Skip to main content

Command Palette

Search for a command to run...

About me

I am Indrayan Sanyal a dedicated Cyber Security Professional with over 4+ years of hands-on experience in identifying, analyzing, and mitigating security vulnerabilities across web, mobile, and enterprise applications. My expertise lies in delivering end-to-end application security assessments, enabling organizations to strengthen their security posture and safeguard critical digital assets.

Throughout my professional journey, I have built a strong foundation in multiple domains of application security, combining automated tools with deep manual testing methodologies to uncover complex vulnerabilities that often evade standard scans.

Core Expertise

Dynamic and Static Application Security Testing (DAST/SAST)
I have performed comprehensive DAST and SAST assessments using both automated scanners and manual validation techniques. My work includes secure code reviews across multiple programming languages such as Java, PHP, Python, .NET, and C++, allowing me to identify logic flaws, insecure coding practices, and exploitable weaknesses early in the SDLC.

Web & Mobile Application Penetration Testing
I have successfully conducted penetration testing for 100+ web applications across diverse sectors including banking, healthcare, and education. My assessments follow industry standards such as OWASP, covering vulnerabilities like authentication flaws, injection attacks, business logic issues, and misconfigurations.
In mobile security, I have tested both Android and iOS platforms, performing static analysis, dynamic testing, traffic interception, and reverse engineering to ensure comprehensive coverage.

API Penetration Testing
I possess strong experience in securing REST and SOAP APIs. Using tools such as Postman, SoapUI, Insomnia, and Swagger, I configure test environments, manipulate requests, validate authentication mechanisms, and identify issues such as broken authorization, injection, and data exposure, while providing clear remediation guidance.

Software Composition Analysis (SCA)
I have worked extensively with SCA tools including BlackDuck, Checkmarx, and OWASP Dependency-Check to detect vulnerable open-source components. My responsibilities include manual triaging of findings, validating exploitability, and delivering detailed upgrade and mitigation recommendations aligned with business risk.

Threat Modeling
I am proficient in identifying architectural risks through structured threat modeling exercises. I collaborate closely with development and service teams to analyze attack surfaces, prioritize threats, and implement effective security controls, ensuring vulnerabilities are addressed proactively rather than reactively.

Professional Strengths

  • Strong understanding of OWASP Top 10 & secure coding practices

  • Balance of automated scanning and deep manual testing

  • Clear, developer-friendly vulnerability reporting

  • Risk-based prioritization and remediation guidance

  • Cross-functional collaboration with Dev, QA, and Ops teams