Security Engineer
Seattle, WA · nitish.yaddala@gmail.com
EXECUTIVE SUMMARY
4+ years hunting vulnerabilities across web apps, cloud infrastructure, mobile platforms, and AI systems. 200+ findings, 177 targets, every single one found by hand. From a 4-step invisible XSS chain that hijacked accounts without a single click, to an empty signature list that bypassed an entire blockchain's consensus mechanism; I find what automated tools simply can't. Currently operating as Security Engineer at Bureau Veritas, doing cloud security assessments for a major cloud provider. OSCP certified.
THE JOURNEY
ISRO
Security Trainee
Sriharikota
Reduced network attack surface by 30+ services across 20 production devices through Wireshark traffic analysis
Led decommissioning of legacy protocols (FTP, Telnet) based on findings from independent investigation
Enabled early threat detection by building custom monitoring for 30 critical assets
Identified anomalous traffic patterns and unexpected service exposure that hadn't been previously flagged
SRM Institute of Science and Technology
BTech Computer Science
HighRadius
Security Consultant
Hyderabad
Eliminated cross-tenant data exposure in Fortune 500 financial workflows by identifying IDOR and auth bypass across collections, cash application, and credit management
Discovered broken auth,improper token handling, missing session invalidation, weak credential enforcement traced to code root cause
Identified business logic flaws in financial workflows by abusing request ordering, state transitions, and retry behavior
Found injection vulnerabilities (SQLi, XSS, CSRF) and API misconfigs across REST endpoints using Burp Suite Pro
Detected sensitive data exposure,financial PII, credentials, and transaction details in API responses without access controls
Prevented insecure releases by conducting secure design reviews on data flows and trust boundary assumptions
Mapped privilege escalation paths using BloodHound and validated with Metasploit under scoped rules of engagement
HP Inc.
Cybersecurity Engineer
Bangalore
Exposed 20+ critical vulnerabilities including SQLi, XSS, CSRF, AuthN/AuthZ bypass, XXE, and race conditions by pentesting 6 production apps
Traced root causes deeper than Veracode by performing manual code-level analysis and correlating SAST against runtime behavior
Identified business logic flaws by manipulating multi-step workflows, request ordering, and retry behavior
Demonstrated horizontal and vertical privilege escalation by abusing role boundaries and insufficient access control
Standardized transport security validation by building Python automation for TLS/SSL checks across all 6 apps
Produced developer-friendly reports with CWE, CVSS, reproduction steps, and retested every fix post-implementation
Performed manual code review identifying insecure patterns, missing validation, and access control gaps SAST missed
Georgia Institute of Technology
MS Cybersecurity
Bureau Veritas
Security Engineer
Seattle, WA
BUREAU VERITAS, MAJOR CLOUD PROVIDER
Cloud Security Assessments
Mar 2024 – Present · Security Engineer · Seattle, WA
WEB / API
10documented findings & activitiesby abusing IAM trust relationships, undocumented API parameters, and role assumption chains
Validated real exploitability of SQLi, XXE, command injection, SSTI, and CRLF across all user-controlled surfaces,beyond scanner output
Exposed CORS misconfigurations enabling credential-bearing cross-origin requests by testing wildcard origins and null origin reflection
Revealed full GraphQL schemas and unauthorized resolver access through introspection abuse, batching, and missing depth limits
Discovered systemic business logic chains by manipulating request ordering, state transitions, and cross-API interactions
Identified mass assignment and parameter pollution by injecting unexpected fields and observing server-side model behavior
Assessed cryptographic implementations for weak algorithms, insecure randomness, and improper certificate handling
Detected second-order vulnerabilities by tracing stored payloads that executed in different contexts
Identified subdomain takeover risks through dangling DNS records pointing to deprovisioned resources
Tested authentication for brute force gaps, MFA bypass, session fixation, and token entropy weaknesses
OPERATOR CAPABILITY ASSESSMENT
THE EVIDENCE
200+ documented vulnerabilities across professional engagements and independent research
Individual findings under NDA. Aggregate impact documented.
60 findings · 5 platforms · All individually verified
MOST WANTED
Top 10 highest-impact vulnerabilities,ranked by severity and real-world consequence
postMessage XSS → ATO
Demonstrated a 4-step invisible chain that no automated scanner could detect,each link harmless alone, devastating together. Found through manual code review during a cloud security engagement.
Prototype Pollution
Proved that a single polluted prototype key could compromise application-wide state across every user session simultaneously. No automated tool flagged it.
Stored XSS → Headless Admin
Showed that a single user comment could silently hijack an admin-level automated agent,zero interaction required, full privileged access gained. The attack required only a standard user account.
State Government IDOR
CloudFormation CLI Injection
DIBZ Hardcoded Credentials
SDK SSRF via bucketEndpoint
Tron PBFT Bypass
WPForms Webhook Forgery
Trusted Types CSP Bypass
STANDARD OPERATING PROCEDURE
PLATFORM-ADAPTED 7-PHASE METHODOLOGY,SELECT PLATFORM, THEN INSPECT PHASES
THE CREDENTIALS
Academic training, professional certifications, and competition records
Georgia Institute of Technology
MS Cybersecurity
SRM Institute of Science and Technology
BTech Computer Science
Offensive Security Certified Professional
Offensive Security · 2023
Flipkart Grid
National-level competition by Flipkart. Advanced through multiple rounds against 3000+ teams to semi-finals.
NahamCon CTF
International online CTF. Placed in top third across web exploitation, binary analysis, and forensic challenges.
Red Team Academy
Simulated enterprise red team engagement. Achieved 5th place through AD exploitation and lateral movement chains.
"The next breach is already happening.
The question is who finds it first."