cloud Security. With over 5 years of experience in Red Teaming and Penetration Testing, I have gained a deep understanding of Web. Mobile, Network, OS, API, and network exploitation. I have completed my EC-Council CEH Certification in Dec. 2017.

My skills and interests include Web Security, Automation, Penetration Testing (API/Network/Web), and Red Teaming (Internal and External). I am proficient in programming languages like Basic JavaScript, Bash, Python and well-versed in using tools and environments.

What Services I'm Providing

In order to secure organization, I am proficient with managing security controls according to Mitre Att&ck and Cyber Kill Chain.

Web/API/Network VAPT

To perform Web/mobile Apps, API, Network, Servers vulnerabilities through automated VA and Manual Penetration Testing as per OWASP and SANS standard.

Red Teaming & Threat Hunting

To perform the Offensive Attacks on Network, OS, Active Directory to find out the existing security loopholes of the organization.

Cloud Security

To find the security configuration issues in different services of AWS including EC2 Instances, DynamoDb, RDS, S3 Buckets, Lambda etc.

Working Process

Every Security Activity follows Mitre Att&ck Strategy in order to secure organization information security. Each activity has different approach depending on DAST/SAST VAPT, SIEM Management, Red Teaming, Threat Hunting, Threat Modelling.

Work Experience

Total of 5+ Years of Cyber Sec Experience

App Sec & Infra Sec - VAPT
2018-2023

To perform Web/mobile Apps, API, Network, Servers vulnerabilities through automated VA and Manual Penetration Testing as per OWASP and SANS standard.

App Sec & Infra Sec - VAPT
Red Teaming & Threat Hunting
2018-2023

To perform the Offensive Attacks on Network, OS, Active Directory to find out the existing security loopholes of the organization.

Red Teaming & Threat Hunting
Network Security
2020-2023

To review policies and configuration issues Network Devices like Firewall, Routers, Switches, Load Balancers, etc. along with managing ACLs, IDS, IPS from security prospective.

Network Security
SOC
2021-2023

To deploy and manage SIEM, Proxy, EDR/XDR, DLP, Brand Monitoring, Privilege Access Management, HIPS, PGP Encryption, WAF.

SOC
Cloud Security
2022-2023

To find the security configuration issues in different services of AWS including EC2 Instances, DynamoDb, RDS, S3 Buckets, Lambda etc.

Cloud Security

Stay In Touch

If you have any questions about certifications, bug bounties, or how to deep dive into offensive/defensive security, feel free to reach out to me. I would be more than happy to share my experience and knowledge with you.

Scroll to Top