// security_consultant.init()

Vrushali Pote

VAPT & Application Security Consultant

Cybersecurity consultant specializing in Vulnerability Assessment and Penetration Testing, web and mobile application security, and network penetration testing — analyzing and validating findings to eliminate false positives, prioritize real-world risk, and turn raw scan output into remediation that actually closes the gap.

01 / Impact

What the numbers say

Proficient in leveraging industry-standard tools and vulnerability scanners to deliver clear, actionable insights that streamline remediation and strengthen overall security posture — across every surface an organization exposes.

900+

Servers & network devices assessed

30+

Web applications assessed

15

Mobile apps assessed (iOS & Android)

API

Endpoints assessed across engagements

3

Hall of Fame recognitions (Nokia, BASF, Frappe)

02 / Capabilities

Scan results: skill set

Web Application VAPT 92%
Mobile Application VAPT 88%
Network Penetration Testing 85%
API Security Assessment 90%
Vulnerability Validation & Triage 87%
Bug Bounty Hunting 80%

Frameworks & Methodology

  • OWASP Top 10
  • Bug bounty methodologies
  • Patch management
  • PCI-DSS aligned payment gateway review

Tools

  • Burp Suite
  • Kali Tools
  • Frida
  • Jadx

03 / Engagement Log

Experience

Consultant

ongoing

Banking Client · Navi Mumbai, Maharashtra

June 2025 — Present

  • Conducting regular security assessments across web and mobile applications, network infrastructure spanning 900+ servers and network devices, and APIs — with practical remediation recommendations.
  • Performing revalidation of fixes and ensuring timely closure of identified vulnerabilities against defined timelines.
  • Monitoring emerging vulnerabilities and recommending process improvements to strengthen the organization's security posture.

Associate Consultant

ongoing

Anzen Technologies · Navi Mumbai, Maharashtra

Feb 2024 — Present

  • Assessed security across 15 mobile applications on iOS and Android, identifying platform-specific vulnerabilities with comprehensive coverage.
  • Conducted security assessments for 30+ web applications using OWASP Top 10 methodology to detect and remediate vulnerabilities.
  • Reviewed mobile applications integrating payment gateways, ensuring safeguards for financial transactions in line with PCI-DSS.

Cyber Security Trainee

Anzen Technologies · Navi Mumbai, Maharashtra

July 2023 — Jan 2024

  • Learned to identify and exploit common web vulnerabilities — SQL injection, XSS, and insecure direct object references.
  • Built hands-on proficiency with Burp Suite and Kali Tools for web testing, and Frida and Jadx for mobile testing.
  • Studied API security practices including OAuth authentication, authorization checks, and secure handling of sensitive data.
  • Practiced clear, actionable reporting of findings, impacts, and remediation steps for developers and stakeholders.

04 / Findings

Bug bounty & community

Hall of Fame

Recognized by Nokia, BASF, and Frappe for responsibly disclosed vulnerabilities.

Critical

Secured vulnerabilities on Indian Government websites.

Reward

Earned swag from JIO for identifying a critical vulnerability.

Community

Writes cybersecurity content on Medium to support community learning, and engages students through cybersecurity talks and educational initiatives.

05 / Credentials

Certifications

Certified Red Teaming Analyst — CRTA

06 / Education

Education

Bachelor's Degree in Cybersecurity

Indira College of Commerce and Science, Savitribai Phule Pune University

2020 — 2023

S.S.C & H.S.C

MIT College, Savitribai Phule Pune University

2019

07 / Contact

Get in touch

Open to new opportunities, collaborations, and conversations about security. Reach out directly — whichever way works best for you.