Securing Technology,Empowering Innovation.
Hi, I'm Sidharth Arora, a Security Engineer helping organisations ship safer software through modern Application Security, VAPT, and AI Security practices.

A quiet obsession with secure software.
I'm a Security Engineer with 2.5+ years of experience working on Application Security and offensive testing. My work connects hands on exploitation with the process that turns findings into fixes.
I've performed penetration testing across 30+ high end web applications, including customer-facing platforms, banking gateways serving 50,000+ users globally.
I assess web applications and APIs following OWASP Top 10 standards covering injection, broken access control, authentication, SQL command injection, broken access control, authentication and session flaws, insecure deserialisation, CSRF and SSRF using Burp Suite and OWASP ZAP. I go beyond automated findings to chase business logic abuse, social engineering, privilege escalation, and multi-step attack chains that link low-severity issues into critical compromise.
Beyond exploitation, I own the full remediation lifecycle: tracking issues through JIRA, monitoring SLA compliance to keep fixes on schedule, and partnering with developers on practical, low-friction remediations. I build Power BI dashboards to give management real-time visibility into risk posture, open findings, and remediation progress, turning technical findings into decisions leadership can act on. I'm increasingly drawn to AI Security, LLM vulnerabilities, prompt injection, and the new threat surface of intelligent systems.
I'm actively expanding my scope into AI Security , integrating my current workflows with AI-driven tooling, and building expertise in LLM security and compliance, including prompt injection and the emerging threat surface of intelligent systems.
A journey shaped by curiosity & craft.
From engineering foundations to hands-on offensive security, building a career around securing systems, not just applications.
Associate Application Security Analyst
- Perform Vulnerability Assessment and Penetration Testing (VAPT)
- Conduct Web Application Security Assessments
- Identify, validate, and triage application security vulnerabilities
- Partner with engineering teams on remediation and re-testing
- Assess applications against OWASP Top 10 risks
- Drive security testing using Burp Suite and OWASP ZAP
- Prepare technical and executive security assessment reports
Cybersecurity Intern
- Learned hands-on web application security testing fundamentals
- Gained practical experience with Burp Suite and OWASP ZAP
- Explored Dynamic Application Security Testing (DAST) workflows
- Supported vulnerability identification and reporting processes
B.E. Electronics & Communication Engineering
How I can help you and your team.
A complete security lifecycle, from scoping and testing to reporting, remediation and executive dashboards.
Security Assessment
Scope review, architecture analysis and security planning.
- Scope document
- Threat model
- Test plan
An interactive security knowledge map.
End-to-end offensive testing and secure design review across modern web applications, identifying exploitable flaws, validating fixes, and embedding security practices throughout the development lifecycle
Let's build secure digital experiences.
Open to security engagements, collaborations, and meaningful conversations about AppSec and AI security.