Chinmay Kumar Mahto

Chinmay Kumar Mahto

Security Engineer with 3.9 years of experience

Pune, India

About

Security Engineer with 3.9 years of experience in Application Security, DevSecOps, Vulnerability Assessment Penetration Testing (VAPT), Cloud Security, and AI/LLM Security. Experienced in securing Web, Mobile, API, Thick-Client, and cloud applications through penetration testing, secure code reviews, SAST, DAST, SCA, and DevSecOps integrations. Skilled in CI/CD security automation, AWS security, vulnerability management, AI security testing, and secure software development practices aligned with OWASP Top 10, OWASP API Security Top 10, OWASP LLM Top 10, and SANS Top 25.

What I'm looking for

Seeking opportunities in Application Security, Cloud Security, and DevSecOps.

Experience

Tata Technologies Pvt. Ltd.

Security Solutions Developer

Tata Technologies Pvt. Ltd.

Apr 2025 – Present

• Conducted comprehensive VAPT assessments for Web, Mobile (iOS/Android), API, Thick-Client, and cloud applications, identifying and validating critical security vulnerabilities aligned with OWASP Top 10 and SANS Top 25. • Performed penetration testing and adversarial simulations to evaluate organizational resilience against real-world cyber threats. • Led secure code reviews and SAST assessments for Java, JavaScript, C, . NET, PHP, Python (Django), and React.js applications using Checkmarx, reducing false positives and providing remediation guidance. • Automated DAST assessments using Burp Suite Enterprise and integrated security testing into CI/CD pipelines to enable continuous vulnerability detection. • Designed and implemented DevSecOps security controls using Jenkins and GitHub Actions, embedding security throughout the SDLC. • Conducted security assessments of AI/LLM-powered applications, including Prompt Injection (Direct Indirect), RAG Security, Agentic AI Security, Jailbreak Testing, Function Calling Security, Data Leakage Assessment, and Insecure Output Handling validation aligned with OWASP LLM Top 10. • Deployed and managed Rapid7 InsightVM to support enterprise-wide vulnerability management and risk prioritization. • Create detailed testing reports that clearly communicate findings, risks, and recommended action. • Integrated automated security testing into CI/CD pipelines, validated findings, and partnered with development teams to remediate security risks and improve overall application security posture.. • Delivered security awareness and secure coding training programs for development teams to improve security maturity. • Managed bug bounty programs by validating researcher submissions, assessing business impact, and coordinating remediation activities.

VAPTCheckmarxJenkins
AKS IT Services Pvt. Ltd.

Information Security Consultant

AKS IT Services Pvt. Ltd.

Sep 2022 – Mar 2025

• Conduct thorough assessments to identify vulnerabilities and potential weaknesses in client’s infrastructure and application. • Perform penetration testing to simulate real-world cyberattacks and evaluate the organization’s ability to withstand security threats. • Conducted comprehensive Vulnerability Assessment and Penetration Testing (VAPT) for Web, Mobile, API, and Thick-Client applications, as well as Network infrastructure. • Executed Red Teaming exercises, including Social Engineering and Active Directory (AD) penetration testing, to simulate real-world attack scenarios. • Provide guidance on patch deployment strategies to minimize system vulnerabilities. • Performed thorough Source Code Reviews using Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies, both manually and through automation. • Create detailed audit reports that clearly communicate findings, risks, and recommended actions to clients. • Responsible for interacting and handling clients directly on day-to-day basis for the initiation, and execution of Cyber security assessments and completion of the projects on time. • Conducted an ISO 27001 audit to evaluate the organization’s information security system. Reviewed policies, assessed risks, and checked control measures for compliance with ISO 27001 standards • Experienced in conducting comprehensive security assessments for AWS cloud-based applications.

Penetration TestingSASTAWS Security

Education

Delhi University

Delhi University

Post-Graduation diploma · cyber security and Law

2021 – 2022
Birla Institute of Technology Mesra Ranchi

Birla Institute of Technology Mesra Ranchi

Bachelor of Computer Application

2017 – 2020

Certifications

Certified ethical hacker

EC-Council

Languages

English (Professional working proficiency)Hindi (Professional working proficiency)