Shradha Karhekar — professional portrait 10 yrs

Application Security · Portfolio

0 Years of hands-on AppSec

Shradha Karhekar

Cyber Security Consultant | VAPT | Penetration Tester

SAST & DAST | Security Researcher

10 years securing web, mobile, API, and infrastructure — from pentest to DevSecOps.

Email me
Career summary

About

Experienced cybersecurity consultant specializing in web, mobile, API, and thick-client application security testing, vulnerability assessment, and software composition analysis. Application Security Consultant with 10 years across penetration testing, vulnerability management, SAST/DAST/SCA, and DevSecOps — reducing risk exposure for enterprise and banking clients while partnering with global cross-functional teams.

LinkedIn focus areas

  • Web application security testing
  • Mobile application security testing
  • API security
  • Thick client application security
  • Vulnerability assessment
  • Software component analysis (SCA)

Penetration Testing

Web applications, Mobile (Android/iOS), Thick Client, API (REST/SOAP)

Application Security

Secure code review (SAST), DAST, secret scanning, SCA, SBOM analysis, container image scanning

DevSecOps

Security gate failures in PRs, fixing issues with developers before release, fine-tuning security tools with DevOps

Vulnerability Management

Risk assessment, prioritization, remediation tracking, governance reporting

Collaboration

Stakeholder reporting, cross-functional coordination, remediation ownership

10-year path

Career timeline

From education to today — follow the path, then open a role below.

Start Education B.E. Information Technology — University of Mumbai.
Next Ready for next challenge Open to impactful AppSec roles, consulting, and collaboration.
  1. 01

    Product Security Engineer

    BMC Software Pune, India

    Jan 2026 – Present
    • Conduct web application penetration testing, SAST, SCA, and DAST for enterprise applications and API security assessments — identifying and validating vulnerabilities before release.
    • Perform SBOM analysis on open-source and third-party components, contributing to publishing security advisories.
    • Deliver risk-prioritized security reports with remediation guidance and revalidation testing to ensure effective resolution.
  2. 02

    Associate Consultant / Cyber Security Consultant

    Tech Mahindra Pune, India

    Apr 2023 – Jan 2026
    • Executed web application penetration testing, DAST, and SAST source code assessments across multiple applications; reported critical, high, and medium findings and supported remediation.
    • Performed network infrastructure vulnerability assessments, prioritized remediation, and tracked critical findings to improve security posture.
    • Owned end-to-end vulnerability management lifecycle using Rapid7 InsightVM and Nessus, improving remediation SLA compliance.
    • Built vulnerability trend and compliance dashboards for monthly governance reviews with stakeholders.
    • Documented and tracked risk exception requests with periodic re-review aligned to security governance policy.
  3. 03

    Security Consultant

    NST Cyber (Netsentries Technologies) Client: Emirates NBD Bank, Dubai, UAE

    Apr 2022 – Mar 2023
    • Delivered application penetration testing and API security assessments for a top-tier UAE bank across multiple applications and Agile change requests.
    • Documented vulnerabilities, assigned risk ratings, provided remediation recommendations, and verified fixes through retesting.
    • Managed risk exception and acceptance workflows for unresolved findings aligned to organizational risk tolerance.
    • Performed log reviews and AWS cloud security configuration reviews, identifying misconfigurations across cloud components.
  4. 04

    Security Consultant

    Capgemini Mumbai, India

    Apr 2020 – May 2022
    • Performed penetration testing on web applications and RESTful APIs across client engagements.
    • Delivered vulnerability reports with actionable remediation steps and revalidation testing.
    • Authored client-specific secure development guidelines adopted across engineering teams.
    • Mentored junior AppSec engineers on penetration testing and vulnerability management.
  5. 05

    Sr. Security Analyst

    Paladion Networks (ATOS) Mumbai, India

    Jan 2016 – Mar 2020
    • Delivered penetration testing across web, Android mobile, thick-client, and API surfaces for BFSI and enterprise clients.
    • Produced detailed security reports and presented findings directly to client stakeholders.
    • Maintained and enhanced security testing checklists aligned to industry frameworks, improving coverage and consistency.
Core competencies

Skills snapshot

Web / API / Mobile Pentest SAST · DAST · SCA SBOM & Container Scan DevSecOps PR Gates Vulnerability Management AWS Config Reviews Stakeholder Reporting Mentorship
Security toolkit

Tools & frameworks

Web

Burp Suite · OWASP ZAP · SQLmap · Acunetix · WinHex · Wireshark · DirBuster · HCL AppScan · Nmap · InsightAppSec · WebInspect

Mobile

MobSF · Drozer · JD-GUI · ADB · APKTool · dex2jar · JADX

API

Postman · SoapUI

SAST

Checkmarx One · Fortify · GitHub Advanced Security · JFrog Xray

SCA / Container

Aqua Security · Sonatype Lifecycle

VM

Nessus · Rapid7 InsightVM

Frameworks

OWASP Top 10 · SANS Top 25 · NIST · CWE

Recognition

Achievements & education

Achievements & certifications

  • Certified Ethical Hacker (CEH)
  • OSCP (appearing Oct 2026)
  • Award for Excellence in Project Delivery — Paladion Networks
  • Award for Best Agile Delivery Support — Emirates NBD Bank
  • Featured guest — AppSecWarrior Breaking In: Pentester’s Voice podcast

Education

  • Bachelor of Engineering (B.E.) in Information Technology — University of Mumbai

Protected resume download

The PDF includes personal contact details. Enter the access key shared with you.