Penetration Testing Consultant · Mumbai, IN

SAGAR
JONDHALE

Penetration Tester  //  CVE Author  //  Bug Bounty Hunter

3+ years breaking production systems across banking and enterprise. Published CVE author. Recognised by NASA, Nokia, Philips & BASF. 60+ apps, 70+ APIs manually assessed. CRTA certified offensive security professional.

60+Apps Assessed
70+APIs Tested
10+Hall of Fames
1CVE Published
Key Proof Points

Results That Speak

01 // CVE
CVE-2025-53545
Independently discovered and published under own name in the global CVE database.
02 // HOF
10+ Hall of Fames
NASA · Nokia · Philips · BASF · UK Ministry of Defence and more.
03 // GOV
Government Attack Surface
Secured 30+ Indian gov websites and the UK Ministry of Defence via VDP programs.
04 // API
70+ APIs Assessed
Auth, authz, input validation, encryption flaws across banking-grade APIs.
05 // PCI
Payment Gateway / PCI-DSS
Mobile app financial transaction flows assessed against PCI-DSS-aligned controls.
06 // CERT-IN
CERT-In Contribution
Manual web app testing contribution to a CERT-In empanelment assessment.
Hall of Fame
🛸 NASA 📡 Nokia 💡 Philips ⚗️ BASF 🇬🇧 UK Ministry of Defence 📶 Jio 💳 Mollie 📺 LG 🛡️ TruCSR 🏛️ 30+ Indian Gov Sites 🛸 NASA 📡 Nokia 💡 Philips ⚗️ BASF 🇬🇧 UK Ministry of Defence 📶 Jio 💳 Mollie 📺 LG 🛡️ TruCSR 🏛️ 30+ Indian Gov Sites
Work History

Experience

Penetration Testing Consultant Banking Client · Mumbai Jun 2025 — Present
  • Hands-on SAST/DAST and re-validation across web, mobile, and API attack surfaces for core banking infrastructure.
  • Independently re-exploits previously identified vulnerabilities to verify remediations fully close the attack path — not just automated re-scans.
  • Manual exploitation to separate true positives from false positives, reducing noise for engineering stakeholders.
  • Advises vendors on code-level, server-level, and load balancer remediation to eliminate root-cause vulnerabilities.
  • Owns end-to-end risk exception and risk acceptance tracking across the assessment lifecycle.
Associate Consultant — Penetration Tester Anzen Technologies · Navi Mumbai Feb 2024 — Jun 2025
  • Payment gateway security assessments on mobile apps — financial transaction flow flaws and PCI-DSS-aligned controls.
  • Manual penetration testing on 60+ web applications using OWASP Top 10 — SQLi, XSS, insecure authentication.
  • API security assessments across 70+ APIs targeting auth, authz, input validation, and encryption.
  • Technical liaison between app owners and offensive security team; verified remediations withstood re-exploitation before sign-off.
Cyber Security Intern Anzen Technologies · Mumbai Jul 2023 — Jan 2024
  • Identified and exploited SQLi, XSS, and IDOR using manual testing techniques.
  • Built proficiency with Burp Suite, Kali Linux, Frida, and Jadx for Android security testing.
  • Tested OAuth and API authorization logic for sensitive data handling flaws.
  • Contributed to a CERT-In empanelment assessment — manual web app testing and co-authored consolidated findings report.
Bug Bounty Hunter HackerOne · Bugcrowd · VDP · Remote 2023 — Present
  • 10+ Hall of Fame recognitions — NASA, Nokia, Philips, BASF for responsibly disclosed vulnerabilities.
  • Discovered and reported CVE-2025-53545, published in the global CVE database under own name.
  • Critical vulnerabilities reported to UK Ministry of Defence and 30+ Indian government websites.
  • Bounties and recognition from Jio, Mollie; appreciation letters from LG and TruCSR.
Technical Arsenal

Skills

Core Offensive Skills
Web App Penetration Testing 95%
API Security Testing 92%
Mobile (Android/iOS) VAPT 85%
Manual Exploitation 90%
Network VAPT 78%
Bug Bounty / Vuln Research 88%
Tools
Burp Suite Kali Linux Frida Jadx Nmap OWASP ZAP SQLmap Metasploit
Specializations
PCI-DSS / Payment Security 82%
Technical Reporting 90%
SAST / DAST 85%
Responsible Disclosure 98%
Credentials

Certifications & Education

Education
B.Sc. Information Technology
Mumbai University
Higher Secondary Certificate
Maharashtra Board
Community
Led cross-functional security assessment projects at Anzen Technologies with teams of 8+. Active contributor to cybersecurity communities through meetups, conferences, and workshops. Publishes technical write-ups on bug bounty findings on Medium.
Get In Touch

Contact