Subhash Paudel

Security Consultant

Geelong, Victoria, Australia8 yrs 5 mos experience
Most Likely To Switch

Key Highlights

  • Published 10+ CVEs in open-source projects.
  • Expert in Red Teaming and advanced adversary simulations.
  • Led vulnerability management achieving Essential 8 Maturity Levels.
Stackforce AI infers this person is a Cybersecurity expert specializing in penetration testing and vulnerability management.

Contact

Skills

Core Skills

Penetration TestingCloud SecurityVulnerability ManagementVulnerability AssessmentTraining DevelopmentCybersecurity AwarenessVulnerability ReportingNetwork Support

Other Skills

Digital ForensicsIncident ResponseClient ConsultationProject ManagementMentoringAPI SecurityPhishing SimulationsCybersecurity Awareness TrainingBug Bounty ProgramsNetwork ConfigurationClient SupportBashScriptingPythonC#

About

Subhash is an Experienced Security Consultant and Penetration Tester with a proven track record of working with global clients across the information security domain. He has conducted penetration tests on enterprise-scale web applications, APIs, mobile, IoT, wireless, and network infrastructures, uncovering and remediating critical vulnerabilities. He is a Partner of MITRE CNA, actively leading CVE services and vulnerability management. He has published 10+ CVEs in open-source projects, identifying issues such as SQL injection, XSS, and XPath injection. In addition, he has authored multiple blogs and articles on offensive security and cloud security, contributing to the wider cybersecurity community. With strong expertise in Red Teaming, Purple Teaming, and advanced adversary simulations, he is highly skilled in frameworks and standards, including MITRE ATT&CK, Cyber Kill Chain, NIST 2.0, OWASP, PTES, ISO 27001, and Essential 8. Professional Portfolio spans: 🚩 Web Application & API Penetration Testing 🚩 Internal | External Assessments | Purple Teaming 🚩 Office/M365 and Cloud Security Reviews 🚩 IoT | Wireless & Physical Security Testing 🚩 Threat Hunting | EDR Monitoring & SIEM Management 🚩 Incident Response and Digital Forensics 🚩 Awareness Training | Phishing Campaigns 🚩 Vulnerability Management | Password Audits 🚩 Security Uplift through NIST Zero Trust Implementation Known for being an enthusiastic, ethical, and driven professional, he has a strong record of identifying critical issues such as account takeover, SQL injection, XSS, and unrestricted file uploads, often compromising entire domains during controlled engagements. Certifications: CREST CRT/CPSA, OSCP, OSEP, CRTO, CBBH, CASA, CISCO, Microsoft, Qualys, Rapid7, etc.

Experience

Spartans security

2 roles

Security Consultant

Promoted

Jun 2024 – Present Β· 1 yr 9 mos Β· Australia

  • Key Responsibilities:
  • Conducted Penetration testing across external, internal, web application, API, mobile and physical devices etc.
  • Conducted red teaming including assume breach, end user device compromise with remote work setting and Purple teaming assessment.
  • Collaborated with service providers and technical teams to ensure effective remediation and improved vulnerability management, achieving Essential 8 Maturity Levels.
  • Performed Cloud Security and DLP reviews, resolving security gaps and enhancing compliance.
  • Led end-to-end project management, overseeing communication, budgeting, and stakeholder debriefs.
  • Managed Digital Forensics and Incident Response (DFIR) projects, analyzing incidents, creating attack timelines, and providing remediation strategies using the MITRE ATT&CK Framework.
  • Earned Offensive Security Experienced Professional (OSEP) certification and deepened expertise in NIST, ISO 27001, PCI DSS, and Essential 8 frameworks.
Penetration testingCloud SecurityDigital ForensicsIncident ResponseVulnerability ManagementPenetration Testing

Penetration Tester

Apr 2023 – Jun 2024 Β· 1 yr 2 mos Β· Australia

  • Key Responsibilities:
  • Assisted clients in enhancing security posture across diverse industries, including local government, retail, finance, education, health, and logistics.
  • Conducted External, Internal Network, API, and Web Application Penetration Tests, along with Physical Device Assessments.
  • Supported senior management with project quotations, planning, and successful deliveries.
  • Delivered end-to-end security assessment projects, ensuring thorough analysis and actionable outcomes.
  • Developed internal documentation and user guides focused on infrastructure security best practices.
  • Facilitated client meetings to enhance the vulnerability management process and improvements.
  • Introduced advanced offensive security tools and techniques to enhance clients' infrastructure security.
  • Authored insightful information security articles covering topics such as DMARC and Security Frameworks.
  • Implemented effective vulnerability and patch management strategies, reducing vulnerabilities by 40%.
  • Performed dark web monitoring and investigated breached data and impersonating domains.
  • Managed EDR/XDR, FIM, and SIEM monitoring and response across Microsoft and Qualys platforms.
  • Achieved CREST CPSA and CRT certifications, along with multiple credentials in Qualys, Rapid7, and KnowBe4 platforms.
Penetration TestingVulnerability AssessmentClient ConsultationProject Management

Hacking articles

Cyber Security Consultant

Jan 2023 – Nov 2023 Β· 10 mos Β· Remote

  • Key Responsibilities:
  • Conducted External Network, API and Web Application Penetration Tests and performed Vulnerability Assessments to identify and mitigate security risks.
  • Delivered comprehensive security assessment projects from initiation to completion.
  • Mentored and led junior penetration testers on offensive security engagements.
  • Developed internal documentation and user guides focused on infrastructure security best practices.
  • Facilitated client meetings, addressing service-related queries and ensuring clear communication.
  • Enhanced reporting standards to produce more detailed and actionable penetration testing reports.
  • Designed and developed an API Security Training Course as part of a client-focused service offering.
  • Introduced advanced offensive security tools and techniques to strengthen clients' infrastructure security.
  • Authored multiple information security articles, including topics on Windows security and tool expertise.
Penetration TestingVulnerability AssessmentMentoring

Nexon asia pacific

Penetration Tester / Security Specialist

Sep 2022 – Mar 2023 Β· 6 mos Β· Australia

  • Key Responsibilities:
  • Conducted Phishing Simulations to assess and improve organizational resilience against social engineering attacks.
  • Performed Penetration Testing, including External, Internal, Web Application, and Wireless assessments.
  • Delivered Cybersecurity Awareness Training to clients via training videos.
  • Conducted Vulnerability Assessments to identify and mitigate security weaknesses.
  • Leveraged OSINT (Open Source Intelligence) techniques for threat analysis and reconnaissance.
  • Performed Physical Device Assessments to evaluate hardware security vulnerabilities.
  • Conducted Cloud Security Reviews to ensure secure configurations and compliance with best practices.
  • Communicated effectively with clients on cybersecurity awareness platforms, addressing concerns and resolving queries promptly.
  • Provided clear, actionable insights through client training sessions to foster a security-first culture.
Phishing SimulationsCybersecurity Awareness TrainingVulnerability AssessmentCybersecurity Awareness

Bugcrowd

Security Researcher

Dec 2021 – Nov 2022 Β· 11 mos Β· Remote

  • Key achievements:
  • Featured in the Hall of Fame of renowned entities, including NASA, Kmart, Indeed, and more.
  • Actively tested and reported vulnerabilities on bug bounty programs.
  • Identified and responsibly disclosed vulnerabilities in web applications of leading organizations.
  • Completed 150+ challenges on platforms like PortSwigger, Hack The Box Academy, and others.
Vulnerability ReportingBug Bounty Programs

Total it global

Network and System Support Engineer

Sep 2020 – Sep 2022 Β· 2 yrs Β· Adelaide, South Australia, Australia

  • Key Responsibilities:
  • Managed communication, scheduling, and reporting across projects.
  • Collaborated with third-party vendors to resolve technical issues.
  • Configured and updated Cisco switches and routers.
  • Supported clients including NOKIA, Levi's, and local businesses.
  • Filled System Engineer roles for various clients.
  • Deployed and configured servers, sensors, and cameras.
  • Troubleshot Microsoft applications, third-party software, and EFTPOS systems.
  • Configured and maintained Windows Server networking and devices.
Network ConfigurationClient SupportNetwork Support

Coles

Customer Service Representative

Sep 2017 – Aug 2020 Β· 2 yrs 11 mos Β· Adelaide, South Australia, Australia

  • Experience Across Multiple Departments: Frontend to Backend
  • Key Responsibilities:
  • Assisted customers during checkout, ensuring they get a great customer experience.
  • Responded to customer inquiries via phone, providing product information and resolving queries.
  • Supported the department manager with stock ordering and merchandising tasks.
  • Participated in stock audits, accurately documenting inventory records.
  • Managed the receipt of deliveries, verifying items and reporting any discrepancies to the manager.
  • Trained and mentored newly onboarded team members.
  • Led team members in daily tasks, delegating responsibilities to maintain workflow efficiency and meet operational goals.

Education

Kennesaw State University

GRC Approch Managing Cyber Security β€” Cyber Security Risk Management

Feb 2025 – Apr 2025

University of South Australia

Bachelors β€” Information Technology

Stackforce found 100+ more professionals with Penetration Testing & Cloud Security

Explore similar profiles based on matching skills and experience