Open to Opportunities — Bengaluru, India
Sugnana Murthy
GM
Penetration Tester
Cybersecurity Engineer
Security Consultant
Vulnerability Analyst
VAPT Specialist

Cybersecurity engineer with hands-on experience in VAPT, vulnerability management, and security assessments across web applications and cloud environments. Hunting threats with OWASP Top 10, MITRE ATT&CK, and NIST CSF frameworks.

6+
Projects
12+
Certifications
8.0
CGPA
Sugnana Murthy GM
📍 Bengaluru, India · +91-7483546559
BCA (Hons.) · Cybersecurity & Digital Forensics
Open to Work

Me And Myself

I'm a Cybersecurity Engineer specializing in VAPT, vulnerability management, and security assessment across web applications and cloud-hosted environments. Completed my BCA (Honours) in Cybersecurity & Digital Forensics at Chanakya University, Bengaluru (CGPA: 8.0, Expected May 2026).

I'm proficient in identifying, analyzing, validating, and remediating security vulnerabilities using tools like Burp Suite, Nessus, Metasploit, Nmap, Wireshark, and Splunk. Strong knowledge of OWASP Top 10, MITRE ATT&CK, NIST CSF, CVSS, and secure design principles.

Experienced in conducting vulnerability scans, risk assessments, security audits, and preparing technical remediation reports. Familiar with Linux, Windows, AWS Cloud Security, and offensive security methodologies.

Passionate about ethical hacking, threat intelligence, and strengthening enterprise security posture through proactive security testing and continuous improvement.

OWASP Top 10 MITRE ATT&CK NIST CSF CVSS DAST SAST STRIDE
Security Engineering
Pen TestingVAPTWeb App SecAPI SecuritySIEM MonitoringIncident ResponseThreat HuntingSecure Code Review
Security Tools
Burp SuiteNessusMetasploitWiresharkNmapOWASP ZAPSplunk
Development
PythonJavaScriptPHPJavaReactFlaskHTML/CSS
Cloud & AI
AWSAWS Encryption SDKGoogle CloudIAMLangChainYOLOv8Adversarial ML

Battle-Tested

PROFESSIONAL

Jan 2026 — May 2026
Cybersecurity Intern
Fidrox Technology Pvt. Ltd. · Bengaluru
  • Conducted end-to-end penetration testing and VAPT on web applications, identifying OWASP Top 10 vulnerabilities using Burp Suite, Nmap, Metasploit, OWASP ZAP, and Wireshark; validated findings across platforms including PortSwigger, HackTheBox, and TryHackMe.
  • Conducted Nessus-based vulnerability scans on real-world client applications; identified critical and high-risk findings with technical remediation guidance.
  • Collaborated with developers and senior engineers to validate vulnerabilities, retest fixes, and improve the security posture of client-facing systems.
  • Contributed to internal security checklists and best practices for future project repeatability.

VIRTUAL JOB SIMULATIONS (FORAGE)

Deloitte Australia
Completed threat analysis and cyber risk assessment tasks; produced concise risk summaries.
Tata Cybersecurity
Practiced security monitoring and incident triage in SOC-like scenarios with alert prioritization.
Telstra
Investigated a simulated malware attack; prepared an incident postmortem with recommended controls.
IBM Cyber Investigator
Analyzed digital evidence and correlated indicators of compromise in an interactive investigation.
Mastercard Cybersecurity
Completed Mastercard Cybersecurity Virtual Experience Program focused on phishing awareness, security operations, incident response, cyber risk management, and security best practices.

What I've Built

01
🛡️
SENTINEL.IO — AI Threat Detection
  • Designed and implemented a multi-layered AI-based detection system to identify suspicious activity patterns and raise automated alerts, simulating enterprise monitoring pipelines.
  • Tuned detection logic and thresholds to reduce manual triage effort by ~40% in test scenarios.
PythonAI/MLAnomaly DetectionLangChain
−40% triage
02
🔐
Translatr — Encryption/Decryption Tool
  • Engineered a multi-cipher encryption tool (Caesar, Beaufort, Autokey) to secure text data, with configurable algorithms and key lengths.
  • Integrated AWS Encryption SDK for secure key management and storage, aligning with cloud security best practices.
PythonAWS SDKCryptography
03
🤖
Secure Adversarial AI Models
  • Developed and deployed a secure AI image-classification platform using Python, Flask, TensorFlow, AWS EC2, JWT, and MySQL/Amazon RDS.
  • Identified and remediated FGSM, DoS, RCE, brute-force, JWT tampering, and SQL injection vulnerabilities, improving the system’s security and resilience against real-world attacks.
PyTorchAdversarial MLFGSMPGD
+15% robust
04
🖼️
Steganography Web App
  • Created a JavaScript–Flask app to hide and extract messages in images using LSB steganography, achieving zero data loss across 500+ test cases.
  • Applied secure input handling and validation to prevent misuse and maintain integrity of hidden data.
JavaScriptFlaskLSB Steganography
500+ tests ✓
05
🛡️
FireScan Pro – Firewall & Network Security Assessment Tool
  • Developed a JavaScript-based security scanner for WAF detection, port scanning, SSL/TLS, DNS, and security header analysis.
  • Built risk scoring, technology fingerprinting, and exportable JSON/CSV/HTML security reports covering 10+ security parameters per scan.
06
🏏
CPL Mega Cricket Auction Platform
  • Developed and deployed a live-synchronized cricket auction platform that successfully managed live-bidding and dynamic asset tracking for over 1,800 global users simultaneously.
  • Built a highly responsive front-end dashboard featuring real-time team statistics, financial tracking, and animated auction alerts, resulting in highly positive user feedback for seamless performance.
ReactFlaskMongoDBAWS
1,500+ users

Technical Writing

I actively publish cybersecurity, networking, cloud security, and secure software design articles on Medium.

View All Articles

Credentials

G
Google
AI Essentials
G
Google
Fundamentals of Cybersecurity
G
Google
Generative AI
G
Google
Play It Safe: Manage Security Risks
G
Google
Cloud Cybersecurity Certificate
C
CISCO
Cybersecurity
C
CISCO
Ethical Hacker
IN
Infosys
Open AI Development
IN
Infosys
Ethical Hacking for Beginners
Li
LinkedIn
Introduction to Quantum Cryptography

Skill Arsenal

SECURITY & TOOLS

Penetration Testing / VAPT92%
Vulnerability Assessment88%
Burp Suite / OWASP ZAP / Nessus90%
SIEM / Splunk / Incident Response82%
STRIDE / MITRE ATT&CK / NIST78%
Cloud Security (AWS / GCP)75%

DEVELOPMENT & AI

Python88%
JavaScript / React / Flask80%
Secure Code Review / DAST / SAST83%
AI Security / Adversarial ML80%
MySQL / MongoDB72%
YOLOv8 / Computer Vision70%
// 06 — Contact

Let's Build
Something Secure

Actively seeking roles as a Penetration Tester, Security Consultant, or Cybersecurity Engineer. If you're hiring or want to collaborate on security projects — let's talk.

Based in Bengaluru, India · Open to Remote & On-site