Open to Product Security roles · Chennai, Tamil Nadu — IN

BHARATH
J.

> PRODUCT SECURITY ENGINEER · Application Security · Offensive Security · Bug Bounty Hunter

I break enterprise apps before attackers do — auditing web, API and Android surfaces, chaining logic flaws into critical impact, and automating the boring parts of the SDLC.

0+
Apps Assessed
0+
Vulns Validated
0+ yr
AppSec Experience
0
Bug Bounty Since
bharath@sec-ops:~◉ REC
$
Focus
Product · AppSec · Offensive
Signal
150+ Vulns Validated
VAPTAPI SECURITYMOBILE VAPTOAUTH2 / OIDCIDOR / BOLABUG BOUNTYEASMTHREAT INTELAUTOMATIONSECURE DESIGNVAPTAPI SECURITYMOBILE VAPTOAUTH2 / OIDCIDOR / BOLABUG BOUNTYEASMTHREAT INTELAUTOMATIONSECURE DESIGN
// 01 · About

Operator profile.

Application / Product Security Engineer with 1+ years of hands-on VAPT across web apps, REST APIs and Android — 50+ enterprise apps assessed and 150+ vulnerabilities validated. Skilled in manual testing of authentication, authorization (BOLA/IDOR), business logic and secure configuration, with working exposure to OWASP Top 10, OWASP API Top 10, OAuth2 / OIDC and JWT / session security.

I run mobile security testing with Frida and MobSF, drive External Attack Surface Management, and build Python + Power Automate pipelines that streamline security testing and threat-intelligence workflows. I partner with engineering to validate remediation and push secure-by-design outcomes across the SDLC.

Active bug bounty researcher on HackerOne & Bugcrowd since 2021, with a track record of responsible disclosure across enterprise programs.

LOCATION
Chennai, Tamil Nadu — IN
ROLE
AppSec Engineer @ HTC
EDU
BCA Cyber Security · Hindustan U
PURSUING
MCA · Anna University
CGPA
8.98
AVAILABILITY
Open to opportunities

Break early. Fix it right.

Ship a threat model before the sprint, not after the incident. Every finding gets a re-test until the class of bug is dead.

Beyond the scanner.

Automated tools handle the noise. Business logic, authz chains and auth flows still need human intuition — that’s where I live.

Automate the boring.

Python + Power Automate turn CVE feeds, IOCs and re-tests into signal — so humans focus on the interesting bugs.

// Journey

2021
First bug bounty submission · HackerOne
2022
First responsible disclosure acknowledgements from enterprise programs
2023
Deep dive into API security, OAuth2 & JWT internals
2025
BCA Cyber Security · Hindustan University (CGPA 8.98)
2025
Application Security Engineer @ HTC Global Services
2026
150+ validated vulns · critical ATO & SQLi in production
2027
MCA in progress · BSCP & eMAPT targeted
// 02 · Arsenal

Skills & tradecraft.

Six domains, one operator. Manual depth first — automation to make it repeatable.

Application & Product Security

Web App VAPTREST API SecurityAndroid VAPTBusiness Logic TestingAuth & Authz TestingIDOR / BOLAAccount TakeoverSecure Design ReviewExternal Attack Surface ManagementSecure Configuration Review

Standards & Frameworks

OWASP Top 10OWASP API Top 10OWASP MASVS / MSTGOAuth2 / OIDCJWT & Session SecurityThreat Modeling

Vulnerability Classes

SQLiXSSCSRFSSRFBroken Access ControlBroken AuthenticationBusiness Logic FlawsRate-Limit BypassSecurity Misconfiguration

Tools & Tradecraft

Burp Suite ProMobSFFridaPostmanNmapSQLMapFFUFHTTPXAmassSubfinderFeroxbuster

Programming & Automation

PythonBashJavaScriptNode.jsPower AutomateGitDockerAPI Automation

Platforms & DevSecOps

Kali LinuxUbuntuWindows / WSLDockerSAST / DAST / SCA (concept)Secret ScanningIaC Security (growing)

Certifications

SysGroup
Certified AppSec Practitioner
Earned
TryHackMe
Certified Penetration Tester
Earned
Cisco
Networking Essentials
Earned
NDG
Linux Essentials
Earned
Sumo Logic
Sumo Logic Fundamentals
Earned
Cisco
Computer Hardware
Earned
PortSwigger
Burp Suite Certified Practitioner
In Progress · Q4 2026
INE Security
eMAPT — Mobile App Pentester
In Progress
// 03 · Field Ops

Experience.

Jul 2025 — Present

Application Security Engineer

HTC Global Services
Chennai, IN
Impact
150+ vulnerabilities validated across 50+ enterprise apps
  • End-to-end manual VAPT on 50+ web apps, REST APIs, Android apps and internal platforms — 150+ validated findings.
  • Discovered critical Account Takeover on an enterprise recruitment platform and vertical privilege escalation to C-level accounts.
  • Reported production SQL Injection and broken access control chains with executive-level impact.
  • Continuous EASM identified a high-risk exposed asset later confirmed in a ransomware compromise — escalated in time.
  • Built Python + Power Automate pipelines for zero-day CVE feeds, IOC tracking and API testing utilities.
  • Partnered with dev + infra teams to validate remediation and drive secure-by-design outcomes across the SDLC.
Burp Suite ProMobSFFridaPythonPower AutomateNmapSQLMap
2021 — Present

Independent Security Researcher

HackerOne · Bugcrowd
Remote
Impact
Responsible disclosure · 4+ years of bug bounty research
  • Independent research and responsible disclosure focused on web / API auth, authz and business logic flaws.
  • Recognized by multiple enterprise programs for responsible vulnerability disclosure.
  • Publishes technical write-ups on Linux internals, CORS, browser + API security.
ReconBurp SuiteCustom Python ToolingOSINT
// 04 · Payloads

Projects.

Selected offensive, blue-team and product-security work — problem, solution and outcome.

Offensive · Automation

Offensive Security Automation Toolkit

Problem
Manual API enumeration, request tampering and reporting were eating hours of every engagement.
Solution
Modular Python + Bash utilities for API enumeration, HTTP request manipulation, security data parsing and report generation.
Outcome
Cut per-engagement manual effort dramatically; reused across every assessment cycle.
PythonBashBurp APIRequests
Blue Team · Automation

Threat Intelligence & Security Automation

Problem
CVE feeds, IOCs and zero-day alerts were scattered across mailing lists and dashboards.
Solution
Power Automate workflows continuously ingest zero-day intel, CVE feeds, IOCs and ops notifications into a single daily brief.
Outcome
Turned raw intel noise into an actionable daily signal for the security team.
Power AutomateREST APIsCVE Feeds
Product · IoT Security

DefIOT — IoT Security Platform

Problem
Testing vulnerable IoT devices at scale required a repeatable lab and reporting harness.
Solution
Cross-platform app that simulates vulnerable IoT devices, orchestrates Nmap-based assessments and generates detailed vuln reports.
Outcome
One-click IoT recon + reporting — from device fingerprint to writable report.
FlutterFastAPISQLiteNmap
Recon · EASM

EASM Recon Pipeline

Problem
Shadow assets and exposed credentials keep appearing outside the traditional perimeter.
Solution
Continuous external attack-surface monitor combining Amass, Subfinder, HTTPX and custom scoring to surface high-risk exposure.
Outcome
Flagged an external exposure later confirmed compromised in a ransomware incident.
AmassSubfinderHTTPXPython
// 05 · Dossier

Resume.

The full brief — preview inline, download the PDF, or hit print.

Bharath_J_Resume.pdfREADY
Preview unavailable. Download the PDF.

Career snapshot

  • • AppSec Engineer at HTC Global Services (2025 → present)
  • • 50+ enterprise apps · 150+ validated vulnerabilities
  • • Critical ATO, SQLi and C-level privilege escalation
  • • Python + Power Automate threat-intel pipelines
  • • Bug bounty researcher since 2021 · responsible disclosure

Skills snapshot

Web VAPTAPI SecurityAndroid VAPTOWASPOAuth2/OIDCJWTIDOR/BOLABusiness LogicEASMBurp SuiteMobSFFridaPythonPower AutomateDocker
// 06 · Transmission

Cover letter.

Introduction

A year deep in Application Security, I've built my career around finding real risk in web apps, REST APIs and Android surfaces — and shipping fixes with the engineering teams that own them.

Mission
Ship products customers can trust — from threat model to production.
Strengths
Manual VAPT · Auth / Authz · Business Logic · Automation · EASM
Signal
150+ validated vulns · Critical ATO · Responsible disclosure
Excerpt

“The Product Security role extends beyond traditional penetration testing. The emphasis on secure design, API security, mobile security, automation and integrating security throughout the SDLCclosely matches both my current experience and the direction I want to grow professionally.”

Alongside manual testing, I build Python utilities and Power Automate workflows that streamline threat intelligence, vulnerability management and API testing — and I run continuous EASM to catch exposure before it becomes an incident.

// 07 · Signal

Achievements.

0+
Enterprise Apps Assessed
0+
Vulnerabilities Validated
0
Production Critical Bugs
0+ yrs
Bug Bounty Research
0+
Certifications Earned
0+
Automation Pipelines Built
0
Published Projects
0
Researching Since
// 08 · Feed

Writing & research.

Live feed from bharath.medium.com — research, write-ups and notes.

// 09 · Handshake

Let's talk.

Recruiting, security partnerships or a quick question — the fastest way in.