BASED IN BENGALURU

Chirag Arora

Cybersecurity Professional

VAPT · Application Security · Security Engineering

Finding the vulnerability is the easy part. Translating it into business risk — and getting it fixed — is the job.

View My WorkResume — Coming Soon
security-session — zsh

0+

Years in Security Consulting

0

Security Certifications

Finance · Healthcare · Government

Sectors Assessed

PCI DSS

Compliance-Driven Engagements

About

Security is a decision problem before it's a technical one.

A vulnerability report is only useful if someone acts on it. Over four years across consulting engagements in Finance, Healthcare, and Government, that’s been the throughline — running the full VAPT and vulnerability management lifecycle, then making sure the result lands as a decision a client can act on, not a PDF they file away.

That means going deep technically — network, OS configuration, and web application testing, much of it inside PCI DSS-scoped, on-site engagements — and translating it upward into executive summaries and risk reports that hold up in a room with people who don’t read CVE identifiers for a living. It also means running the engagement itself: planning, resourcing, and governance across concurrent assessments, not just the testing inside them.

What I Do

01

Web Application VAPT

Vulnerability assessment and penetration testing across authentication, session, and business-logic layers.

02

Network & Infrastructure Security

Network security reviews and OS configuration hardening assessments.

03

Compliance-Driven Assessment

PCI DSS-scoped engagements run on-site, aligned to regulatory and audit requirements.

04

Engagement Governance & Reporting

Executive summaries and risk reports that turn technical findings into decisions clients can act on.

05

Resource & Program Management

Workforce planning, OKR-driven backlog management, and delivery across concurrent engagements.

Education

  • M.S., Cyber Security and Forensics

    Southern New Hampshire University

    Completed Aug 2024

  • MBA, Information Technology

    Lovely Professional University

    Nov 2022 – Aug 2025

  • B.E., Computer Science

    BMS Institute of Technology and Management

    2018 – 2022

Recognition

  • Best Client Recognition
  • CyRAACS — Top Performer
  • Top 10% on TryHackMe

Experience

From hands-on testing to leading the engagement.

A vertical record of the roles that built the way I work today. Expand any entry for the full scope.

Associate Manager

Jul 2026Present · Bengaluru

Role details pending.

Team Lead

Jul 2025Jun 2026 · Mumbai
VAPT Program GovernanceExecutive ReportingResource Management
  • Enabled strategic decision-making by providing clear, actionable executive summaries and risk reports to clients.
  • Accountable for the planning, execution, and governance of large-scale VAPT initiatives, ensuring compliance with regulatory standards and business risk posture.
  • Drove resource management and workforce planning, ensuring optimal team utilization, skill alignment, and proactive risk mitigation across concurrent engagements.

Senior Consultant — Information Security and Compliance

Jul 2023Jun 2025 · Mumbai · On-site
PCI DSSNetwork SecurityOS Configuration ReviewWeb Application Review
  • Partnered closely with Information Security and Compliance stakeholders on PCI DSS-scoped projects, driving on-site assessment activities, engagement closure, and remediation support.
  • Led vulnerability and security assessments including Network, OS Configuration, and Web Application reviews; coordinated quarterly OKR planning, security backlog management, resource allocation, and reprioritization.
  • Developed project deliverables and reports, supported clients with remediation efforts, and collaborated on defining step-by-step operational procedures.

Consultant — Technical Services

May 2022Jun 2023
Web Application VAPTFinanceHealthcareGovernment
  • Conducted comprehensive Web Application Vulnerability Assessments and Penetration Testing (VAPT) across Finance, Healthcare, and Government sectors, identifying attack vectors and vulnerabilities using industry-standard tools and methodologies, and recommending effective remediation strategies.
  • Prepared detailed security reports and project deliverables, supported clients through remediation efforts, and communicated complex technical findings to non-technical stakeholders while contributing to step-by-step operational procedures.

Case Studies

Security work, not side projects.

Anonymized engagement summaries — client names withheld, scope and substance intact.

Multi-Sector Web Application VAPT

Client: ConfidentialIndustry: Finance, Healthcare & Government

Web Application VAPT

Problem

Organizations across three regulated sectors needed independent validation that customer- and citizen-facing web applications could withstand real attack techniques before and after release.

Attack Surface

Authenticated and unauthenticated web application surfaces, spanning login, session, and business-workflow layers.

Testing Approach

Structured VAPT methodology using industry-standard tooling to map attack vectors, informed by the specific compliance posture of each sector.

Finding

Specifics pending — anonymized detail to follow.

Business Impact

Specifics pending — anonymized detail to follow.

Remediation

Detailed remediation guidance delivered with every engagement, with direct support through the client's fix cycle.

PCI DSS-Scoped Security Assessment Program

Client: ConfidentialIndustry: Financial Services / Payments Compliance

Network, OS Configuration & Web Application review — on-site

Problem

A PCI DSS-scoped environment required recurring, on-site security assessment aligned to compliance cadence rather than a one-off test.

Attack Surface

Network layer, OS/server configuration, and web application components within PCI scope.

Testing Approach

On-site assessment activities coordinated with Information Security and Compliance stakeholders, run against quarterly OKR-driven planning and backlog management.

Finding

Specifics pending — anonymized detail to follow.

Business Impact

Specifics pending — anonymized detail to follow.

Remediation

Engagement closure and remediation support coordinated directly with compliance stakeholders through to resolution.

Capability Map

Security Toolkit

Tool list pending confirmation — the categories below mark where the real toolkit will land.

Application Security

Awaiting tool list

Network Security

Awaiting tool list

Exploitation / Research

Awaiting tool list

Platforms

Awaiting tool list

Security Operations

Awaiting tool list

Certifications

Credentials

CEH (Practical)

Certified Ethical Hacker — Practical

EC-CouncilYear pending

CRTP

Certified Red Team Professional

Altered SecurityYear pending

eWPTX

eLearnSecurity Web Application Penetration Tester eXtreme

INE (eLearnSecurity)Year pending

Contact

Let’s secure something.

Whether you’re looking for

Security AssessmentApplication SecuritySecurity EngineeringConsultingCollaboration

Let’s talk.