rohit@appsec:~ — bash — 80×24
rohit@appsec:~$ ./whoami --init

Rohit Kumar

Senior Application Security Engineer with 5+ years securing enterprise systems across web, mobile, and API platforms. Currently at PwC — building tooling, breaking things (legally), and making software safer.

5+
Years Exp
3
CVEs Published
300+
Assessments
200+
Devs Trained

Who I Am

I'm a Senior Application Security Engineer specializing in web application penetration testing, iOS/Android mobile security, API assessments, and source code analysis (SCA). With over 5 years across banking, e-commerce, and enterprise environments, I bridge the gap between offensive security findings and practical remediation.

Currently a Senior Associate at PwC, I build internal security automation tooling alongside conducting comprehensive assessments. Previously at Black Duck (Synopsys), I led teams, mentored junior consultants, and delivered executive-level security roadmaps to C-suite stakeholders.

My proudest achievement: discovering and responsibly disclosing 3 CVEs — CVE-2024-35581, CVE-2024-35582, CVE-2024-35583 — now published in the MITRE and NVD databases.

Kolkata, West Bengal, India
B.Tech Computer Engineering — Punjab Technical University (2020)
OSCP (Pursuing) · CEH · LPT
certifications
Pursuing Offensive Security Certified Professional (OSCP)
Active Certified Ethical Hacker (CEH)
Active Licensed Penetration Tester (LPT)

Where I've Worked

PwC
Senior Associate
Mar 2026 – Present
  • Conduct web application, Android, iOS, and API penetration testing and source code analysis (SCA) for enterprise clients across multiple industries.
  • Built an internal Burp Suite extender tool to streamline vulnerability triage workflow — helps the team manage and track flagged/hidden issues more efficiently.
  • Developed a session cookie analysis tool to identify session management weaknesses during web application assessments.
  • Contribute to building internal security automation tooling to support penetration testing and reporting workflows.
Black Duck (Synopsys)
Senior Security Consultant
Mar 2025 – Mar 2026
  • Directed end-to-end security assessments for enterprise clients covering penetration testing, threat modeling, and remediation validation across web, mobile, and API platforms.
  • Executed advanced iOS and Android security testing — identified critical authentication bypass and data leakage vulnerabilities in 40+ mobile applications.
  • Delivered executive-level security reports and remediation roadmaps to C-suite stakeholders, improving client security posture by 45%.
  • Mentored a team of 5 junior security consultants on OWASP methodologies, secure coding practices, and vulnerability exploitation.
  • Designed scalable security testing frameworks using Python and Bash, reducing manual testing time by 30%.
Black Duck (Synopsys)
Security Consultant
Sep 2024 – Mar 2025
  • Executed 80+ comprehensive web application assessments for banking and fintech clients, identifying high-severity vulnerabilities including IDOR, XXE, and SQL injection.
  • Completed 50+ RESTful and GraphQL API penetration tests, uncovering business logic flaws and broken authentication mechanisms.
  • Reduced false positive rates by 35% through validation workflows and script-based vulnerability verification.
  • Collaborated with 10+ development teams to integrate security best practices into CI/CD pipelines, ensuring SOC2 and GDPR compliance.
  • Facilitated security awareness training for 200+ developers on secure coding and the OWASP Top 10.
Synopsys Inc.
Security Service Associate
Mar 2022 – Sep 2024
  • Discovered and reported 3 CVEs (CVE-2024-35581, CVE-2024-35582, CVE-2024-35583), published in the MITRE and NVD databases.
  • Orchestrated 160+ web application penetration tests and 70+ mobile security audits across e-commerce and healthcare sectors.
  • Directed threat modeling and architecture reviews for 30+ cloud-native applications, reducing attack surface by 40%.
  • Engineered custom Python security automation tools for reconnaissance and reporting, improving efficiency by 25%.
  • Triaged and validated 500+ security findings from commercial scanners to ensure accurate risk assessment.
CSCC Labs
Cyber Security Analyst
Jul 2021 – Mar 2022
  • Managed engagements for 40+ web applications, identifying OWASP Top 10 vulnerabilities and business logic flaws.
  • Assessed network security and configurations, identifying misconfigurations across 60+ systems.
  • Spearheaded forensic analysis for security breaches, reducing mean time to resolution by 50%.
CSCC Labs
Cyber Security Intern
Feb 2021 – Jul 2021
  • Supported vulnerability assessments for 20+ client applications and performed OSINT-based reconnaissance for 15+ targets.

Technical Arsenal

🎯
Security Testing
Web App PentestingiOS Security Android SecurityAPI Security VAPTSource Code Analysis Network SecurityThreat Modeling
🛠️
Tools & Frameworks
Burp Suite ProOWASP ZAP MetasploitMobSF FridaObjection JADXApktool GenymotionPostman3uTools
📋
Standards & Compliance
OWASP Top 10OWASP Mobile Top 10 CWE/SANS 25SOC2 GDPRSecure SDLCCVE Research
💻
Languages & Scripting
PythonBash JavaC++

Published Advisories

CVE-2024-35581High
Stored XSS — Borrower Name
CWE-79 · SourceCodester Laboratory Management System
Stored cross-site scripting via the lname (Borrower Name) field in the Borrow workflow. Payload executes in the authenticated admin context on the borrow view page, enabling session theft and account takeover.
CVE-2024-35582High
Stored XSS — Department
CWE-79 · SourceCodester Laboratory Management System
Stored XSS via the department field of the same Borrow workflow — the second of three unencoded fields on one render sink, confirming a systemic missing output-encoding layer.
CVE-2024-35583High
Stored XSS — Remarks
CWE-79 · SourceCodester Laboratory Management System
Stored XSS via the free-text remarks field. Persistent payload re-fires for any user — including higher-privileged accounts — who opens the affected borrow record.

Hall of Fame

P
Philips
Hall of Honors
Acknowledged in the Philips Coordinated Vulnerability Disclosure Hall of Honors for responsibly reporting a security vulnerability.
IBM
IBM
Security Acknowledgement
Recognized by IBM's Product Security Incident Response Team for responsibly disclosing a security vulnerability.
Acknowledged
C
Cisco
Security Hall of Fame
Listed in Cisco's Security Hall of Fame for responsibly reporting a security vulnerability through their disclosure program.
Acknowledged

Research & Tools

🔍
CVE Research & Disclosure
Discovered and responsibly disclosed 3 CVEs — CVE-2024-35581/35582/35583 — through zero-day vulnerability research in open-source web applications. All published in the official MITRE and NVD databases.
Stored XSSCWE-79 Zero-DayMITRE / NVD
🛰️
OWASP Sentinel Pro
Real-time passive OWASP Top 10 scanner for Burp Suite, built on the Montoya API — with dedicated JWT, OAuth, and SAML detection modules that flag issues as you browse the target.
Montoya APIJava OWASP Top 10Passive Scan
🍪
Burp Session Token Analyzer
Burp Suite extension that pinpoints the exact cookie(s) or header(s) maintaining a session — with OR-group and minimal-combination detection to isolate precisely which tokens matter.
Burp SuiteSession Security JavaWeb Security

Let's Connect

Whether you're looking for a security assessment, want to discuss a CVE, need a consultant for your enterprise, or just want to talk offensive security — my inbox is always open.