// security_consultant.init()
Vrushali Pote
VAPT & Application Security Consultant
Cybersecurity consultant specializing in Vulnerability Assessment and Penetration Testing, web and mobile application security, and network penetration testing — analyzing and validating findings to eliminate false positives, prioritize real-world risk, and turn raw scan output into remediation that actually closes the gap.
01 / Impact
What the numbers say
Proficient in leveraging industry-standard tools and vulnerability scanners to deliver clear, actionable insights that streamline remediation and strengthen overall security posture — across every surface an organization exposes.
900+
Servers & network devices assessed
30+
Web applications assessed
15
Mobile apps assessed (iOS & Android)
API
Endpoints assessed across engagements
3
Hall of Fame recognitions (Nokia, BASF, Frappe)
02 / Capabilities
Scan results: skill set
Frameworks & Methodology
- OWASP Top 10
- Bug bounty methodologies
- Patch management
- PCI-DSS aligned payment gateway review
Tools
- Burp Suite
- Kali Tools
- Frida
- Jadx
03 / Engagement Log
Experience
Consultant
ongoingBanking Client · Navi Mumbai, Maharashtra
June 2025 — Present
- Conducting regular security assessments across web and mobile applications, network infrastructure spanning 900+ servers and network devices, and APIs — with practical remediation recommendations.
- Performing revalidation of fixes and ensuring timely closure of identified vulnerabilities against defined timelines.
- Monitoring emerging vulnerabilities and recommending process improvements to strengthen the organization's security posture.
Associate Consultant
ongoingAnzen Technologies · Navi Mumbai, Maharashtra
Feb 2024 — Present
- Assessed security across 15 mobile applications on iOS and Android, identifying platform-specific vulnerabilities with comprehensive coverage.
- Conducted security assessments for 30+ web applications using OWASP Top 10 methodology to detect and remediate vulnerabilities.
- Reviewed mobile applications integrating payment gateways, ensuring safeguards for financial transactions in line with PCI-DSS.
Cyber Security Trainee
Anzen Technologies · Navi Mumbai, Maharashtra
July 2023 — Jan 2024
- Learned to identify and exploit common web vulnerabilities — SQL injection, XSS, and insecure direct object references.
- Built hands-on proficiency with Burp Suite and Kali Tools for web testing, and Frida and Jadx for mobile testing.
- Studied API security practices including OAuth authentication, authorization checks, and secure handling of sensitive data.
- Practiced clear, actionable reporting of findings, impacts, and remediation steps for developers and stakeholders.
04 / Findings
Bug bounty & community
Recognized by Nokia, BASF, and Frappe for responsibly disclosed vulnerabilities.
Secured vulnerabilities on Indian Government websites.
Earned swag from JIO for identifying a critical vulnerability.
Writes cybersecurity content on Medium to support community learning, and engages students through cybersecurity talks and educational initiatives.
05 / Credentials
Certifications
06 / Education
Education
Bachelor's Degree in Cybersecurity
Indira College of Commerce and Science, Savitribai Phule Pune University
2020 — 2023
S.S.C & H.S.C
MIT College, Savitribai Phule Pune University
2019
07 / Contact
Get in touch
Open to new opportunities, collaborations, and conversations about security. Reach out directly — whichever way works best for you.