Piyush Singh

Piyush Singh He/Him

Cybersecurity Mentor & Bug Bounty Trainer

Cybersec Researcher | Ex-CyberSrc • Tech Mahindra • Dover

Application Security Engineer with hands-on experience securing web, API, mobile, and infrastructure environments.
Delivered end-to-end penetration testing, vulnerability triage, and remediation guidance — including critical infrastructure (power plants).

CEH CRTP
SEC_LOG_v2 • PROTO: HTTPS/TLS1.3 • UPTIME: 99.9%
PORTFOLIO_HUD • ID: PS_2026 • ACCESS: GRANTED

Core Expertise

Application Security

  • Web & API Security Testing
  • Mobile Security (Android/iOS)
  • OWASP Top 10 • CVE • CWE • CVSS
  • Vulnerability Triage & Reporting
  • Secure SDLC / DevSecOps

Penetration Testing

  • Network & Wireless Pentest
  • Red Teaming Fundamentals
  • Active Directory Assessments
  • Infrastructure Security

Security Analysis

  • SAST / DAST / SCA
  • Auth & Authorization Flaws
  • Business Logic Vulnerabilities
  • IDOR & Misconfigurations

Tooling

  • Burp Suite • Nmap • Wireshark
  • Metasploit • Nessus • SQLmap
  • BloodHound • Impacket • CME
  • FFUF • Amass

Automation & Dev

  • Python & Bash Automation
  • CI/CD Security (GitHub/GitLab)
  • Linux & Windows AD

Professional Experience

Application Security Engineer

Ralfkairos
07/2025 – 01/2026
  • Conducted security assessments (web, API, mobile, internal networks)
  • Built repeatable exploitation environments for complex vuln validation
  • Standardized recon & exploitation workflows + evaluated automation tools

Associate Security Analyst

Cybersrc
01/2025 – 07/2025
SCADA
Badge
  • VAPT for 30+ clients (web, infra, networks)
  • Onsite assessments including critical infrastructure (power plants)
  • Developed custom scripts & PoC exploits
VAPT
Dover Corporation
06/2024 – 08/2024
  • Found 5+ critical vulnerabilities (CVSS 8+)
  • Delivered actionable remediation reports
VAPT
Tech Mahindra
06/2023 – 08/2023
  • Supported VAPT for Australian Union project
  • Contributed to remediation tracking
Tech Mahindra

Security Projects

Tracedrill

PythonAutomationDevSecOps

Security automation platform — reconnaissance, misconfiguration detection, OWASP Top 10 testing.

Recon-Automator

PythonCLIOSINT

CLI + web interface reconnaissance tool — improved efficiency by ~40%.

Google Dorking Query Generator

OSINTAutomation

Simplifies complex Google dork creation for exposed assets discovery.

Achievements & Recognition

Inflectra HoF
Bosch HoF
  • Hall of Fame: Nvidia, Ferrari, Bosch, Philips, Michelin, Inflectra, Redvilla
  • Certified Red Teaming Professional (CRTP)
  • Certified Ethical Hacker (CEH)
RedVilla HoF
Ferrari HoF

Recommendations

Abhishek - Cisco
Julien
Poras
Kangwon

Certifications & Training

CEH
CRTP
TCM Security
Java Cert

Education

Bachelor of Technology, Computer Science

Sharda University

Sept 2021 – 2025

Interests & Tools

Hardware hacking • Wireless security • Custom security tooling

WiFi

Wireless Security

Arduino

Hardware / BadUSB

Defcon

Community