Red Team Specialist with 7 years of professional experience in cybersecurity. Qualifications include a Master's in Digital Forensics and Information Security; OSCP and CEH v10 certifications; and in-depth knowledge of security tools, technologies, and best practices. This includes 7+ years in web application/API testing, source code review, network pentesting, VDI testing, and external/internal scan assessments.
09+
years of professional experience
01+
Certification
Work History
06.2025 - Current1 Year 4 Months
Sr. Specialist, Red Team
Colgate Palmolive
Conducted external vulnerability scans to identify security gaps in company assets and infrastructure [Over 900 passwords cracked].
Led purple team exercises, coordinating red team attacks with green team detection and response.
Conducted EDR/XDR Proof of Concept (POC) evaluations to assess alert logic, utilizing custom process hollowing, Native .NET APIs, and obfuscated payloads.
Performed Active Directory penetration testing including user enumeration, password spraying, privilege escalation, and attack path mapping [Domain Admin Achieved].
Researched and analyze the latest threat intelligence to defend against emerging cyber threats.
Developed Docker based automated linux scanner with Web UI to perform automated OSINT and Active Scan with user defined configuration.
06.2022 - 05.20252 Years 11 Months
Sr. Specialist, Security Engineer
Colgate Palmolive
Led web application onboarding onto Akamai, including DNS record management and cutover (CNAME to edge hostnames), Property Manager rule configuration, and origin/edge certificate provisioning via CPS.
Onboarded applications into Akamai security configurations, deploying and tuning WAF policies (App & API Protector / Kona Site Defender) with appropriate match targets and rate policies.
Authored custom WAF rules to allow or deny specific traffic based on application requirements, tuning conditions to block malicious patterns while permitting legitimate requests.
Reviewed and analyzed WAF logs to assess rule effectiveness, triage blocked requests, and reduce false positives.
Managed and Configured multiple application load balancers (F5, GCP).
Automated Threat Intelligence Feed and IOCs from multiple enterprise tools to Threat Stream using python.
Implemented security hardening using CIS Benchmarks on Windows and Linux systems.
Organized Capture the Flag event and being a part of Team Building committee.
Implemented, maintained, and enhanced policies for security tools including WAF, endpoint security, web decoys, and DLP.
Built Tanium sensors for custom detections and implementations.
Built Security Monitoring Tool to actively check the status of endpoint security solutions.
Built SIEM integrations and conducted POCs for multiple security tools like [Akamai WAF, Radware WAF, API Security, GCP Load Balancer, Decoys, Gytpol, Alert Logic IDS, Aliyun WAF, Tencent WAF].
09.2021 - 06.20229 Months
Security Consultant
EY GDS
Performed web application penetration testing.
Performed virtual desktop infrastructure [VDI] penetration testing for the clients.
Decide scope of activities and help clients to understand the vulnerabilities.
05.2018 - 08.20213 Years 3 Months
Security Services Associate Consultant
Synopsys
Audited 15+ clients on various grounds like source code review [SAST], Web Application, API Penetration Testing and performed Vulnerability Assessments [DAST] for verticals like banking, consulting, marketing and IT firms.
First hand experience in both Manual and Automated testing for Web-Applications APIs and finding the root cause of the vulnerability.
Extensive knowledge in manual testing for web service API's as well as business logic, JWT, SAML and OAuth related testing.
Hands on experience on testing application security as per the guidelines / requirements from OWASP.
Conducted automated as well as manual penetration testing of Web Applications in Java, J2EE, .NET, IIS, PHP, ASP.
Perform both automation and manual tests for the network vulnerability assessment.
Worked on ATOR BurpSuite extender to easily configure automated scanning for web applications and perform auto login to maintain the active web application session throughout the active scanning.
Direct communication with the clients for prequalification, troubleshooting and remediations.
Deciding scope of the activities based on regulatory circulars and mandates.
Developed strategies to audit clients for their technology stack.
Ensured smooth testing from all the participating team members.
Prepare client reports and presentations to an exceptional standard like NIST, CVSS.
Trained Interns and new joiners.
Suggested controls for risk reduction and mitigation.
Developed an internal portal for a client to get insights of projects, application and vulnerabilities details per application and client region.
01.2018 - 05.20184 Months
Information Security Intern
Synopsys
Developed a web portal to implement different authentication techniques such as Cookie Based, JWT, OAuth 2.0 using C#.Net.
Developed scripts using python that assisted my work in file search and data comparison.
Analyzed, compared various web applications and automated results from different tools to find out which one gives better results in terms of automated scanning.
Worked on Web Application and API testing.
09.20179 Years 1 Month
Intern
Directorate of Forensic Sciences | Gandhinagar
Worked on CCTV, HDD and Mobile Phone forensics.
Hands-on experience on Enterprise Forensic Tools including EnCase, FTK, Autopsy, Cellebrite UFED.
Developed and gave verbal reports and inputs on assigned cases.
Education
M.Sc. | Digital Forensics & Information Security, Cyber Security and Computer Forensics
National Forensic Sciences University | 05.2018
National Forensic Sciences University
05.2018
M. Sc. | Information Technology, Web Application Development
Sardar Patel University | 05.2016
Sardar Patel University
05.2016
Bachelor | Computer Application, Web Application Development
Certified Red Team Expert CRTE Training, by Altered Security 2025
Splunk Fundamentals Part 1, Splunk 2021
Blue Team Star Challenge CTF, RangeForce, 2021
Malware Analysis workshop taken by Monnappa K A, March 2019
Rest API, Android Pentesting by Null, February 2018
AWARDS AND HALL OF FAMES
Vulnerability of the Month, Synopsys 2019, Spot Award, EY GDS 2021, Sunshine Stories, Colgate-Palmolive 2022, Hall of Fame (bug bounty): Stripo Inc, Helium, Glossier etc.
Timeline
Sr. Specialist, Red Team
Colgate Palmolive
06.2025 - CurrentRead more
Sr. Specialist, Security Engineer
Colgate Palmolive
06.2022 - 05.2025Read more
Security Consultant
EY GDS
09.2021 - 06.2022Read more
Security Services Associate Consultant
Synopsys
05.2018 - 08.2021Read more
Information Security Intern
Synopsys
01.2018 - 05.2018Read more
Intern
Directorate of Forensic Sciences
09.2017 Read more
Sardar Patel University - M. Sc., Information Technology, Web Application Development
Read more
Sardar Patel University - Bachelor, Computer Application, Web Application Development
Read more
National Forensic Sciences University - M.Sc., Digital Forensics & Information Security, Cyber Security and Computer Forensics