PRINCE MAURYA SYSTEM
BSc IT Graduate with 9.20 CGPA. Penetration Tester at ITQCR — specializing in manual exploitation of web apps, RESTful APIs, and networks. Making automated scanners look lazy since 2025.
Who Is The Threat
Results-driven cybersecurity professional with a BSc in Information Technology (9.20/10 CGPA) and hands-on experience as a Penetration Tester at ITQCR. Based in Mumbai, India — open to relocation worldwide.
Specializes in manual vulnerability discovery for web applications and RESTful APIs, with deep expertise in identifying complex logic flaws aligned with OWASP Top 10 and API Top 10. The kind of attacker that finds what automated scanners miss.
Proficient in delivering detailed technical reports with actionable remediation strategies. Actively expanding into SIEM/XDR monitoring, cloud security, and thick client testing. Passionate about continuous learning and staying ahead of emerging cyber threats.
Tools & Weapons
Field Experience
- Perform manual penetration testing on web applications, networks, and infrastructure for enterprise clients across multiple industries.
- Manual Exploitation: Identify complex authentication and authorization logic flaws including IDOR, BOLA, and SQL Injection that automated scanners miss.
- API Security Testing: Advanced testing of RESTful endpoints against OWASP API Top 10, including Mass Assignment and Broken Object Level Authorization vulnerabilities.
- AI-Assisted Recon: Leverage Python and AI LLMs to build custom reconnaissance automation scripts, significantly reducing manual testing time.
- Reporting: Deliver high-precision technical and executive reports with step-by-step exploitation proof and structured remediation recommendations.
- Wazuh SIEM: Actively expanding into SIEM/XDR monitoring for log analysis and File Integrity Monitoring (FIM).
- Conducted VAPT (Vulnerability Assessment & Penetration Testing) on networks and web applications for clients.
- Identified security loopholes and delivered structured remediation strategies to reduce client risk exposure.
- Gained hands-on experience with Nmap, Burp Suite, and Metasploit for reconnaissance and exploitation workflows.
Key Exploits
Certs & Education
2022 – 2025
Ready To Break
Your Defenses?
Open to opportunities — Full-time, contract, or collaborative engagements. Open to relocation worldwide.