Overview
SUMMARY
Work History
Education
Skills
Websites
Certification
AWARDS AND HALL OF FAMES
Timeline
bgImages
ZUBER VHORA

ZUBER VHORA

Colgate Palmolive
Mumbai

Overview

Red Team Specialist with 7 years of professional experience in cybersecurity. Qualifications include a Master's in Digital Forensics and Information Security; OSCP and CEH v10 certifications; and in-depth knowledge of security tools, technologies, and best practices. This includes 7+ years in web application/API testing, source code review, network pentesting, VDI testing, and external/internal scan assessments.
09+
years of professional experience
01+
Certification

Work History

06.2025 - Current1 Year 4 Months
Sr. Specialist, Red Team
Colgate Palmolive
  • Conducted external vulnerability scans to identify security gaps in company assets and infrastructure [Over 900 passwords cracked].
  • Led purple team exercises, coordinating red team attacks with green team detection and response.
  • Conducted EDR/XDR Proof of Concept (POC) evaluations to assess alert logic, utilizing custom process hollowing, Native .NET APIs, and obfuscated payloads.
  • Performed Active Directory penetration testing including user enumeration, password spraying, privilege escalation, and attack path mapping [Domain Admin Achieved].
  • Researched and analyze the latest threat intelligence to defend against emerging cyber threats.
  • Developed Docker based automated linux scanner with Web UI to perform automated OSINT and Active Scan with user defined configuration.
06.2022 - 05.20252 Years 11 Months
Sr. Specialist, Security Engineer
Colgate Palmolive
  • Led web application onboarding onto Akamai, including DNS record management and cutover (CNAME to edge hostnames), Property Manager rule configuration, and origin/edge certificate provisioning via CPS.
  • Onboarded applications into Akamai security configurations, deploying and tuning WAF policies (App & API Protector / Kona Site Defender) with appropriate match targets and rate policies.
  • Authored custom WAF rules to allow or deny specific traffic based on application requirements, tuning conditions to block malicious patterns while permitting legitimate requests.
  • Reviewed and analyzed WAF logs to assess rule effectiveness, triage blocked requests, and reduce false positives.
  • Managed and Configured multiple application load balancers (F5, GCP).
  • Implemented Cloud Armor Policy, NAT implementation.
  • Automated Threat Intelligence Feed and IOCs from multiple enterprise tools to Threat Stream using python.
  • Implemented security hardening using CIS Benchmarks on Windows and Linux systems.
  • Organized Capture the Flag event and being a part of Team Building committee.
  • Implemented, maintained, and enhanced policies for security tools including WAF, endpoint security, web decoys, and DLP.
  • Built Tanium sensors for custom detections and implementations.
  • Built Security Monitoring Tool to actively check the status of endpoint security solutions.
  • Built SIEM integrations and conducted POCs for multiple security tools like [Akamai WAF, Radware WAF, API Security, GCP Load Balancer, Decoys, Gytpol, Alert Logic IDS, Aliyun WAF, Tencent WAF].
09.2021 - 06.20229 Months
Security Consultant
EY GDS
  • Performed web application penetration testing.
  • Performed virtual desktop infrastructure [VDI] penetration testing for the clients.
  • Decide scope of activities and help clients to understand the vulnerabilities.
05.2018 - 08.20213 Years 3 Months
Security Services Associate Consultant
Synopsys
  • Audited 15+ clients on various grounds like source code review [SAST], Web Application, API Penetration Testing and performed Vulnerability Assessments [DAST] for verticals like banking, consulting, marketing and IT firms.
  • First hand experience in both Manual and Automated testing for Web-Applications APIs and finding the root cause of the vulnerability.
  • Extensive knowledge in manual testing for web service API's as well as business logic, JWT, SAML and OAuth related testing.
  • Hands on experience on testing application security as per the guidelines / requirements from OWASP.
  • Conducted automated as well as manual penetration testing of Web Applications in Java, J2EE, .NET, IIS, PHP, ASP.
  • Perform both automation and manual tests for the network vulnerability assessment.
  • Worked on ATOR BurpSuite extender to easily configure automated scanning for web applications and perform auto login to maintain the active web application session throughout the active scanning.
  • Direct communication with the clients for prequalification, troubleshooting and remediations.
  • Deciding scope of the activities based on regulatory circulars and mandates.
  • Developed strategies to audit clients for their technology stack.
  • Ensured smooth testing from all the participating team members.
  • Prepare client reports and presentations to an exceptional standard like NIST, CVSS.
  • Trained Interns and new joiners.
  • Suggested controls for risk reduction and mitigation.
  • Developed an internal portal for a client to get insights of projects, application and vulnerabilities details per application and client region.
01.2018 - 05.20184 Months
Information Security Intern
Synopsys
  • Developed a web portal to implement different authentication techniques such as Cookie Based, JWT, OAuth 2.0 using C#.Net.
  • Developed scripts using python that assisted my work in file search and data comparison.
  • Analyzed, compared various web applications and automated results from different tools to find out which one gives better results in terms of automated scanning.
  • Worked on Web Application and API testing.
09.20179 Years 1 Month
Intern
Directorate of Forensic Sciences | Gandhinagar
  • Worked on CCTV, HDD and Mobile Phone forensics.
  • Hands-on experience on Enterprise Forensic Tools including EnCase, FTK, Autopsy, Cellebrite UFED.
  • Developed and gave verbal reports and inputs on assigned cases.

Education

M.Sc. | Digital Forensics & Information Security, Cyber Security and Computer Forensics

National Forensic Sciences University | 05.2018
National Forensic Sciences University
05.2018

M. Sc. | Information Technology, Web Application Development

Sardar Patel University | 05.2016
Sardar Patel University
05.2016

Bachelor | Computer Application, Web Application Development

Sardar Patel University | 05.2015
Sardar Patel University
05.2015

Skills

Security Frameworks: OWASP Top 10
MITRE ATT&CK
NIST
PTES
CIS Benchmarks
Pentesting & Red Team Tools: Burp Suite
Nmap
SQLmap

Certification

  • OSCP+/OSCP, 2025
  • CEH v10, 2018
  • Certified Red Team Expert CRTE Training, by Altered Security 2025
  • Splunk Fundamentals Part 1, Splunk 2021
  • Blue Team Star Challenge CTF, RangeForce, 2021
  • Malware Analysis workshop taken by Monnappa K A, March 2019
  • Rest API, Android Pentesting by Null, February 2018

AWARDS AND HALL OF FAMES

Vulnerability of the Month, Synopsys 2019, Spot Award, EY GDS 2021, Sunshine Stories, Colgate-Palmolive 2022, Hall of Fame (bug bounty): Stripo Inc, Helium, Glossier etc.

Timeline

Sr. Specialist, Red Team
Colgate Palmolive
06.2025 - CurrentRead more
Sr. Specialist, Security Engineer
Colgate Palmolive
06.2022 - 05.2025Read more
Security Consultant
EY GDS
09.2021 - 06.2022Read more
Security Services Associate Consultant
Synopsys
05.2018 - 08.2021Read more
Information Security Intern
Synopsys
01.2018 - 05.2018Read more
Intern
Directorate of Forensic Sciences
09.2017 Read more
Sardar Patel University - M. Sc., Information Technology, Web Application Development
Read more
Sardar Patel University - Bachelor, Computer Application, Web Application Development
Read more
National Forensic Sciences University - M.Sc., Digital Forensics & Information Security, Cyber Security and Computer Forensics
Read more
ZUBER VHORA