V
vvek's photo
Vivek Ghinaiya
From India 07:13 PM (GMT+05:30)
$18/hr or $35,000/yr

Active over a week ago


Member since Mar 2026

Share this profile:

Application Security Engineer

Cybersecurity Engineer
Available for hire
Years of experience
4+ years
Experience level
Mid-level
Available for
Full-time
Available from
22 Aug 2026
Download Resume / CV

I've been in cybersecurity for about 4 years now and it started with a simple obsession — I just wanted to know how things break. That curiosity turned into a career where I've done penetration testing across web, API, mobile, and cloud environments, slowly picking up red teaming, security automation, and compliance work along the way.Along the way I've identified 300+ vulnerabilities across different clients and environments which taught me that finding issues is only half the job. Helping teams actually fix them, understand why they happened, and build better habits going forward — that's where the real impact is.

Right now I'm the lead security person at my company which means I own everything from threat modeling and SIEM monitoring to running red team exercises, phishing simulations, and incident response. I've also supported full ISO 27001 ISMS implementation which gave me a solid appreciation for the governance and compliance side of security.Outside of work I'm active on HackerOne, Bugcrowd, and TryHackMe which honestly just keeps me sharp and connected to how real attackers think and operate.

I'm looking for a role where I can keep growing across the full security spectrum whether that's deep technical penetration testing, building out secure DevSecOps pipelines, or leading red team engagements. I want to be somewhere that values both the offensive and defensive sides of security and where I can bring my whole skill set to the table every day.

Skills

No skills.

Languages

Employment History

Security Engineer at FYNXT Current 2025 - Now
Penetration Testing — Hands-on pentesting across web, API, networks, Docker, and Kubernetes to find and fix critical vulnerabilities. Automation & Tooling — Built custom Python and Bash scripts to automate vulnerability detection and streamline CI/CD security assessments. Threat Modeling — Performed STRIDE-based threat modeling and risk analysis during application design and architecture reviews. SIEM & Alerting — Monitored and triaged daily security alerts via Wazuh SIEM ensuring rapid incident validation and response. Secure SDLC — Integrated SAST, SCA, and DAST into CI/CD pipelines to catch security issues before they hit production. VAPT Reporting — Led full VAPT cycles with detailed risk-classified reports, remediation guidance, and vulnerability tracking. Incident Response — Served as primary incident response contact — identifying, validating, and coordinating remediation across the org. Security Awareness — Ran phishing campaigns, security simulations, and training sessions to strengthen the human layer of defence. Security Architecture — Designed and reviewed cybersecurity architectures aligning security controls with organisational risk tolerance. Threat Intelligence — Created internal threat intelligence reports analysing attack trends and indicators of compromise. ISMS Audits — Supported internal and external ISMS audits, maintaining records and reporting performance metrics to management. Red Teaming — Led red team exercises including social engineering and physical security testing to evaluate organisational resilience. ISO 27001 — Drove ISO/IEC 27001 implementation covering risk assessment, Annex A control mapping, and audit remediation.
Senior Security Analyst at SecIq Technology 2022 - 2025
Conduct web, API, and Android penetration tests to identify and remediate vulnerabilities. • Provide security consulting to global clients, ensuring compliance with best practices. • Perform SCA, SAST, DAST, and cloud security assessments for data protection. • Develop secure coding guidelines and train teams on integrating security into SDLC. • Addressed over 300+ vulnerabilities, contributing to improved product security. • Collaborated with cross-functional teams to enhance cybersecurity awareness. • Performed cloud security assessments to ensure the safety and security of client data in the cloud. • Executed comprehensive network security assessments to uncover critical weaknesses. • Created detailed vulnerability reports with actionable remediation plans. • Conducted workshops on secure development practices, boosting team security capabilities.

Education

No education history.