profile-pic

Arpan Dasgupta

A detail-oriented and analytical professional, committed to delivering high-quality results through evaluation and continuous improvemen, targeting challenging assignments as Penetration Tester with a reputed organization.
  • Role

    Product Application Security Engineer

  • Years of Experience

    7 years

Skillsets

  • OpenVAS
  • Web penetration
  • Thunderhead
  • Spring
  • Selenium
  • Postman
  • Parrot linux
  • OWASP ZAP
  • Oracle Database
  • VAPT - 5.0 Years
  • Nessus
  • Metasploit
  • Kali Linux
  • JMeter
  • Java
  • C++
  • Burp Suite
  • Api penetration

Professional Summary

7Years
  • Nov, 2023 - Present2 yr 4 months

    Product Application Security Engineer

    Smart Energy Water
  • Jul, 2023 - Nov, 2023 4 months

    Security Consultant

    Netrika
  • May, 2019 - Jun, 20234 yr 1 month

    Penetration Tester

    TCS

Work History

7Years

Product Application Security Engineer

Smart Energy Water
Nov, 2023 - Present2 yr 4 months
    Executing in-depth penetration testing on mobile and web applications, identifying security gaps and recommending corrective actions. Conducting API security assessments, focusing on vulnerabilities in authentication, data handling, and access controls to secure essential services. Directing network security evaluations, performing internal and external penetration tests to uncover misconfigurations and attack vectors. Simulating advanced cyber-attacks, including privilege escalation, SQL injection, and buffer overflows, to assess system resilience. Producing comprehensive vulnerability reports with actionable remediation steps, aligned with OWASP, NIST, and CIS standards. Presented findings, risks, and conclusions to management and relevant stakeholders to ensure informed decision-making. Assessed the potential impact of security breaches on business operations and user experience, aligning recommendations with business objectives. Analyzed vulnerabilities that could disrupt business functions if left unaddressed, emphasized the importance of timely remediation. Conducted training sessions for users to mitigate future security risks and enhance overall cybersecurity awareness.

Security Consultant

Netrika
Jul, 2023 - Nov, 2023 4 months
    Performed ethical hacking to expose weaknesses such as SQL Injection, Cross-Site Scripting (XSS), Broken Authentication, and XML External Entity (XXE) attacks across applications and infrastructure. Led network security scans, analyzing configurations to highlight potential security threats. Interpreted data from network logs and packet captures to identify patterns indicative of potential breaches. Developed recommendations for security enhancements and implemented fixes based on test outcomes. Communicated findings to stakeholders with clear, non-technical documentation. Utilized automated testing technologies including Nessus and OpenVAS.

Penetration Tester

TCS
May, 2019 - Jun, 20234 yr 1 month
    Supported major clients such as Phoenix Life and Aviva, tailoring system solutions to meet their needs. Assisted in product development and customization based on client requirements. Managed deployment requests and implemented changes within the system. Resolved technical issues promptly, ensuring smooth operations and client satisfaction.

Major Projects

1Projects

(8-Day Project)

    Conducted market research and gathered business requirements to understand market trends and challenges. Designed and implemented system architecture to address identified challenges and deliver a functional solution. Employed programming languages, development frameworks, and database systems to successfully build the project.

Education

  • B.Tech. in Electrical Engineering

    KIIT University (2019)
  • 12th

    DAV Public School (2015)
  • 10th

    DAV Public School (2013)

Certifications

  • Certified ethical hacker (ceh)

  • Website hacking and penetration testing

  • Ethical hacking with metasploit