Rahul Mandal.

Application Security Engineer/VAPT & Red Team/Secure SDLC & DevSecOps

I help product and platform teams ship securely. Over 4+ years delivering enterprise-grade assessments across web, API, mobile, thick-client, network, and cloud - paired with SAST/DAST tooling, secure code review, and red-team simulation aligned to OWASP and MITRE ATT&CK.

Aligned toOWASP Top 10MITRE ATT&CKSecure SDLCDevSecOps
scroll
0+
Years in Security
0
Assessment Types
0
Cloud Platforms
0
Frameworks & Standards
0+
Years in Full-Stack
Experience

From building software to breaking it on purpose.

Three roles, one continuous thread - the path from full-stack development into application security.

April 2022 - April 2026

Security Analyst II

Strobes SecurityRemotely · Hyderabad, India

Lead technical contributor on client-facing security engagements across application, infrastructure, and cloud surfaces.

  • Delivered enterprise-grade assessments across web, mobile, API, and thick-client environments aligned with OWASP
  • Managed engagements end-to-end — scoping, execution, remediation — translating findings into business risk for executives
  • Conducted secure code reviews with developer-friendly remediation aligned to Secure SDLC
  • Integrated SAST/DAST tooling into GitHub Actions and GitLab CI pipelines
  • Performed cloud configuration audits across AWS, Azure, and GCP — IAM gaps, misconfigurations, compliance
  • Executed red-team and adversary-simulation assessments, presenting findings to leadership
Stack
Burp SuiteNmapMetasploitWiresharkAWSAzureGCPPythonOWASP TOP 10MITRE ATT&CK
February 2022 - March 2022

Research Intern - Cyber Security

Internship
SISTMR AustraliaVirtual · In association with VPKBIET, Baramati
Best Award — SISTMR Australia

Two-month Virtual Cyber Security Industry Internship that formalised my transition from full-stack development into application and offensive security.

  • Completed the Virtual Cyber Security Industry Internship program in association with VPKBIET, Baramati
  • Researched real-world attack surfaces, reconnaissance techniques, and exploitation primitives
  • Produced structured technical write-ups translating research into reproducible findings
Stack
Cyber SecurityResearchReconnaissanceExploitationTechnical Writing
June 2019 - October 2021

Associate UI Engineer

DIPCAhmedabad, India

Built user-facing and backend components for internal and public-facing platforms - gaining the systems intuition I now apply to security review.

  • Developed and deployed user-facing and backend components for internal and public platforms
  • Gained hands-on experience with web servers, application servers, and XML/SOAP integrations
  • Set up and configured development and production environments on Windows and Linux
  • Worked with relational databases for application data layers and schema changes
  • Collaborated with UI/UX, QA, and backend teams on responsive, accessible applications
  • Documented system designs, integration patterns, and deployment procedures for onboarding
Stack
MERN StackHTMLJavaScriptMySQLLinuxWindows Server
Certifications & Learning

Continuous study, deliberate breadth.

In Progress
AI / LLM Security

OSAI+ - Advanced AI Red Teaming

Specialised certification focused on offensive and defensive security for AI-integrated applications, prompt injection, and LLM supply-chain risk.

OffSecoffsec.com
Completed
Offensive Security

Penetration Testing Essential Training

Foundational penetration testing methodology, exploitation primitives, and structured engagement workflow.

LinkedIn Learninglinkedin.com
Completed
Ethical Hacking

Practical Ethical Hacking Course

Hands-on training across reconnaissance, exploitation, privilege escalation, and reporting against realistic targets.

Udemyudemy.com
Completed
Networking

Complete Networking Fundamentals

TCP/IP, routing, switching, and the underlying network primitives that every network and infrastructure assessment depends on.

Udemyudemy.com
Contact

Let's get in touch.

Open to security engagements, advisory work, and full-time roles. Send a message below or connect with me on LinkedIn.

Reach me directly

Message me through the form, or use a direct channel — whatever is easiest for you.

Send a message

I typically respond within 24–48 hours.