Available for security engagements

Securing Technology,Empowering Innovation.

Hi, I'm Sidharth Arora, a Security Engineer helping organisations ship safer software through modern Application Security, VAPT, and AI Security practices.

Focus
Application Security
VAPTAppSecAPIAI
Sidharth Arora
Currently at
Sage Publications
Associate Application Security Analyst
Web App SecurityVAPTOWASP Top 10API SecurityAI SecurityThreat ModelingSecure SDLCBurp SuiteWeb App SecurityVAPTOWASP Top 10API SecurityAI SecurityThreat ModelingSecure SDLCBurp Suite
About

A quiet obsession with secure software.

I'm a Security Engineer with 2.5+ years of experience working on Application Security and offensive testing. My work connects hands on exploitation with the process that turns findings into fixes.
I've performed penetration testing across 30+ high end web applications, including customer-facing platforms, banking gateways serving 50,000+ users globally. 

I assess web applications and APIs following OWASP Top 10 standards covering injection, broken access control, authentication,  SQL command injection, broken access control, authentication and session flaws, insecure deserialisation, CSRF and SSRF using Burp Suite and OWASP ZAP. I go beyond automated findings to chase business logic abuse, social engineering, privilege escalation, and multi-step attack chains that link low-severity issues into critical compromise.

Beyond exploitation, I own the full remediation lifecycle: tracking issues through JIRA, monitoring SLA compliance to keep fixes on schedule, and partnering with developers on practical, low-friction remediations. I build Power BI dashboards to give management real-time visibility into risk posture, open findings, and remediation progress,  turning technical findings into decisions leadership can act on. I'm increasingly drawn to AI Security, LLM vulnerabilities, prompt injection, and the new threat surface of intelligent systems.

I'm actively expanding my scope into AI Security , integrating my current workflows with AI-driven tooling, and building expertise in LLM security and compliance, including prompt injection and the emerging threat surface of intelligent systems.

Let's talk security
Experience

A journey shaped by curiosity & craft.

From engineering foundations to hands-on offensive security, building a career around securing systems, not just applications.

Associate Application Security Analyst 

Sage Publications
  • Perform Vulnerability Assessment and Penetration Testing (VAPT)
  • Conduct Web Application Security Assessments
  • Identify, validate, and triage application security vulnerabilities
  • Partner with engineering teams on remediation and re-testing
  • Assess applications against OWASP Top 10 risks
  • Drive security testing using Burp Suite and OWASP ZAP
  • Prepare technical and executive security assessment reports
Feb 2025 — Present

Cybersecurity Intern

Sage Publications
  • Learned hands-on web application security testing fundamentals
  • Gained practical experience with Burp Suite and OWASP ZAP
  • Explored Dynamic Application Security Testing (DAST) workflows
  • Supported vulnerability identification and reporting processes
Jan 2024 — Jan 2025

B.E. Electronics & Communication Engineering

Thapar Institute of Engineering and Technology
Graduated 2024
Engagement Pipeline

How I can help you and your team.

A complete security lifecycle, from scoping and testing to reporting, remediation and executive dashboards.

Stage 01 / 07

Security Assessment

Scope review, architecture analysis and security planning.

Overview
Understand the application's functionality, identify critical features, review authentication flows, and prepare the environment before performing Web Application and API penetration testing.
Outcome
A structured testing plan aligned with business risk that enables efficient vulnerability discovery across the application.
Tools used
Claude MCP · Burp Suite · ZAP Proxy · Developer tools
Deliverables
  • Scope document
  • Threat model
  • Test plan
Knowledge Map

An interactive security knowledge map.

EXPERTISE
Selected discipline
Application Security
Building security into the SDLC

End-to-end offensive testing and secure design review across modern web applications, identifying exploitable flaws, validating fixes, and embedding security practices throughout the development lifecycle

Key focus areas
VAPTReportingRemediation GuidanceIssue TrackingSLA Tracking+
Toolkit & methodologies
Burp SuiteZAP ProxyClaude MCP Power Bi
Related disciplines
Secure SDLCAPI SecurityOWASP
Click any node to switch the selected discipline.
Contact

Let's build secure digital experiences.

Open to security engagements, collaborations, and meaningful conversations about AppSec and AI security.

LinkedIn
/in/sidhartharora28
Live
Available
Open to new engagements & collabs