Junior VAPT Analyst · Pune, India
Soham
D. Jadhav
Network & web application penetration testing, compliance and risk management. Currently at Capgemini — independently recognised with 32+ Hall of Fame credits across Bugcrowd, self-hosted VDPs, and public bounty programmes.
0Disclosed
0TryHackMe
0Day Streak
0Hall of Fame
Experience
Jan 2025 — Present
Junior VAPT Analyst
Capgemini, Pune
- Perform internal and external network VA/PT, including asset discovery, segmentation scans, and firewall rule set reviews.
- Conduct compliance/PCI-driven ASV scans and cloud configuration reviews on Azure and GCP.
- Run web application penetration tests using black box and grey box methodologies — 40–60+ vulnerabilities identified per assessment cycle.
- Own the complete WAPT lifecycle end to end, from scanning through validation to client report.
Jan 2025 — Present
Cybersecurity Researcher
Independent — Bug Bounty / VDP Programmes
- Web application and API security testing across public VDP/BBP programmes using Burp Suite, Nmap, SQLMap, and Dirsearch.
- 30+ vulnerabilities discovered and responsibly disclosed, including SQL injection, XSS, IDOR, account takeover, clickjacking, and a critical RCE.
- Maintained a 480+ day TryHackMe streak while building open-source lab tooling such as BreakTheWeb-CTF.
Arsenal
Methodology, tooling, technical range
VAPT & Security Testing
Network VA/PTWeb App TestingAPI SecurityRisk ManagementResponsible Disclosure
OWASP & AppSec
OWASP Top 10Auth TestingBroken Access ControlIDORJWT SecurityBusiness Logic
Compliance & Cloud
PCI DSSASV ScanningAzure ReviewGCP ReviewSegmentation Testing
Tooling
Burp SuiteOWASP ZAPNmapNessusNucleiFFUFSQLMapMetasploitWireshark
Recon & Scripting
Subdomain EnumOSINTAttack Surface MappingPythonBashClaude Code
Selected disclosures
Withheld where programme policy requires
iAudit GlobalAccount takeover via broken session logicAcknowledged
TwentyOneMissing re-authentication for sensitive functionalityAcknowledged
SocialClimate.techClickjacking on account settingsAcknowledged
DevslyVerified Hall of Fame disclosureAcknowledged
LumiListCertificate of appreciation for responsible disclosureAcknowledged
TrekMail · HobbyDB · Essential Energy · IsoMate · CompletionKit · SiteConnect · HelloAeternaMultiple responsible disclosures across programmesAcknowledged
Confidential ProgrammeCritical remote code executionAcknowledged
Bugcrowd10 Hall of Fame credits across managed programmesAcknowledged
Self-hosted VDPs12+ Hall of Fame credits across independently run disclosure pagesAcknowledged
Employer-side3 Letters of Recognition for securing company systemsRecognised
32+ Hall of Fame credits in total — 10 via Bugcrowd, 12+ across self-hosted VDPs, the rest through independent bounty programmes. Ranked Top 3% globally on TryHackMe (480+ day streak, 140+ labs) and solved 5+ Hack The Box machines. Received a $25 reward for one disclosure and a separate monetary bounty in August 2026.
Projects
Tooling built for offense, defense, and training
Credentials
Certifications
- eJPT — Junior Penetration TesterIn progress
- OSCP — Offensive Security Certified ProfessionalIn progress
- CREST CTF 2026Participation
- Cybersecurity Job Simulation — DeloitteComplete
- Security Hall of Fame — DevslyComplete
- Advent of Cyber 2025 — TryHackMeComplete
- Junior Cybersecurity Analyst — CiscoComplete
- Introduction to Cybersecurity — CiscoComplete
- Claude 101 & Claude Code 101 — Anthropic AcademyComplete
Education
-
Master of Computer Applications (MCA)
Dr. Babasaheb Ambedkar Marathwada University, Aurangabad
Aug 2025 — May 2027
-
Bachelor of Computer Applications (BCA)
Deogiri College, Aurangabad
Jul 2022 — Apr 2025