Parv Bajaj

DevOps Engineer

Gurgaon, Haryana, India4 yrs 6 mos experience

Key Highlights

  • Expert in vulnerability assessment and penetration testing.
  • Proven track record in automating security processes.
  • Strong collaboration with engineering teams for secure design.
Stackforce AI infers this person is a Cybersecurity Specialist with expertise in vulnerability management and application security in SaaS environments.

Contact

Skills

Core Skills

Vulnerability AssessmentApplication SecurityPenetration TestingSecurity ComplianceIncident Response

Other Skills

API TestingAmazon Web Services (AWS)Analytical SkillsApplication Programming Interfaces (API)Application Security ArchitectureAutomationAzure Key VaultBlack Box TestingCCNACloud SecurityCloud StorageCode ReviewCommunicationCyber Security RiskCybersecurity

About

As a Product Security Engineer, I help clients across various industries and sectors to assess, improve, and maintain their information security posture and compliance. I conduct vulnerability assessment and penetration testing for web applications, network, APIs and mobile applications. I have performed cloud architectural review , security configuration review, log monitoring and event collection using various tools and methodologies. I am passionate about cybersecurity and always eager to learn new skills and technologies in this dynamic and evolving field. I enjoy solving complex and challenging problems, collaborating with diverse teams and stakeholders, and delivering high-quality and impactful solutions. My goal is to become a trusted and reliable cybersecurity professional who can protect and enhance the security and resilience of organizations and society.

Experience

Syfe

Security Engineer I

Nov 2025Present · 4 mos · Gurugram, Haryana, India · Remote

Finthrive

2 roles

Security Engineer – Application & Product Security

Promoted

Mar 2025Nov 2025 · 8 mos · Gurugram, Haryana, India · Hybrid

  • Conducted comprehensive vulnerability assessments across 35+ products, including web, mobile, API, and thick client applications.
  • Managed vulnerability operations workflows by triaging vulnerabilities based on risk severity, exploitability, and business impact, utilizing CVSS scoring to prioritize remediation efforts effectively
  • Led remediation efforts for critical industry-wide vulnerabilities, including Log4j, Spring4Shell, and OpenSSL issues.
  • Developed security dashboards to track vulnerability trends, remediation progress, and risk metrics for leadership reporting.
  • Automated security processes using Python, Bash, and Jenkins, improving efficiency in vulnerability scanning and pentesting workflows.
  • Conducted secure SDLC assessments and threat modeling workshops, improving proactive security integration.
  • Provided guidance on API security best practices, ensuring secure authentication, rate limiting, and data protection mechanisms.
Security ComplianceSoftware Development Life Cycle (SDLC)Information SecurityAmazon Web Services (AWS)Application SecurityVulnerability Assessment+3

Jr. Penetration Tester

Apr 2024Mar 2025 · 11 mos · Gurugram, Haryana, India · Hybrid

  • Conducted manual and automated penetration testing on web applications, APIs, and cloud environments.
  • Developed custom exploits and attack payloads, improving security test coverage beyond standard scanners.
  • Performed Active Directory security assessments, identifying privilege escalation risks and configuration weaknesses.
  • Assisted in cloud security testing, identifying misconfigured IAM policies, insecure storage permissions, and weak encryption practices.
  • Researched and presented findings on zero-day vulnerabilities and advanced attack techniques.
Penetration TestingSecurity ComplianceSoftware Development Life Cycle (SDLC)VAPTInformation SecurityOSCP+11

Grant thornton bharat llp

3 roles

Senior Security Consultant

Promoted

Aug 2023Apr 2024 · 8 mos

  • Led penetration testing engagements, simulating real-world attack scenarios on web, network, and cloud environments.
  • Conducted secure design reviews and cloud security assessments (AWS, Azure, GCP), identifying misconfigurations and enforcing security best practices.
  • Developed security automation scripts (Python, Bash, Jenkins) to streamline vulnerability detection, reducing manual effort by 50%.
  • Integrated SAST (Semgrep, SonarQube) and DAST (BurpSuite, Nessus) tools into CI/CD pipelines, improving security coverage.
  • Led threat modeling workshops using STRIDE & MITRE ATT&CK, enabling teams to proactively identify and mitigate risks.
  • Collaborated with engineering teams to implement secure authentication mechanisms (OAuth, SAML, JWT) and data protection policies.
Penetration TestingSecurity ComplianceSoftware Development Life Cycle (SDLC)Information SecurityAmazon Web Services (AWS)Vulnerability Assessment+1

Security Consultant

Sep 2021Aug 2023 · 1 yr 11 mos

  • Conducted penetration testing on web applications, APIs, mobile apps, and thick clients, identifying vulnerabilities and providing remediation guidance.
  • Assisted in network vulnerability assessments, evaluating firewall configurations, segmentation, and Active Directory security controls.
  • Performed secure code reviews, identifying authentication and authorization issues in application logic.
  • Supported incident response and forensic analysis, investigating security breaches and improving detection mechanisms.
  • Provided security awareness training for development teams, helping them understand and mitigate common security risks.
CCNAPenetration TestingInfrastructureSecurity ComplianceSoftware Development Life Cycle (SDLC)VAPT+13

Cyber Security Intern

Apr 2021Sep 2021 · 5 mos

  • Assisted in network vulnerability assessments, identifying security misconfigurations and analyzing risk factors.
  • Conducted basic web application security testing, learning OWASP Top 10 vulnerabilities and secure coding practices.
  • Supported security teams by analyzing SIEM logs, assisting in threat detection and initial triage.
  • Gained hands-on experience in automated vulnerability scanning (Nessus, OpenVAS) and manual testing (BurpSuite, Nmap, Wireshark).
  • Worked on a university cybersecurity project, conducting vulnerability assessments for web applications and network infrastructure.
Penetration TestingSecurity EngineeringCybersecurityWeb Application SecurityCloud Security

Danalitic

Cyber Security Engineer

Jun 2021Sep 2021 · 3 mos

Penetration TestingProject ManagementIncident Response

Haryana

Gurugram Police Cyber Security Summer Internship

Jun 2021Sep 2021 · 3 mos · Haryana, India

Bugcrowd

Bugcrowd Researcher

Jan 2021Jun 2021 · 5 mos

Pac security llp

Penetration Tester

May 2020Jul 2020 · 2 mos

Education

The NorthCap University

Minor Degree — Cyber Security

Jan 2019Jan 2022

The NorthCap University

BTech - Bachelor of Technology — Computer Science

Jan 2018Jan 2022

Stackforce found 100+ more professionals with Vulnerability Assessment & Application Security

Explore similar profiles based on matching skills and experience