Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Sparsh Gulati, Penetration Tester

Sparsh Gulati

Penetration Tester·IBM

United Arab Emirates

Bachelor's degree, Computer Science

Work experience

Total years of experience: 4 years, 5 months

Penetration Tester

May 2024 - Present

IBM

Bengaluru, India

May 2024 - Present

• Conducted comprehensive security assessments across web, API, mobile,
network, cloud, and AI/LLM-based applications to identify and validate security
vulnerabilities.
• Performed security testing on client-facing AI bots and LLM-enabled
applications, assessing risks such as prompt injection, insecure input handling,
misuse scenarios, and application-layer weaknesses.
• Partnered with product and development teams throughout the SDLC to
implement security best practices and strengthen application security from
design through deployment.
• Developed controlled proof-of-concept malware and ransomware samples in
secure testing environments to demonstrate the impact of vulnerabilities such as
Remote Code Execution (RCE) and insecure file upload.
• Performed in-depth manual source code reviews to identify vulnerabilities and
improve application security posture.
• Prepared executive and technical reports aligned with OWASP, CVSS, and
organizational security standards.
• Strengthened IT security posture by performing Vulnerability Assessment and
Penetration Testing (VAPT) on critical infrastructure components, including
Active Directory, Domain Controllers, Layer 3 Switches, and Firewalls.
• Conducted security design reviews and threat modeling exercises to identify
architectural and implementation-level security risks.
• Developed automation scripts to streamline recurring security assessment and
operational tasks.

Company industry:
IT Services

Penetration Tester

May 2024 - Present

IBM - India

Bengaluru, India

May 2024 - Present

*Conducted comprehensive security assessments across web, API, mobile,
network, cloud, and AI/ LLM-based applications to identify and validate security
vulnerabilities.
• Performed security testing on client-facing AI bots and LLM-enabled
applications, assessing risks such as prompt injection, insecure input handling,
misuse scenarios, and application-layer weaknesses.
• Partnered with product and development teams throughout the SDLC to
implement security best practices and strengthen application security from
design through deployment.
• Developed controlled proof-of-concept malware and ransomware samples in
secure testing environments to demonstrate the impact of vulnerabilities such as
Remote Code Execution (RCE) and insecure file upload.
• Performed in-depth manual source code reviews to identify vulnerabilities and
improve application security posture.
• Prepared executive and technical reports aligned with OWASP, CVSS, and
organizational security standards.
• Strengthened IT security posture by performing Vulnerability Assessment and
Penetration Testing (VAPT) on critical infrastructure components, including
Active Directory, Domain Controllers, Layer 3 Switches, and Firewalls.
• Conducted security design reviews and threat modeling exercises to identify
architectural and implementation-level security risks.
• Developed automation scripts to streamline recurring security assessment and
operational tasks.

Company industry:
Software Development

Information Security Analyst

November 2022 - May 2024

Airtel

Pune, India

November 2022 - May 2024

• Conducted end-to-end Vulnerability Assessment and Penetration Testing (VAPT)
on enterprise web applications to identify, validate, and mitigate security
vulnerabilities.
• Performed mobile application penetration testing across Android and iOS
platforms, identifying application-layer and client-side security weaknesses.
• Leveraged tools such as Coverity and Black Duck to automate code analysis and
improve security review coverage.
• Executed detailed manual source code reviews to uncover vulnerabilities and
strengthen secure coding practices.
• Implemented and validated SAST and DAST security gate checks within CI/CD
pipelines to reinforce DevSecOps and secure application delivery.

Company industry:
Telecommunications

Jr. Cyber Security Engineer

February 2022 - October 2022

Time Tec

Jaipur, India

February 2022 - October 2022

• Performed security assessments across web applications, APIs, mobile
applications, and network environments to identify and validate security
vulnerabilities.
• Executed manual source code reviews to uncover security flaws and support
secure coding improvements.
• Conducted security audits and vulnerability assessments to identify weaknesses
across applications and supporting systems.
• Identified common application security vulnerabilities aligned with OWASP Top
10, including XSS, CSRF, authentication weaknesses, and access control issues.
• Collaborated with product teams during closing discussions to communicate
findings, explain business impact, and recommend mitigation strategies.
• Prepared structured vulnerability reports including proof of concept, risk
impact, and remediation guidance.
• Developed automation scripts to reduce manual effort and improve efficiency in
recurring security assessment tasks.

Company industry:
Software Development

Jr. Cyber Security Engineer

January 2022 - October 2022

In Time Tec

Jaipur, India

January 2022 - October 2022

- Executed comprehensive security assessments across web, API, mobile, and network environments.
- Facilitated closing meetings with product teams to review assessment findings and discuss mitigation strategies.
- Conducted meticulous manual source code reviews to identify and address potential vulnerabilities at the code level.
- Performed security audits to uncover vulnerabilities within systems.
- Developed a script to automate routine security tasks, enhancing efficiency.

Company industry:
Software Development

Education

JECRC University

May 2022

May 2022

Bachelor's degree, Computer Science

India

GPA (point): 8.79 out of 20

GPA (point): 8.79 out of 20

Skills

Web Application Penetration Testing
Intermediate
Web Application Penetration Testing
Intermediate
Android & IOS Penetration Testing
Intermediate
Android & IOS Penetration Testing
Intermediate
API Testing
Intermediate
API Testing
Intermediate
Source Code Review
Intermediate
Source Code Review
Intermediate
Red Teaming
Intermediate
Red Teaming
Intermediate
Threat Modelling
Intermediate
Threat Modelling
Intermediate
Active Directory Pentesting
Intermediate
Active Directory Pentesting
Intermediate
SAST & DAST
Intermediate
SAST & DAST
Intermediate
Python
Intermediate
Python
Intermediate
AWS
Intermediate
AWS
Intermediate
Network & Infrastructure Penetration Testing
Intermediate
Network & Infrastructure Penetration Testing
Intermediate
Scripting
Intermediate
Scripting
Intermediate
APPLICATION SECURITY
Intermediate
APPLICATION SECURITY
Intermediate
APPLICATION SECURITY TESTING
Intermediate
APPLICATION SECURITY TESTING
Intermediate
CERTIFIED ETHICAL HACKER
Intermediate
CERTIFIED ETHICAL HACKER
Intermediate
CODE REVIEW
Intermediate
CODE REVIEW
Intermediate
COMPUTER SCIENCE
Intermediate
COMPUTER SCIENCE
Intermediate
ETHICAL HACKING
Intermediate
ETHICAL HACKING
Intermediate
PENETRATION TESTING
Intermediate
PENETRATION TESTING
Intermediate
RED TEAMING
Intermediate
RED TEAMING
Intermediate
THREAT MODELING
Intermediate
THREAT MODELING
Intermediate
VULNERABILITY ASSESSMENTS
Intermediate
VULNERABILITY ASSESSMENTS
Intermediate
APPLICATION SECURITY
Intermediate
APPLICATION SECURITY
Intermediate
APPLICATION SECURITY TESTING
Intermediate
APPLICATION SECURITY TESTING
Intermediate
CERTIFIED ETHICAL HACKER
Intermediate
CERTIFIED ETHICAL HACKER
Intermediate
CODE REVIEW
Intermediate
CODE REVIEW
Intermediate
COMPUTER SCIENCE
Intermediate
COMPUTER SCIENCE
Intermediate
ETHICAL HACKING
Intermediate
ETHICAL HACKING
Intermediate
PENETRATION TESTING
Intermediate
PENETRATION TESTING
Intermediate
RED TEAMING
Intermediate
RED TEAMING
Intermediate
THREAT MODELING
Intermediate
THREAT MODELING
Intermediate
VULNERABILITY ASSESSMENTS
Intermediate
VULNERABILITY ASSESSMENTS
Intermediate

Social profiles

Languages

English

Expert

Training and Certifications

Certifications
Network Security Associate Microsoft Technology Associate — Security Fundamentals
Cyber Forensics & Investigation Certificate NSE 1
CHFI — Computer Hacking Forensic Investigator
Certified Red Team Professional CEH
Network Security Associate Microsoft Technology Associate — Security Fundamentals
Cyber Forensics & Investigation Certificate NSE 1
CHFI — Computer Hacking Forensic Investigator
Certified Red Team Professional CEH
CEH
EC-Council
Aug 2021
CRTP
ALTERED SECURITY
Sep 2024
Show credentials
OSCP
OffSec
Mar 2026
Show credentials
OSCP+
OffSec
Mar 2026 - Mar 2029
Show credentials

Hobbies and interests

Badminton