Available for SOC / VAPT roles

Vimalatithyan SJunior Security Analyst & Bug Bounty Researcher

I identify, validate, and responsibly disclose real-world security vulnerabilities across web applications and supporting infrastructure — with findings acknowledged by NASA, Google, Microsoft, Amazon, and Ferrari.

Through coordinated disclosure programs and hands-on penetration testing, I help organizations strengthen their security posture before adversaries can exploit it.

Vimalatithyan S — Cybersecurity Professional
17+
VAPT Projects
6+
Global Organizations
3+
Bug Bounty Platforms
whoami

About Me

I am a cybersecurity researcher and penetration tester with hands-on experience in real-world vulnerability discovery, exploitation validation, and responsible disclosure. I have contributed to the security posture of globally recognized organizations including NASA, Google, Microsoft, Amazon, and Ferrari — earning formal recognition for responsible and impactful disclosures.

My expertise spans Security, Penetration Testing, Vulnerability Assessment, Cloud Security, Security Automation, API security, Open Source Intelligence, and Security Research & Development — with findings submitted across HackerOne, Bugcrowd, Intigriti, YesWeHack, and Wordfence.

Beyond hunting, I actively build security tools — including an AI-powered vulnerability scanner and a full-stack recon automation framework — to push the boundaries of how modern security research is conducted.

I am currently pursuing a B.E. in Electronics and Communications Engineering at Saveetha School of Engineering, where I serve as Cybersecurity Lead at the Google Developers Group. I am actively seeking cybersecurity opportunities where I can contribute, collaborate, and continuously grow as a security professional.

capabilities

Skills & Expertise

Offensive Security

  • Web App Penetration Testing
  • Bug Bounty Hunting
  • Recon & Asset Discovery
  • Exploitation Validation
  • OAuth & Auth Testing
  • OWASP Top 10

Defensive Security

  • Network Fundamentals
  • Log Analysis
  • Alert Investigation (SOC)
  • Incident Response Concepts

Tools & Tech

  • Burp Suite
  • Nuclei
  • FFUF
  • Subfinder
  • httpx
  • Katana
  • GAU
  • Wayback Machine
  • Kali Linux

Scripting & Automation

  • Python (Security Automation)
  • Bash (Recon Automation)
career.log

Professional Experience

Offensive Security Intern

Feb 2026 – Present
TECHNIEUM
Internship · On-site · Chennai, TN
  • Burp Suite-driven web app testing
  • Vulnerability Assessment & Penetration Testing (VAPT)
  • Hands-on offensive security operations

Penetration Tester

Jan 2025 – Present
YesWeHack
Part-time
  • Web application security testing
  • Responsible disclosure
  • Recon automation & reporting
  • Vulnerability triage

Penetration Tester

Jul 2024 – Present
Google Developers Group
Part-time
  • Security monitoring
  • Vulnerability management
  • Community security awareness

Penetration Tester

Jan 2024 – Present
Bugcrowd
Part-time
  • Web application security testing
  • Responsible disclosure
  • Recon automation & reporting
  • Vulnerability triage & management

Penetration Tester

Jan 2024 – Present
Intigriti
Part-time
  • Web application security testing
  • Responsible disclosure
  • Recon automation & reporting
  • Vulnerability triage

Founder & Cybersecurity Consultant

Jan 2023 – Present
Fortiguardia
Self-employed
  • Conducted VAPT on 20+ web applications
  • Built in-house recon and exploitation tools (Python & Bash)
  • Defence drone research & development
  • Identified high-impact vulnerabilities
  • Trained beginners in ethical hacking
academia

Education

Saveetha School of Engineering

B.E. — Electrical, Electronics & Communications Engineering
Jun 2024 – Jun 2028

Focus on Cybersecurity, Penetration Testing, Red Teaming & SOC Operations. Cybersecurity Lead at Google Developers Group. Active in CTFs, bug bounty research, and community security awareness programs.

Jaya Jaya Sankara International School

Higher Secondary — Computer Science
Jan 2017 – Jun 2024

Grade A. Active participant in science exhibitions, school events, and technology competitions with a focus on academic excellence and foundational STEM skills.

hall_of_fame

Vulnerability Disclosure & Recognition

NASA security recognition logoNASA Secured
Microsoft security recognition logoMicrosoft Secured
Google security recognition logoGoogle Secured
Amazon security recognition logoAmazon Secured
Ferrari security recognition logoFerrari Secured
Wordfence security recognition logoWordfence Secured
Shippit security recognition logoShippit Secured
TrekMail security recognition logoTrekMail Secured
Audinate security recognition logoAudinate Secured
Panasonic security recognition logoPanasonic Secured
ZKTeco security recognition logoZKTeco Secured
NASA security recognition logoNASA Secured
Microsoft security recognition logoMicrosoft Secured
Google security recognition logoGoogle Secured
Amazon security recognition logoAmazon Secured
Ferrari security recognition logoFerrari Secured
Wordfence security recognition logoWordfence Secured
Shippit security recognition logoShippit Secured
TrekMail security recognition logoTrekMail Secured
Audinate security recognition logoAudinate Secured
Panasonic security recognition logoPanasonic Secured
ZKTeco security recognition logoZKTeco Secured
credentials

Certifications

Analyze Speech and Language with Google APIs — Skill Badge

Google · Nov 2025

Google Certifications

Google · Oct 2025

Certified Red Team Operations Management (CRTOM)

CyberWarFare Labs · 2024

Certified Cybersecurity Educator Professional (CCEP)

EC-Council · 2024

Google Cloud Skill Badges

Google Cloud · 2024

Network Fundamentals

LetsDefend · 2024

Digital Forensics

Crypto Eagle Forensics · 2024

AI-Powered Fullstack Development

Hifi11 Technologies · 2025
case_studies

Projects & Case Studies

Recon Automation Tool

End-to-end recon pipeline using Subfinder, httpx, Nuclei, and custom Bash scripts. Automates subdomain enumeration, live host detection, and vulnerability scanning — cutting manual recon time by 80%.

PythonBashAPI IntegrationNuclei

VAPT Case Studies

Security assessments on 20+ web applications. Identified critical vulnerabilities including broken authentication, IDOR, OAuth token leakage, and exposed API keys — each documented with PoC, impact, and remediation.

Burp SuiteOWASP Top 10VAPTReporting
Confidential

ASM

Attack Surface Management platform for continuous asset discovery, shadow IT detection, and external exposure monitoring. Maps organizational digital footprint and identifies rogue assets before adversaries do.

Asset DiscoveryExternal MonitoringShadow IT
Confidential

LLM SUITE

Security testing suite purpose-built for Large Language Model applications. Covers prompt injection, model extraction, training data poisoning detection, and AI red-teaming workflows.

AI SecurityLLM Red TeamingPrompt Injection
Confidential

SAST DAST TOOL

Integrated static and dynamic application security testing platform. Combines source code analysis with runtime vulnerability detection for full-spectrum application security coverage.

SASTDASTCode AnalysisCI/CD
Confidential

Auto Pentest AI

AI-powered automated penetration testing framework that intelligently maps attack surfaces, chains vulnerabilities, and generates actionable reports with minimal human intervention.

AI SecurityAutomated PentestVulnerability ChainingML
Confidential

Security Research

Independent security research initiative focused on zero-day discovery, novel attack vectors, and responsible disclosure across enterprise software and cloud infrastructure.

Zero-DayResearchCloud SecurityDisclosure
Confidential

AI Automation

Intelligent automation platform leveraging AI agents for security workflow orchestration — from triage and enrichment to automated response and reporting pipelines.

AI AgentsSOARAutomationTriage
artifacts

Resume

mentorship

Cybersecurity Mentorship

Hands-on mentorship in offensive security, bug bounty, and VAPT — straight from someone actively shipping disclosures to NASA, Google, Microsoft, and Amazon.

Basic

1:1 monthly call, recon playbooks, bug bounty triage feedback.

Get in touch

Pro

Weekly 1:1s, live target reviews, private VAPT lab access, priority Q&A.

Get in touch
establish_connection

Get In Touch

Interested in discussing security research, vulnerabilities, or opportunities? Let's connect and secure the digital world together.