S.D.J.

Junior VAPT Analyst · Pune, India

Soham
D. Jadhav

Network & web application penetration testing, compliance and risk management. Currently at Capgemini — independently recognised with 32+ Hall of Fame credits across Bugcrowd, self-hosted VDPs, and public bounty programmes.

Soham D. Jadhav
0Disclosed
0TryHackMe
0Day Streak
0Hall of Fame

Experience

Junior VAPT Analyst

Capgemini, Pune

  • Perform internal and external network VA/PT, including asset discovery, segmentation scans, and firewall rule set reviews.
  • Conduct compliance/PCI-driven ASV scans and cloud configuration reviews on Azure and GCP.
  • Run web application penetration tests using black box and grey box methodologies — 40–60+ vulnerabilities identified per assessment cycle.
  • Own the complete WAPT lifecycle end to end, from scanning through validation to client report.

Cybersecurity Researcher

Independent — Bug Bounty / VDP Programmes

  • Web application and API security testing across public VDP/BBP programmes using Burp Suite, Nmap, SQLMap, and Dirsearch.
  • 30+ vulnerabilities discovered and responsibly disclosed, including SQL injection, XSS, IDOR, account takeover, clickjacking, and a critical RCE.
  • Maintained a 480+ day TryHackMe streak while building open-source lab tooling such as BreakTheWeb-CTF.

Arsenal

Methodology, tooling, technical range

VAPT & Security Testing

Network VA/PTWeb App TestingAPI SecurityRisk ManagementResponsible Disclosure

OWASP & AppSec

OWASP Top 10Auth TestingBroken Access ControlIDORJWT SecurityBusiness Logic

Compliance & Cloud

PCI DSSASV ScanningAzure ReviewGCP ReviewSegmentation Testing

Tooling

Burp SuiteOWASP ZAPNmapNessusNucleiFFUFSQLMapMetasploitWireshark

Recon & Scripting

Subdomain EnumOSINTAttack Surface MappingPythonBashClaude Code

Selected disclosures

Withheld where programme policy requires
iAudit GlobalAccount takeover via broken session logicAcknowledged
TwentyOneMissing re-authentication for sensitive functionalityAcknowledged
SocialClimate.techClickjacking on account settingsAcknowledged
DevslyVerified Hall of Fame disclosureAcknowledged
LumiListCertificate of appreciation for responsible disclosureAcknowledged
TrekMail · HobbyDB · Essential Energy · IsoMate · CompletionKit · SiteConnect · HelloAeternaMultiple responsible disclosures across programmesAcknowledged
Confidential ProgrammeCritical remote code executionAcknowledged
Bugcrowd10 Hall of Fame credits across managed programmesAcknowledged
Self-hosted VDPs12+ Hall of Fame credits across independently run disclosure pagesAcknowledged
Employer-side3 Letters of Recognition for securing company systemsRecognised

32+ Hall of Fame credits in total — 10 via Bugcrowd, 12+ across self-hosted VDPs, the rest through independent bounty programmes. Ranked Top 3% globally on TryHackMe (480+ day streak, 140+ labs) and solved 5+ Hack The Box machines. Received a $25 reward for one disclosure and a separate monetary bounty in August 2026.

Projects

Tooling built for offense, defense, and training

Credentials

Certifications

  • eJPT — Junior Penetration TesterIn progress
  • OSCP — Offensive Security Certified ProfessionalIn progress
  • CREST CTF 2026Participation
  • Cybersecurity Job Simulation — DeloitteComplete
  • Security Hall of Fame — DevslyComplete
  • Advent of Cyber 2025 — TryHackMeComplete
  • Junior Cybersecurity Analyst — CiscoComplete
  • Introduction to Cybersecurity — CiscoComplete
  • Claude 101 & Claude Code 101 — Anthropic AcademyComplete

Education

  • Master of Computer Applications (MCA) Dr. Babasaheb Ambedkar Marathwada University, Aurangabad Aug 2025 — May 2027
  • Bachelor of Computer Applications (BCA) Deogiri College, Aurangabad Jul 2022 — Apr 2025

Got something that needs testing?

Open to VAPT engagements, research collaboration, and full-time offensive security roles.