Security Researcher & Bug Bounty Hunter

Rohit Sharma

Offensive Security professional specializing in Web, API, Mobile, and Network Security with 500+ vulnerabilities reported and 70+ pentests delivered.

Professional Profile

Cyber Security Analyst with 4+ years of specialized experience in bug bounty and professional pentesting. Specialized expertise across web, API, mobile, infrastructure, and custom phishing assessments.

400+

Penetration Tests

1500+

Vulnerabilities Identified

Recognized By

Apple (11x)

+ NVIDIA, RedHat, SAP

Published

2 CVEs

CVE-2022-3774, 2023-5302

About Me

I'm a Cyber Security Analyst focused on offensive security and continuous improvement. I conduct VAPT with an emphasis on black-box testing and exploit development to uncover critical vulnerabilities. With 4+ years of experience, I've reported 500+ vulnerabilities and completed 70+ professional pentest engagements, helping teams reduce misconfigurations and strengthen security posture across web, mobile, APIs, and networks.

Vulnerabilities Identified

1500+

Critical to informational

Penetration Tests

400+

Web, mobile, infrastructure

Industry Recognition

50+

Hall of Fame acknowledgments

Experience

  1. R

    Security Analyst — Breachlock

    • Pentesting across web, API, thick client, Android/iOS, and internal/external networks.
    • PCI DSS testing, phishing assessments, OSINT, and Microsoft 365 reviews.
    • Cloud audits on Azure, AWS, GCP, O365; streamlined PTaaS workflows and remediation tracking.
    • Mentored junior analysts on methodologies and exploitation techniques.
  2. A

    Security Analyst Trainee — Appzlogic

    • Led SAST/DAST and VAPT across web and API applications; authored security test cases.
    • Manually found 120+ vulnerabilities across 14+ pentests; improved client awareness.
  3. F

    Freelance Cyber Security Analyst — Various

    • Reduced vulnerabilities for clients by 30% through detailed reporting and VAPT.
    • Secured a proprietary trading platform handling $3.7M+ weekly payouts.
    • Specialized in OWASP Top Ten; contributed to security research with payouts.
  4. I

    Cyber Security Summer Intern — Cyber Cell

    • Assisted in investigations and incident response; conducted forensics and OSINT.
    • Created checklists, guidance for public security hygiene, and authored reports.
  5. B

    Bug Bounty & CVEs

    • Apple Inc. Hall of Fame (10x) through April 2024.
    • Nvidia Hall of Fame (Oct 2022); RedHat acknowledgment (Jul 2022); Lenovo InfoSec (May 2022).
    • Published CVEs: CVE-2022-3774, CVE-2023-5302.

Technical Skills & Expertise

Web Pentesting
  • OWASP Top 10
  • SAST/DAST
  • Secure Code Review
Mobile Security
  • iOS / Android
  • OWASP MSTG
  • Binary Analysis
API Security
  • REST / SOAP
  • AuthN/AuthZ
  • Scope Validation
Network & Thick Client
  • Internal/External
  • Threat Modeling
  • Privilege Escalation
Cloud & Compliance
  • AWS / Azure / GCP
  • O365
  • PCI DSS
Ops & Reporting
  • SIEM Awareness
  • VAPT Reporting
  • PTaaS Workflows
Expertise Proficiency

Based on 400+ completed assessments

Security Services for Companies

Comprehensive penetration testing and security assessments tailored to strengthen your organization's security posture. Leveraging 400+ pentests and identification of 1500+ vulnerabilities across enterprises.

Custom Phishing Assessment Services

Specialized in creating and deploying targeted phishing campaigns for internal security testing and employee education. My custom email templates are designed to realistically simulate threats while providing valuable insights into your organization's security awareness.

Email Template Design

Custom-crafted templates mimicking real-world phishing scenarios, credential harvesting, and social engineering tactics

Campaign Management

End-to-end phishing simulation with user tracking, detailed reporting, and follow-up security training recommendations

Web & Network Testing

• Black/gray box VAPT

• OWASP Top 10 assessment

• Privilege escalation

• Remediation guidance

Mobile & Thick Client

• iOS & Android testing

• OWASP MSTG compliance

• Secure storage audit

• Runtime protection checks

Cloud & Compliance

• Microsoft 365 audit

• AWS, Azure, GCP review

• Identity hardening

• Incident readiness

Scoping & Validation

• Scope validation

• Testing strategy

• Risk prioritization

• Compliance alignment

Resume & Credentials

Resume.pdf

Rohit Sharma - Security Analyst

View or download my comprehensive resume featuring my experience, skills, certifications, and professional achievements in cybersecurity.

Download PDF

Hall of Fame

50+ Security Acknowledgments

Recognized by leading organizations worldwide for responsible security disclosure

Apple Inc.

11 Times

July 2021 - July 2024

Multiple security acknowledgments across iOS, macOS, and web services

NVIDIA

Hall of Fame

Oct 2022

Graphics and AI platform security

RedHat Inc.

Hall of Fame

Jul 2022

Enterprise Linux and cloud security

SAP

Hall of Fame

Jun 2023

Enterprise software security

Lenovo

Hall of Fame

May 2022

Hardware and firmware security

Trend Micro

Hall of Fame

Jun 2022

Cybersecurity platform vulnerabilities

Duke University

Acknowledgment

Apr 2022

Academic infrastructure security

Drexel University

Acknowledgment

Sep 2022

Educational platform security

University of Turku

Acknowledgment

Feb 2023

Research system security

University of Houston

Acknowledgment

2022

Campus network security

Caterpillar Inc.

Hall of Fame

Sep 2022

Industrial equipment security

Michelin

Hall of Fame

Apr 2022

Automotive platform security

Ericsson

Hall of Fame

Jun 2021

Telecommunications security

Deutsche Telekom

Hall of Fame

May 2021

Network infrastructure security

Vodafone

Hall of Fame

Sep 2021

Mobile network security

Renault Group

Hall of Fame

Nov 2021

Automotive systems security

OSS.GG Hackathon

Recognition 2024

Oct 2024

Open-source security bug identification and reporting

NCIIPC India

Government Recognition

Mar 2021

Critical infrastructure vulnerability disclosure

Published CVEs

CVE-2022-3774

Security vulnerability disclosure

CVE-2023-5302

Coordinated vulnerability disclosure

Achievements & Recognition

Hall of Fame acknowledgments and security contributions across global organizations.
Apple logo
Nvidia logo
RedHat logo
Lenovo logo
Drexel logo
More logo
Published CVEs
  • CVE-2022-3774

    Vulnerability disclosure and remediation guidance

  • CVE-2023-5302

    Coordinated disclosure improving ecosystem security

Let's Connect

Open to security consulting, pentesting, and research collaborations. Reach out on LinkedIn for the fastest response.

Send a Message
Connect on LinkedIn

For the fastest response and professional inquiries, connect with me on LinkedIn. I'm actively looking for security consulting opportunities and collaboration.

Built with v0