Application & Product Security · VAPT · Vulnerability Research

Rahul Parmar

Product Security Engineer @ IBM · Independent Security Researcher

5+ years across product security, application security and offensive testing. Currently running DevSecOps and secure-release reviews for enterprise IBM Maximo Application Suite — SAST, DAST, SCA and container scanning, plus hands-on remediation. Previously built an organisation's entire security function from zero — process, tooling and a 5-person team. Credited by Apple, the United Nations, Dell and eBay for responsible disclosure.

4Published CVEs
20+Hall of Fame & Credits
100+Applications Pentested
Top 15NCIIPC India (NTRO)

Featured Projects

🔬VoltVerse — Self-Hosted Cyber Range

Flagship

A cybersecurity training range that looks like a real SaaS product — 11 realistic target apps, 48 hands-on challenges, flags & scoring, cross-app attack campaigns, a role-based admin console and an auto-detecting blue-team SOC.

Covers the OWASP Web Top 10, API Top 10 and LLM Top 10 — SQLi, XSS, SSRF, SSTI, IDOR / BOLA, JWT alg:none, GraphQL abuse, OAuth redirect_uri, PHP object injection, prompt injection & RAG poisoning — each scalable across four difficulty levels from textbook-vulnerable to a hardened reference fix. Ships as one PHP + Docker container: docker compose up and it runs.

PHP 8.2Docker OWASP Web · API · LLM11 target apps 48 challenges
📡Zoom Archive URL Fetcher

OSINT recon tool — surfaces password-bearing Zoom meeting links from Wayback Machine archives. Python.

GitHub →
🎣Gophish Phishing Templates

Landing-page templates for authorised phishing-simulation and security-awareness exercises. HTML.

GitHub →

Security Research & Responsible Disclosure

CVE-2023-3074Advisory
CVE-2023-1975Advisory
CVE-2023-1704Advisory
CVE-2023-1703Advisory
Hall of Fame
AppleUnited NationsDell Deutsche TelekomeBayFitBit HubSpotSpringer NatureInflectra Electro RentWorldline GlobalAPNIC
Letters of Acknowledgement
Harvard UniversityIntuitESET AvastHuaweiIntelHumanFirst
Recognition & Publications
  • Top 15 researchers — NCIIPC India (a unit of NTRO), April 2021, for Government of India disclosures
  • "Hashcat for Forensics" — National Journal of Anti Cyber Crime Research & Studies (ACCRS)
  • Google Dorks — published on Exploit-DB

Experience

Software Developer — Product Security / DevSecOpsDec 2025 – Present
IBM · Gandhinagar, Gujarat
  • Own secure-release review and sign-off across IBM Maximo Application Suite components.
  • Run DAST (OWASP ZAP), SAST & SCA (Mend) and container scanning (Twistlock / Prisma Cloud) in the DevSecOps pipeline.
  • Remediate open-source / SCA and container vulnerabilities hands-on — dependency upgrades, base-image and config fixes — verified by re-scan.
  • Analyse CVEs, PSIRTs and PVRs; run SBOM and open-source dependency risk analysis and executive reporting.
Senior Software Security EngineerNov 2022 – Nov 2025
Zarca Interactive · Mumbai — founding security hire
  • Built the security function from zero — process, tooling stack and a 5-person team.
  • Found 300+ vulnerabilities, remediated down to ~55 open — an ~80% closure rate.
  • Ran breach & attack simulation and phishing programmes; threat hunting and dark-web monitoring.
  • Managed ISO 27001 and SOC 2 audit cycles end to end.
Risk ConsultantFeb 2022 – Nov 2022
PricewaterhouseCoopers (PwC) · Mumbai
  • VAPT across 100+ client applications — web, API and infrastructure.
  • 3 full-scope red-team / BAS engagements for banking, financial services and oil & gas.
  • VPN and remote-access security testing; CVSS-based severity and patch prioritisation.
Security AnalystJul 2021 – Jan 2022
Bulwarkers Websecurity · Ahmedabad
  • Web and mobile application VAPT using OWASP / PTES methodology, manual plus automated.

Capabilities

Offensive Security

VAPT · Web / API / Mobile Pentesting · Red & Purple Teaming · Breach & Attack Simulation · VPN Testing · OWASP Top 10 · JWT / OAuth / Rate-Limit Bypass

Application & Product Security · DevSecOps

SAST · DAST · SCA · Container Scanning (Twistlock / Prisma Cloud) · Mend · OWASP ZAP · Secure SDLC · CI/CD Security · SBOM · OSS Remediation · Secure Release Review

Vulnerability Management

CVE Analysis · CVSS Scoring · PSIRT / PVR Workflows · Remediation Tracking · Executive Reporting

Detection & Response

Threat Hunting · Microsoft Sentinel · Defender for Endpoint · Sophos XDR · Azure WAF · Dark-Web Monitoring

Cloud & GRC

AWS · Azure · Cloud Security Audits · ISO 27001 · SOC 2 · DPDP Act 2023 · Risk Assessment

Toolset

Burp Suite · OWASP ZAP · Mend · Twistlock / Prisma Cloud · Nuclei · Subfinder · httpx · Nmap · Nessus · Metasploit · Acunetix · Netsparker · Hashcat · Autopsy

Certifications & Education

  • ISO/IEC 27001 Lead Auditor — Jul 2024
  • Certified Ethical Hacker (CEH v11) — EC-Council, May 2022
  • Certified Cybersecurity Educator Professional (CCEP)
  • Certified Network Security Specialist (CNSS) — ICSI UK, May 2020
  • Autopsy Basics · OSForensics Triage — 2020
  • Digital Personal Data Protection Act, 2023 — 96%
  • PG Diploma, Cyber Security & Cyber Forensics — Rashtriya Raksha University, 2020–2021
  • M.Sc. Information Technology — Dr. C. V. Raman University, 2017–2019
  • Bachelor of Business Administration — Kadi Sarva Vishwavidyalaya, 2013–2016