[ PENETRATION TESTER · CYBERSEC OPERATOR ]

PRINCE MAURYA SYSTEM

Vulnerability Hunter & Digital Intruder

BSc IT Graduate with 9.20 CGPA. Penetration Tester at ITQCR — specializing in manual exploitation of web apps, RESTful APIs, and networks. Making automated scanners look lazy since 2025.

Scroll to Explore

Who Is The Threat

Results-driven cybersecurity professional with a BSc in Information Technology (9.20/10 CGPA) and hands-on experience as a Penetration Tester at ITQCR. Based in Mumbai, India — open to relocation worldwide.

Specializes in manual vulnerability discovery for web applications and RESTful APIs, with deep expertise in identifying complex logic flaws aligned with OWASP Top 10 and API Top 10. The kind of attacker that finds what automated scanners miss.

Proficient in delivering detailed technical reports with actionable remediation strategies. Actively expanding into SIEM/XDR monitoring, cloud security, and thick client testing. Passionate about continuous learning and staying ahead of emerging cyber threats.

0
CGPA Score
0
THM Rooms Done
0
False Positives
0
% Manual Testing

Tools & Weapons

[ 01 ]
Penetration Testing
Manual VAPT Web App Testing API Security Network PenTest Black-box Grey-box White-box IDOR BOLA SQLi
[ 02 ]
Offensive Tools
Burp Suite Pro95%
Metasploit85%
Nmap / Wireshark90%
SQLMap80%
Acunetix / Caido78%
Nessus / Wazuh72%
[ 03 ]
Frameworks
OWASP Top 10 OWASP API Top 10 PTES CVSS Scoring Risk Prioritization
Programming
Python Bash Scripting AI-Assisted Automation Custom Scripts
Platforms
Kali Linux Ubuntu Windows Server Postman

Field Experience

AUG 2025 – PRESENT
Penetration Tester
ITQCR · FULL TIME · MUMBAI, INDIA
  • Perform manual penetration testing on web applications, networks, and infrastructure for enterprise clients across multiple industries.
  • Manual Exploitation: Identify complex authentication and authorization logic flaws including IDOR, BOLA, and SQL Injection that automated scanners miss.
  • API Security Testing: Advanced testing of RESTful endpoints against OWASP API Top 10, including Mass Assignment and Broken Object Level Authorization vulnerabilities.
  • AI-Assisted Recon: Leverage Python and AI LLMs to build custom reconnaissance automation scripts, significantly reducing manual testing time.
  • Reporting: Deliver high-precision technical and executive reports with step-by-step exploitation proof and structured remediation recommendations.
  • Wazuh SIEM: Actively expanding into SIEM/XDR monitoring for log analysis and File Integrity Monitoring (FIM).
2025 · 3 MONTHS
Cybersecurity Intern
INFOTACT SOLUTIONS · INTERNSHIP · MUMBAI, INDIA
  • Conducted VAPT (Vulnerability Assessment & Penetration Testing) on networks and web applications for clients.
  • Identified security loopholes and delivered structured remediation strategies to reduce client risk exposure.
  • Gained hands-on experience with Nmap, Burp Suite, and Metasploit for reconnaissance and exploitation workflows.

Key Exploits

01
[ CRITICAL FIND ]
BOLA Vulnerability Discovered
Discovered a critical Broken Object Level Authorization (BOLA) vulnerability in a client API during manual testing that automated tools completely failed to detect — prevented potential enterprise data breach.
02
[ EFFICIENCY ]
Recon Automation with AI
Reduced pentest reconnaissance time significantly by automating target discovery using custom Python scripts integrated with AI assistance — faster intel, sharper results.
03
[ ZERO DEFECT ]
Zero False Positive Record
Consistently delivered zero-defect reports — all client-reported findings verified accurate with zero false positives across all engagements. Precision is the mission.
04
[ TRAINING ]
25+ TryHackMe Rooms Completed
Completed 25+ TryHackMe rooms focused on API security, web exploitation, and SOC fundamentals — alongside full-time penetration testing work. Always sharpening the edge.

Certs & Education

CEH
Certified Ethical Hacker (CEH)
NETTECH INDIA · EC-Council Recognized
THM
TryHackMe — 25+ Rooms Completed
API Security · SOC Fundamentals · Web Exploitation
HTB
Hack The Box — Active Practitioner
Multiple Machines Compromised · Ongoing Practice
SIEM
SIEM/XDR Self-Study — Wazuh
Log Analysis · FIM · Active Response Rules
CLO
Cloud Security Training (Active)
AWS / Azure — In Progress
[ ACADEMIC RECORD ]
BSc Information Technology
BGPS's Mumbai College, Wadala East · Mumbai University
2022 – 2025
9.20
/ 10 GPA Score
First Class with Distinction
Initiate Contact

Ready To Break
Your Defenses?

Open to opportunities — Full-time, contract, or collaborative engagements. Open to relocation worldwide.

Located in Mumbai, Maharashtra, India · Open to Relocation Worldwide