// SECURITY OPERATIONS ACTIVE

Vaibhav Sanwa

Application Security Engineer · Penetration Tester · Security Researcherr

Securing products, uncovering critical flaws, and building trust through offensive thinking. Currently driving Application security at National Informatics Center with Hall of Fame recognitions across 27+ organizations, 200+ vulnerabilities found, $2M+ in prevented incidents.

🛡
Recognition
200+ Vulns Found
Current Role
National Informatics Center
📍
Location
Gurugram, India
🔧
Arsenal
Nuclei · Burp · Automation

Who I Am

I'm Vaibhav Sanwa — a cybersecurity professional who walked into this field driven by curiosity, stayed for the impact, and keeps pushing deeper every day. My academic roots lie in Computer Science at Guru Jambheshwar University, Hisar, where I learned to think in systems, question assumptions, and break things down to understand how they truly work.

That mindset translated directly into security. I've built hands-on expertise across VAPT, bug bounty hunting, API security, web application security, ethical hacking, and automation. I don't just find vulnerabilities — I understand the business impact behind them, document them rigorously, and work to ensure they're resolved.

I'm a quick learner who adapts fast, thinks offensively, and operates with a single goal: making products and digital systems genuinely safer.

I've identified 200+ critical vulnerabilities across 25+ web applications, including critical bugs in Indian government portals that were publicly acknowledged. When I'm not breaking things ethically, I'm at security conferences like BSides, NULLCON, and DEFCON — contributing to and learning from the community.

0
HoF Organizations
0
Vulnerabilities found
0
Years in Security
0
Roles & Engagements

Core Arsenal

Capabilities honed across live product environments, bug bounty programs, and offensive security engagements.

🛡

Product Security

End-to-end security integration within product development lifecycles.

🔍

VAPT

Vulnerability assessment and penetration testing across web and API surfaces.

🎯

Bug Bounty Hunting

Active researcher on Bugcrowd, HackerOne, and independent programs.

📋

Responsible Disclosure

Ethical reporting to global organizations with clear impact documentation.

🌐

Web Application Security

Deep understanding of OWASP Top 10, authentication flaws, and injection vectors.

API Security & Exploitation

Identifying IDOR, broken access controls, and logic flaws in API architectures.

💀

Ethical Hacking

Offensive security methodology with a disciplined, research-driven approach.

🔗

Network Security

Network analysis, packet inspection, and infrastructure assessment.

🐍

Python Scripting & Automation

Custom tools, Burp extensions, and automated detection pipelines.

📡

Security Intelligence

Threat detection, monitoring, and intelligence-driven security operations.

Nuclei

Template-driven vulnerability scanning and automated reconnaissance.

🧰

Burp / Metasploit / Wireshark

Industry-standard tooling for testing, exploitation, and traffic analysis.

Hall of Fame

Recognized across 27+ organizations for identifying and responsibly disclosing security vulnerabilities that strengthened their digital defenses.

Indian Army NASA Barclays Bank Cisco AppDynamics Seagate Morgan Stanley + 21 More Organizations
0
Organizations Recognized
0
Issues in 2 Months
Product Security
Multi-Domain Exposure

Operational Timeline

A trajectory built through hands-on security work — from SOC floors to product security engineering.

Aug 2025 — Present
Cyber Security Engineer-I
HighRadius
Hyderabad, Telangana, India
Mar 2025 — Jul 2025
Product Security Intern
HighRadius
Hyderabad, Telangana, India
  • Built 2 Burp Suite extensions using Python to automate IDOR finding
  • Reported 65+ issues within 2 months of joining
  • Developed skills in report writing, CVSS scoring, and manual testing
Nov 2023 — Present
Security Researcher
Bugcrowd
Nov 2023 — Present
Security Researcher
HackerOne
Sep 2023 — Present
Bug Hunter
Com Olho
  • Reported issues to Flipkart, DS Group, Quantiphi, Quick Reels, BrandMuscle
Nov 2023 — Mar 2024
Security Analyst
Hunto AI
  • Automated threat detection processes
  • Built and assisted development of Cyphone AI
  • Observed SOC activities and tested automation features
Nov 2023 — Feb 2024
SOC Analyst
TIKAJ Security
  • Vulnerability research and threat detection
  • Developed new detection methods
Aug 2023 — Nov 2023
Cyber Security & Digital Forensics
Cyber Secured India
Jun 2023 — Aug 2023
Cyber Security Analyst
Senselearner Technologies Pvt Ltd
  • Learned OWASP Top 10 and explored cybersecurity trends
  • Built an Instagram scraping-related tool as part of learning exposure
  • Improved teamwork, leadership, and responsibility
Sep 2022 — Oct 2022
Cyber Security Analyst
FireShark
  • Cisco Packet Tracer, networking, CLI tools, Burp Suite
  • Threat detection, vulnerability assessment, network security

Field Reports

Selected write-ups on real-world findings, responsible disclosures, and offensive security research.

Responsible Disclosure

Kicking Off 2025: Findings on U.S. Department of Energy

A detailed walkthrough of security findings identified in the U.S. Department of Energy's digital assets at the start of 2025.

Read on Medium →
Government Security

How I Secured The Indian Army?

The story behind discovering and responsibly reporting a security vulnerability to one of the world's largest military organizations.

Read on Medium →
Banking Security

Unveiling a Critical Bug in One of the World's Largest Banks: My Barclays Story

How a critical vulnerability was identified in Barclays Bank's infrastructure and the responsible disclosure journey that followed.

Read on Medium →
Bug Bounty

How I Got My First Collaboration Bounty of $1000

The approach, methodology, and teamwork behind earning a $1000 collaboration bounty — a milestone in the bug bounty journey.

Read on Medium →
Denial of Service

WP-CRON Leading to a Complete Denial of Service (DoS) for Bank 'X'

A technical deep-dive into how a WordPress cron misconfiguration created a complete denial-of-service condition for a banking application.

Read on Medium →

Education & Certifications

⎔ Education

University of Lucknow

Bachelor of Science — Physics
Sep 2020 — Aug 2023

Army Public School, Nehru Road, Lucknow

High School & Senior Secondary — Physics, Chemistry, Mathematics
Apr 2007 — Mar 2019

⎔ Certifications & Events

GET SET HACK BY RISE

Hackathon

FOSS CTF

Capture The Flag Competition

BugBase CyberSeige

Security Challenge

Hack The Mountains 3.0

Hackathon

Fundamentals of Information Security

Certification

Let's Connect

📍 GURUGRAM, INDIA