Anand Jogawade

Security Researcher



Lead Penetration Tester

I am a Penetration Tester with 2.5+ years of experience conducting web application, mobile (Android & iOS), and enterprise infrastructure security assessments across internal and external environments. My work focuses on identifying exploitable weaknesses, mapping realistic attack paths, and demonstrating measurable business impact through controlled exploitation. In internal assessments, I analyze network architecture and Active Directory environments to identify privilege boundaries, trust relationships, and lateral movement opportunities. I prioritize attack path validation, assessing how an initial foothold could escalate toward broader compromise within enterprise domains.

My methodology emphasizes manual testing, business logic flaw discovery, authentication and authorization bypass analysis, privilege escalation, and structured attack chaining. Where in scope, I also evaluate the effectiveness of security controls by validating detection and response mechanisms, including endpoint and XDR defenses, to assess resilience against adversarial techniques. Beyond vulnerability discovery, I work closely with engineering and IT teams to provide risk-prioritized remediation guidance, support secure configuration improvements, and conduct retesting to ensure effective resolution. Alongside enterprise engagements, I undertake independent security testing and source code reviews, helping organizations strengthen secure development practices and reduce overall attack surface exposure.

Experience

Lead Penetration Tester

Infilux AppSec

  • Web Application Penetration Testing
  • Mobile Application Penetration Testing
  • Internal Network / Active Directory Security Assessments
  • Firewall Rule Reviews
  • Lead and Mentor Penetration Testing Team
  • Provide Client Remediation Guidance

Application Security Engineer

Pixel Softwares

  • Web Application Penetration Testing
  • Conduct Secure Code Reviews
  • Work With Development Teams

Security Researcher(Bug Bounty)

Com Olho

  • Web Application Penetration Testing
  • Vulnerability Discovery & Responsible Disclosure
  • Reporting and Documenting Security Findings

Security Auditor

Phoenix TechnoCyber

  • Infrastructure VAPT
  • Firewall Rule Reviews
  • Web Application Penetration Testing
  • Conducting IS/GAP Audits
  • client Remediation Guidance

Web Application Security Intern

TechnoHacks EduTech Official

  • Web Application Penetration Testing
  • Setup/Configuring VMs
  • Packet Capturing

Penetration Testing Intern

ShadowFox

  • Network Penetration Testing
  • Web Application Penetration Testing
  • Wifi Hacking
  • Packet Capturing

Cyber Security Intern

Tutelr

  • Configuration Hardening Of Windows Machine
  • Performing Forensics Assessments
  • Creating & Configuring Network

Skills

Active Directory Assessment
AV/XDR/EDR Bypass
Red Teaming
Network VAPT
Web Application VAPT
Android/IOS Application VAPT
API Security Testing
Secure Code Review
Firewall Rule Review
IS/GAP Audit
Shell Scripting
Bash Scripting
Python
Networking
Team Lead
Problem Solving
Critical Thinking

Stats

0

Certifications

0

Course Completed

0

Conducted Awareness Trainings

0

Total Work Exp (Months)

Latest Blogs

My eCPPTv3 Exam Experience — A Real Test of Manual Pentesting Skills...
(Read More)
🚫The Dark Side of Free Streaming Apps: Why PikaShow, Castle, and Others Are Digital Landmines⚠️...
(Read More)
Social Engineering Attacks and Cybersecurity Awareness...
(Read More)
Cybersecurity for Small Businesses...
(Read More)
LDAP Nightmare: A Serious Threat to Active Directory in 2025...
(Read More)
Emerging Cybersecurity Technologies: The Future of Digital Protection...
(Read More)
CyberWarFare Labs: Certified Red Team Analyst (CRTA) Certification — My Experience & Honest Review (24hr Exam Format)...
(Read More)
Coming Soon...
(Read More)