AVAILABLE FOR OPPORTUNITIES

KHANT SHAH

Passionate Cybersecurity Professional specializing in Web Application Security, API Security, Vulnerability Assessment & Penetration Testing while also building secure and scalable web applications.

SCROLL

About Me

KS
Khant Shah
Cybersecurity Analyst | VAPT Engineer | Full Stack Developer
Vadodara, India
shahkhant2024@gmail.com
+91 9898024637
7+
VAPT Projects
9.0
Max CVSS Score
5+
Certifications
3+
Years Dev

Detail-oriented Cybersecurity Analyst with hands-on experience in Vulnerability Assessment and Penetration Testing (VAPT) across web, API, mobile, and network environments.

Delivered 7+ end-to-end penetration testing engagements independently, uncovering critical vulnerabilities including a 0-click account takeover (CVSS ~9.0) and authentication bypass flaws. Proficient in OWASP Top 10 standards, CVSS scoring, proof-of-concept (PoC) development, and responsible disclosure.

Additional background in full-stack web development enables a developer-aware approach to vulnerability assessment and secure design.

Discovered 0-Click Account Takeover with CVSS score ~9.0
Identified Authentication Bypass in production login flows
B.E. Computer Science & Engineering — Babaria Institute of Technology
Actively pursuing eJPT (eLearnSecurity Junior Penetration Tester)
Black box & white box testing, CVSS-scored reporting, responsible disclosure

Technical Skills

Cybersecurity
VAPT Web Security API Security Mobile Security Network Security OWASP Top 10 Black Box Testing White Box Testing CVSS Scoring Responsible Disclosure Threat Analysis Risk Assessment
🛠 Security Tools
Burp Suite OWASP ZAP Nmap Wireshark Metasploit Nikto Netcat PoC Development VAPT Reporting Remediation Roadmaps
Development
ReactJS NodeJS ExpressJS PHP JavaScript Tailwind CSS Prisma MongoDB MySQL PostgreSQL
Platforms & CMS
WordPress WooCommerce Secure Coding Technical Documentation Git Linux Payment Gateways SEO Practices

Experience

FEB 2025 – PRESENT
Cybersecurity Analyst Intern
Invesics Cyber Forensics · Vadodara
  • Independently completed 7+ end-to-end penetration testing projects across web and API applications, performing both black box and white box assessments.
  • Discovered a 0-click account takeover vulnerability (CVSS score ~9.0); produced full PoC, coordinated responsible disclosure, and recommended session-binding and token validation fixes.
  • Identified authentication bypass flaw in production login flows enabling unauthorized account access without credentials; delivered CVSS-scored VAPT report and remediation roadmap.
  • Conducted comprehensive vulnerability assessments aligned with OWASP Top 10 standards, uncovering critical and high-impact vulnerabilities across client environments.
  • Produced professional technical documentation including CVSS-scored reports, PoC write-ups, and mitigation strategies for each engagement.
JUL 2024 – JAN 2025
WordPress Developer
Swiss Tech · Vadodara
  • Designed and developed custom WordPress themes and plugins meeting unique client requirements across multiple industry verticals.
  • Built, updated, and maintained responsive, SEO-friendly websites; integrated WooCommerce and custom payment gateways for e-commerce clients.
  • Developed dynamic, data-driven web applications using Core PHP; applied secure coding practices to reduce injection and authentication vulnerabilities.
JUN 2023 – DEC 2023
Web Development Intern
DotTech · Vadodara
  • Gained hands-on experience in modern web development using ReactJS and full-stack technologies.
  • Built full-stack applications with ReactJS frontend and Node.js/Express backend.
  • Worked with relational and non-relational databases including MySQL and MongoDB for application data design.

Vulnerability Discoveries

CRITICAL
CVSS: 9.0+
0-Click Account Takeover
Discovered a session fixation flaw leading to full account takeover with no user interaction required. Produced complete proof-of-concept, coordinated responsible disclosure, and recommended session-binding and token validation fixes.
CRITICAL
CVSS: High
Authentication Bypass
Identified a business logic flaw in production login flows that allowed unauthorized account access without valid credentials. Delivered CVSS-scored VAPT report with comprehensive remediation roadmap.
HIGH
CVSS: 7.5+
Session Fixation
Discovered improper session handling that resulted in potential account compromise. The flaw allowed an attacker to fix a user's session identifier prior to authentication.
HIGH
CVSS: 7.0+
Business Logic Vulnerability
Exploited flawed application workflow leading to unauthorized actions. Identified through systematic analysis of application business logic beyond standard OWASP Top 10 checks.

Projects

01 // SECURITY
VAPT Assessments
Performed 7+ end-to-end Web and API security assessments aligned with OWASP Top 10. Delivered professional CVSS-scored reports, proof-of-concept write-ups, and remediation roadmaps for client environments.
Burp Suite OWASP Top 10 API Security CVSS Scoring
02 // FULL STACK
QC Management System
Full-stack quality control management application built using ReactJS, Prisma ORM, and PostgreSQL. Features role-based access control, real-time reporting, and secure data workflows.
ReactJS Prisma PostgreSQL NodeJS
03 // E-COMMERCE
Secure E-Commerce Platforms
Developed multiple WordPress and WooCommerce-based e-commerce websites with custom payment gateway integrations. Applied secure coding practices to reduce injection and authentication vulnerabilities.
WordPress WooCommerce PHP Secure Coding

Certifications

PURSUING
🎯
eJPT
eLearnSecurity
Blockchain & its Application
NPTEL · IIT
💉
SQL Injection Attacks
EC-Council
🔐
Cybersecurity Job Simulation
Mastercard · Forage
🛡
Cybersecurity Job Simulation
TATA · Forage
📱
OWASP Mobile Security 2025
Udemy

Download CV

Khant_Shah_CV.pdf  ·  Cybersecurity Analyst
DOWNLOAD RESUME

PDF · Updated 2025 · Includes VAPT findings & full project history

// CURRENT ROLE
Cybersecurity Analyst Intern
Invesics Cyber Forensics · Feb 2025 – Present
// EDUCATION
B.E. Computer Science & Engineering
Babaria Institute of Technology, Vadodara · 2021–2024
// KEY ACHIEVEMENT
0-Click Account Takeover · CVSS 9.0+
Critical vulnerability discovered & responsibly disclosed
// ENGAGEMENTS
7+ Independent VAPT Projects
Web, API, Mobile & Network — Black & White Box
// PURSUING
eJPT Certification
eLearnSecurity Junior Penetration Tester

My CV covers all VAPT engagements, critical vulnerability write-ups, development projects, and certifications in full detail.

GET THE FULL PICTURE

Contact

Open to cybersecurity roles, penetration testing projects, and freelance development work. Let's connect and build something secure together.

Phone
+91 9898024637

✓ MESSAGE SENT

Thanks for reaching out! I'll get back to you soon.

* Direct email: shahkhant2024@gmail.com