~Hello World~
I'm, Devansh Bordia

Product Security Analyst at HackerOne | Ex-CoLead-Cloud Security Consultant at Payatu | Strike Pentester | Bugcrowd 2020 MVP Q2 | CVE-2022-27432 | CVE-2022-26589 | CVE-2022-26588 | CVE-2021-44321 | eJPT | eCPPTv2 | eWPTXv2 | AWS Solution Architect | Author of AWS Security Series | SRT

About Me

Hey World, I am Devansh Bordia. Here a little about me :)

Devansh Bordia is working as Security Consultant where his expertise is around Application Security & AWS Penetration Testing.He also an part of Synack Red Team and has been Acknowledged with Bugcrowd MVP 2020 for Q2.Devansh is also an bug bounty hunter with more than 20+ Hall of Fames and being Ranked under 1500 researchers on Bugcrowd.The certifications being hold by him are eJPT, eCPPTv2, eWPTXv2, AWS Solution Architect in the area of Penetration Testing.Also he holds an Bachelors Degree in Computer Science from Amity University and has publication in Book related to Cyber Security known as Mastering the Art of Information Gathering & Scanning.

Download CV

Skills

Web Application Penetration Testing

API Penetration Testing

Internal & External Network Penetration Testing

Mobile Application Penetration Testing (Android & iOS)





AWS Cloud Configuration Review

Thick Client Penetration Testing

Security Tools - Burp Suite, Nmap, Metasploit, Sqlmap & Others

Python,Bash

Writing & Communication - Blogs, Articles & Reports

Experience

HackerOne

Product Security Analyst

October 2022 - Present

Review incoming vulnerability reports and reproduce issues, assessing the severity and impact of each issue within the context of each organization’s threat model. Work with hackers to identify missing information in reports, as well as help educate the community when reports are incorrect. Coordinate with our Customer Success team and customers to ensure smooth triage workflows for any programs you work with. Write a brief summary for each report, including clear reproduction steps, the impact of the issue, and remediation advice.

Payatu

Security Consultant

September 2019 - Sepetember 2022

Perform various type of Security Assessments on Web,API,Network,AWS Config Review, Android Applications.Responsible for Cloud Config Review of services such as IAM,EC2,Lambda,API Gateway etc and have profound knowledge of tools such as Pacu,Scoutsuite,Enumerate-IAM,Prowler,Pmapper.

Strike

Striker Pentest

February 2022 - Present

Conducted 15+ Pentest for strike which includes Web, Mobile(Android/IOS) and Cloud Pentesting. Found over 100+ vulnerabilities which consist of Account Takeover, SSRF(PDF Parser), Privilege Escalation, Request Smuggling, and Information Disclosures in multiple applications comprising of Web & Mobile assessments.

Bugcrowd

Freelance Security Reseracher

Feb 2020 - Present

20+ Hall of Fames for the securing the companies and perform Security Assesments for the platform and Bugcrowd MVP 2020 Q2

Synack Red Team

Red Team Member

December 2020 - Present

Accessing & Securing the applications.

Wall of Fame

CVE-2022-27432

CVE-2022-26589

CVE-2022-26588

CVE-2021-44321

Gusto

Bitdefender

ConvertKit

Xfinity Home & xFi

Healtifyme

Mastercard

Telefonica Germany

Hubspot

Hindustan Unilever

Seagate

SAP Concur

Sophos

Telefonica Germany

Gusto

Education

B.Tech-Computer Science

Amity University Rajasthan

Session : 2017-2021

CGPA : 7.22

High School

Subodh Public School

Session : 2016-2017

83.4 %

Publications

Mastering Hacking - The Art of Information Gathering & Scanning

Khanna Publishers

2019

Get a Copy

Certifications & Achievements

eLearn Security Certified Penetration Testing Professional

Elearn Security

eLearnSecurity Web application Penetration Tester eXtreme

Elearn Security

AWS Solution Architect Associate

AWS

eLearn Security Junior Penetration Tester

Elearn Security

Introduction, Unix, Essential, PCAP, White & Serialize Badge

PentesterLab

Qualys Certified Specialist - Vulnerability Management

Qualys

ICSI Network Security Specialist

ICSI

Cyberops Information Security Expert

Cyberops

Nutanix Cloud Scholar by Udacity

Udacity

Network Pentesting,Recon,Wifi,Privilege Escalation.Password Cracking

Attack Defense

Cisco Newtorking Basics Specialization

Cisco

Palo Alto Network CyberSecurity Gateway

Palo Alto

Bugcrowd MVP 2020 Q2

97th Rank - HacktheBox All over India & Pro Hacker on the platform

8th Rank - OWASP Seasides CTF organized by Security Innovation

2020

Community Engagements

Session:MLH Local Hackday Cyber Security on Recon in Penetration Testing at Amity University.

Head of Technija Cyber Security Club at Amity University Rajasthan

OWASP-Bikaner Chapter Member

2019-Present

Projects

XSSTest: The tool is used to perform XSS Vulnerability Scan using predefined payloads

SubdomainEnum: The tool is used to discover subdomains,status code using custom worldist

CVE_finder_2017-7529: The CVE Finder is used to check Nginix Remote Integer Overflow Vulnerablity.

Network-Scanner: The tool is used to perform ARP Ping Scan on the network to detect live host on the network.

Profile

HackTheBox

Link

Github

Link

Bugcrowd

Link

Blogs

Payatu

Link

Cybrary

Link

Get in Touch

Drop me a text over Whatsapp or Email at below details .

devansh3008@gmail.com

9799380589

46B Uniara Garden near Tri-Murti Circle opposite govind marg Jaipur