Jalaj Kumar Nimesh Offensive Security Engineer Discuss a VAPT ↗

Web + API VAPT

Security testing, done by the person you speak with.

Manual testing across authorization, authentication, APIs and business logic. Findings are reported in terms of what an attacker could actually access, change or control.

Security work

What the flaw meant — not just what it was called.

Axis Bank Responsible disclosure

Unauthorized access to credit-card customer PII.

Sensitive information associated with credit-card customers could be retrieved outside the intended access controls.

Business impact: customer data exposure
Passport Seva Government of India

Account recovery weakness could lead to account takeover and sensitive data access.

The issue affected a high-value identity account flow and was later fixed.

Business impact: account compromise
CVE-2026-72831 Public advisory · 8.8 High

A lower-privilege user could gain full administrative control.

An authorization flaw allowed privilege escalation to administrator-level access.

NVD ↗Vendor advisory ↗
MSG91 Paid security research

Multiple paths to sensitive-data exposure and account compromise.

Validated findings included database injection, persistent/reflected script injection, and a broken account-update authorization control that weakened the intended 2FA boundary.

Technical detail: SQL injection · stored/reflected XSS · broken authorization
Confidential B2B client Authorized VAPT

One customer tenant could act on another tenant’s user accounts.

The assessment identified a cross-tenant authorization failure in a multi-tenant security platform.

Business impact: tenant-isolation failure
Also acknowledged or rewarded by Red Hat Blinkit Utho Survicate

Background

Professional testing, research and delivery.

20+web & API assessments
500+reports reviewed / triaged
90+freelance orders completed
4.8 / 5Fiverr rating · 68 reviews
Professional

Security Engineer / Penetration Tester at BugBase. Web & API assessments, exploitability analysis, vulnerability triage and remediation validation.

Built

TryHackMe Road ↗ · Intigriti 1337UP Traveller challenge · 20 Docker-based security labs for PWNX.

Recognition

1st place — Great AppSec Hackathon 2026 · 2nd individual — Ghost in the Ledger, IIT Bombay.

Engineering

Python and Bash automation for testing helpers, repetitive security workflows and edge-case reproduction.

Credentials

CRTP + CWES — practical offensive-security certifications.

Independent VAPT

One tester.
Scope to retest.

I scope the engagement, perform the testing, write the report and retest the fixes myself. No sales-to-tester handoff.

Lower overhead keeps the fee lean — not the testing depth.

Typical Web + API VAPT ₹60,000–₹90,000 one remediation retest included
Testing
Authentication, authorization, sessions, tenant isolation, APIs, business logic and high-risk workflows.
You receive
Prioritized report, reproducible evidence, business impact, remediation guidance and a findings readout.
Quote changes with
User roles, API surface, workflow complexity, integrations and number of applications.

Start with the scope

Have something that needs testing?

Application type, user roles, API scope and preferred testing window are enough to start. I’ll reply with scope questions, timeline and a fixed quote.