Rohit Agarwal
Contact No: +91-7504070201 E-Mail: agr_rohit@[Link]
Linkedin: [Link]
Aspiring to leverage my expertise in cybersecurity to protect organizational assets from emerging threats.
Committed to continuous learning and staying ahead of the curve in security technologies. My goal is to keep
learning while driving innovative solutions that safeguard information and inspire trust.
PROFILE SUMMARY
Overall, of 8 years of experience in Cyber Security Domain with in-depth knowledge in web, desktop and
mobile applications and API security assessment and penetration testing.
Expertise in exploiting application business logic manually.
Strong knowledge in threat profiling and preparing various test cases to exploit the application.
White and Black Box application security assessments.
Area of expertise includes Vulnerability assessments and Vulnerability Remediation Process.
Strong hold on various security guidelines and standards of OWASP TOP 10 and SANS TOP 25.
EMPLOYMENT DETAILS
1. Tata Consultancy Services (June 2016 – April 2019)
Cyber Security Analyst US 1. Performing Source Code review on Web Applications/APIs
based Healthcare Industry 2. Briefing application developers of the discovered Vulnerabilities
3. Formulating mitigation plans for the discovered vulnerabilities
4. Preparing assessment reports with vulnerability details and
tracking vulnerability fixes
TCS internal Dev Team 1. Development of Hacking platform php5
2. Development of Mobile apps using ionic and cordova
3. Development of Threat Modelling tool using Java / Spring
2. PwC (April 2019 – July 2019)
Cyber Security Analyst 1. Meeting with all stake-holders and determining the scope of
Leading Indian Bank vulnerability assessment.
2. Performing black-box testing on Various banking and HRMS
platforms
3. Assisting development teams in fixing the identified vulnerabilities.
4. Briefing bank’s management of the Risks of the vulnerabilities.
PwC Inhouse roles 1. Conducting sessions on Mobile application penetration testing
2. Conducting sessions on hands on usage of pentesting tools
3. Deloitte (September 2019 – July 2021)
DevSecOps Engineer 1. Active involvement with various Dev teams starting from the
Pioneer company in design phase of the product development.
virtualization technology 2. Performing Threat Modelling on the application architectures
3. Running White-Box analysis on Source code during the Dev phase.
4. Executing Manual source code review during Dev Phase.
5. Performing Grey Box Security Assessment on UAT deployments.
6. Creating Analysis reports on JIRA and Confluence.
7. Briefing Application Architects on potential risks of the identified
vulnerabilities.
8. Briefing Client Managers on latest trends of the vulnerabilities
across the applications
Deloitte Inhouse roles 1. Conducting sessions on various aspects of application security
2. Training interns on customer approach and technical aspects of
assessments
3. Working with Managers in drafting proposals for security
assessment of their products
4. Microsoft (July 2021 - Till Date)
Infosec Engineer END to END Product Security – Game development portal
Industry leader in Gaming 1. Performing Threat Modelling on the cloud Solution architectures
2. Working with architects to determine security loopholes.
3. Formulating test cases based on the threat model.
4. Aligning dev teams to implement security controls.
5. Conducting sprint to sprint code reviews.
6. Conducting secure development sessions for the team and
documentation for knowledge base creation.
7. Briefing customer product owners on security development and
cost effect analysis for various cloud security solutions.
Microsoft Inhouse 1. Conducting knowledge building sessions
2. Conducting workshops for global community within MS.
3. Training interns on Threat modelling, code reviews, Pentest.
4. Mentoring new hires in role alignment
Certifications
Certified Ethical Hacker (CEH) – CEH Certification | EC-Council
Azure Fundamentals (AZ-900) – Microsoft Learn
Azure AI Fundamentals (AI-900) - Microsoft Learn
TECHNICAL SKILLS
Commercial Tools: IBM AppScan Standard/Source, Veracode, HP WebInspect/Fortify, BurpSuite Pro
Open Source Tools: OWASP ZAP, WebScrab, SQLMap, Nikto, WireShark, Nmap, Metasploit
Web Development: HTML5, AJAX, JQuery, Angular JS, Ionic Framework (Mobile)
Scripting Languages: PHP, Python, Bash Script
EDUCATION
[Link]. (Electrical and Electronic Engineering) from VSSUT, Burla in 2015 with 70% marks
Higher Secondary Education from Vikash Junior College, Bargarh in 2011 with 84%
PERSONAL DETAILS
Date of Birth : 25th April 1994
Languages Known : English, Hindi, Odia
Address : Bengaluru, India