Hemant Patidar (HemantSolo)

AI Researcher

Madhya Pradesh, India3 yrs 10 mos experience
Highly Stable

Key Highlights

  • Reported 5,000+ validated vulnerabilities globally.
  • Earned Hall of Fame recognitions from major tech companies.
  • Led vulnerability research initiatives and mentored junior engineers.
Stackforce AI infers this person is a Cybersecurity Expert specializing in Application Security and Vulnerability Research.

Contact

Skills

Core Skills

Application SecurityVulnerability ResearchSecurity ResearchPublic Relations

Other Skills

Application TestingAutoCADBug Bounty HuntingBurp SuiteC (Programming Language)C++Content ManagementCritical ThinkingCybersecurityDASTEthical HackingHTMLKali LinuxLinuxMicrosoft Excel

About

Senior Application Security Engineer & Security Researcher with 5+ years of hands-on experience securing large-scale web, API, mobile (Android & iOS), network, and cloud environments. I specialize in real-world vulnerability research, combining manual exploitation with advanced AppSec tooling to identify high-impact security risks—including 0-day and previously untracked vulnerabilities. My expertise spans DAST, SAST, SCA, reachability analysis, and source code review, with a strong focus on validating exploitability and business impact to eliminate false positives and drive meaningful remediation. I have reported 5,000+ validated vulnerabilities across global organizations and open-source projects, earning Hall of Fame recognitions and rewards from Google (7x), Apple (10+), U.S. Department of Defense, and many other leading companies. I’ve published 12+ CVEs via MITRE, authored exploits on Exploit-DB, and contributed to Google Hacking Database. Beyond research, I lead vulnerability research initiatives, mentor security engineers, review technical findings, and collaborate closely with customers and internal stakeholders to raise security maturity at scale. 🔐 Core Expertise Application Security (Web, API, Mobile, Cloud) Vulnerability Research & 0-Day Discovery SAST | DAST | SCA | Reachability Analysis Source Code Review (Java, JS, Python, Go, C/C++, PHP, Ruby) OWASP Top 10, Business Logic Flaws, Auth & Access Control Security Automation & Tooling 🏆 Highlights 5,000+ validated vulnerabilities (Critical → Low) Researcher of the Month – U.S. DoD Top 15 Security Researcher – NCIIPC (Govt. of India) Yogosha All-Time Top 10 Represented Yogosha at RootedCON (Spain) & GISEC (Dubai) 🎓 Certifications eCPPTv2 | eWPTXv2 | CEH-Master | eJPT | CAPen | CAP | CNSP I’m driven by breaking complex security problems, uncovering impactful vulnerabilities, and helping organizations build secure-by-design systems. 📫 Open to collaboration, AppSec leadership roles, and advanced security research opportunities.

Experience

Hack the box

2 roles

Hack The Box SME

Promoted

Jul 2024Present · 1 yr 8 mos

  • As a recognized Hack The Box Subject Matter Expert, I am honored to be part of an esteemed group of cybersecurity professionals. By contributing my expertise and passion through regular insights and quotes to HTB’s editorial content, I aim to help our community of over 2 million members deepen their understanding of the cybersecurity landscape.
Public RelationsRed TeamingContent ManagementPenetration TestingPublic SpeakingSecurity Research

CTF Player

Sep 2020Present · 5 yrs 6 mos

Synack red team

Synack Red Team Member

Jul 2022Present · 3 yrs 8 mos

Loginsoft

Senior Security Researcher

May 2022Present · 3 yrs 10 mos · Hyderabad, Telangana, India

  • ➤ Conduct advanced vulnerability research on large-scale open-source and enterprise software across multiple
  • programming languages including Java, JavaScript, C/C++, Python, PHP, Go, Ruby, and iOS ecosystems.
  • ➤ Performed SAST, DAST, SCA, and reachability analysis to identify critical, high, and medium-risk security issues,
  • including 0-day and previously untracked vulnerabilities.
  • ➤ Validate exploitability and real-world impact to reduce false positives and improve vulnerability accuracy.
  • ➤ Lead vulnerability research activities, customer escalations, documentation, and coordination with internal and
  • external stakeholders.
  • ➤ Mentor junior researchers and review security findings to ensure high-quality technical reporting.
Vulnerability ResearchSASTDASTSCAReachability AnalysisSource Code Review+1

Technoxi

Cyber Security Engineer

Dec 2021Apr 2022 · 4 mos · India

  • ➤ Web Application Pentesting
  • ➤ API Pentesting
  • ➤ Blog Writing
  • ➤ Reporting and Documentation
  • ➤ Learning

Securelayer7

Cyber Security Consultant

Sep 2021Nov 2021 · 2 mos · Pune, Maharashtra, India

  • ➤ Performed black-box, grey-box, and white-box penetration testing for web applications, APIs, Android applications, and internal/external infrastructure.
  • ➤ Delivered detailed vulnerability assessment reports including risk ratings, exploitation details, and remediation guidance.

Yogosha

Penetration Tester - Network/Web/API/Mobile (All Time Top 10)

Aug 2021Present · 4 yrs 7 mos · India

  • ➤ Link: https://app.yogosha.com/r/HemantSolo
  • ➤ Rank: All Time Top 10
  • ➤ Secured 3rd Rank in Top Hackers S2 2021
  • ➤ Secured 6th Rank in Top Hackers 2021

Gir software services

Application Security Intern

Jul 2021Jul 2021 · 0 mo

  • Responsibility Includes:
  • ➤ Performed a security check of eCommerce Website.
  • ➤ Report and make documents of investigations identified on the product along with the mitigations.
  • ➤ Learning.

Ismiletechnologies

Cyber Security Engineer Intern

Jun 2020Aug 2020 · 2 mos · India

  • ➤ Received training in Professional Cloud Architecture and cloud security fundamentals.
  • ➤ Conducted security assessments for Google Cloud Platform (GCP) and AWS environments.
  • ➤ Prepared high-level security architecture, Cloud Control Matrix (CCM), and hardening guidelines for GCP components.
  • ➤ Authored technical blogs focused on cloud security best practices.

Open bug bounty

Security Researcher

May 2020Present · 5 yrs 10 mos

  • ➤ Reported 50+ vulnerabilities.
  • ➤ Got one recommendation from Vovsoft.
  • ➤ Check Here: https://www.openbugbounty.org/researchers/HemantSolo/

Safehack

Web Application Penetration Testing - Mentor

May 2020Jun 2020 · 1 mo · India

  • Responsibility Includes:
  • ➤ Successfully guided 30+ VAPT interns for finding web application vulnerabilities.
  • ➤ Secured 5+ websites that are clients of SafeHack.

Hackerone

Security Researcher

Jan 2020Present · 6 yrs 2 mos

  • ➤ Thanks received: 10+
  • ➤ U.S. Dept Of Defence: Researcher of the Month (Feb. 2021)
  • ➤ Reputation: 500+
  • ➤ Profile URL: https://hackerone.com/HemantSolo

Bugcrowd

Security Researcher

Jan 2020Present · 6 yrs 2 mos

  • ➤ Hall Of Fame: 50+
  • ➤ Current Rank: Bugcrowd Top 600 Hackers Globally
  • ➤ Profile: https://bugcrowd.com/HemantSolo

Nciipc india (a unit of ntro)

Security Researcher

Jan 2020Present · 6 yrs 2 mos

  • ➤ Got listed in Top 15 Researcher and Contributor in the newsletter announced by NCIIPC India (A unit of NTRO) in Oct 2020.
  • ➤ Secured 40+ websites of Indian Govt. with various web application vulnerabilities.
  • ➤ Reported 10+ high-security vulnerabilities including:
  • RCE via file upload - 5+
  • Cross Site Scripting - 6+
  • No Rate Limiting leads to account takeover and OTP bypass - 20+
  • and more...

Provilac dairy farms private limited

Cyber Security Consultant

Dec 2019May 2020 · 5 mos · Pune/Pimpri-Chinchwad Area

  • Responsibility Includes:
  • ➤ Web & Android Application Penetration Testing
  • ➤ Reporting and Documentation
  • ➤ Learning

Education

SRM IST Chennai

BTech - Bachelor of Technology — Civil Engineering

Jan 2018Jan 2022

Himalaya International School

High School — Science Stream

Jan 2013Jan 2017

Stackforce found 100+ more professionals with Application Security & Vulnerability Research

Explore similar profiles based on matching skills and experience