Application Security Engineer · Penetration Tester · Security Researcherr
Securing products, uncovering critical flaws, and building trust through offensive thinking. Currently driving Application security at National Informatics Center with Hall of Fame recognitions across 27+ organizations, 200+ vulnerabilities found, $2M+ in prevented incidents.
I'm Vaibhav Sanwa — a cybersecurity professional who walked into this field driven by curiosity, stayed for the impact, and keeps pushing deeper every day. My academic roots lie in Computer Science at Guru Jambheshwar University, Hisar, where I learned to think in systems, question assumptions, and break things down to understand how they truly work.
That mindset translated directly into security. I've built hands-on expertise across VAPT, bug bounty hunting, API security, web application security, ethical hacking, and automation. I don't just find vulnerabilities — I understand the business impact behind them, document them rigorously, and work to ensure they're resolved.
I'm a quick learner who adapts fast, thinks offensively, and operates with a single goal: making products and digital systems genuinely safer.
I've identified 200+ critical vulnerabilities across 25+ web applications, including critical bugs in Indian government portals that were publicly acknowledged. When I'm not breaking things ethically, I'm at security conferences like BSides, NULLCON, and DEFCON — contributing to and learning from the community.
Capabilities honed across live product environments, bug bounty programs, and offensive security engagements.
End-to-end security integration within product development lifecycles.
Vulnerability assessment and penetration testing across web and API surfaces.
Active researcher on Bugcrowd, HackerOne, and independent programs.
Ethical reporting to global organizations with clear impact documentation.
Deep understanding of OWASP Top 10, authentication flaws, and injection vectors.
Identifying IDOR, broken access controls, and logic flaws in API architectures.
Offensive security methodology with a disciplined, research-driven approach.
Network analysis, packet inspection, and infrastructure assessment.
Custom tools, Burp extensions, and automated detection pipelines.
Threat detection, monitoring, and intelligence-driven security operations.
Template-driven vulnerability scanning and automated reconnaissance.
Industry-standard tooling for testing, exploitation, and traffic analysis.
Recognized across 27+ organizations for identifying and responsibly disclosing security vulnerabilities that strengthened their digital defenses.
A trajectory built through hands-on security work — from SOC floors to product security engineering.
Selected write-ups on real-world findings, responsible disclosures, and offensive security research.
A detailed walkthrough of security findings identified in the U.S. Department of Energy's digital assets at the start of 2025.
Read on Medium →The story behind discovering and responsibly reporting a security vulnerability to one of the world's largest military organizations.
Read on Medium →How a critical vulnerability was identified in Barclays Bank's infrastructure and the responsible disclosure journey that followed.
Read on Medium →The approach, methodology, and teamwork behind earning a $1000 collaboration bounty — a milestone in the bug bounty journey.
Read on Medium →A technical deep-dive into how a WordPress cron misconfiguration created a complete denial-of-service condition for a banking application.
Read on Medium →