Available for senior pentesting, bug bounty & freelance engagements
Portrait of Nihal Tikka

Nihal Tikka

Certified Ethical Hacker & Azure Security Engineer

VAPT · Vulnerability Management · Bug Bounty Researcher

He/Him · 6+ years · Hyderabad, India

I help organizations across finance, healthcare, and other regulated industries identify and address security vulnerabilities before attackers can. Six years of manual web and mobile penetration testing, source code review, and bug bounty research — focused on real-world exploitability beyond what automated scanners catch.

01 — About

Detail-oriented.
Results-driven. Collaborative.

Certified Ethical Hacker and Azure Security Engineer with 6+ years specializing in Vulnerability Assessment & Penetration Testing (VAPT), bug bounty hunting, and vulnerability management. I help organizations across finance, healthcare, and other regulated industries identify and address security vulnerabilities before attackers can — combining manual web and mobile pentesting, source code review, and business-logic testing to surface the complex flaws automated scanners miss.

Proficient with Burp Suite, Nmap, Nessus, Nuclei, Onapsis, Splunk, SQLmap, and more. Proven track record delivering risk-driven reports with reproducible PoCs, reducing recurring vulnerabilities by 90%, and partnering with 20+ development teams to strengthen security posture. Detail-oriented, results-driven, and collaborative — open to senior engagements and freelance partnerships.

Years of experience
6+
Vulnerabilities exploited
70+
Dev teams partnered with
20+
Recurring findings reduced
90%
02 — Capabilities

The stack I reach for when things get serious.

Offensive Security

  • Web application penetration testing
  • Mobile penetration testing
  • Source code review
  • Business logic & authorization testing
  • API security testing
  • Vulnerability assessment & penetration testing (VAPT)

Tools

  • Burp Suite
  • Nmap
  • Nessus
  • Nuclei
  • SQLmap
  • OWASP ZAP
  • MobSF (Mobile Security Framework)
  • Metasploit
  • Onapsis (SAP security)
  • Splunk (SIEM)

Methodology & Soft Skills

  • OWASP Top 10 & Secure SDLC
  • Bug bounty & vulnerability research
  • CVSS-based risk prioritisation
  • Executive reporting & stakeholder translation
  • Cross-functional collaboration
  • Mentoring & training
03 — Experience

Six years in the trenches of applied security.

Senior Software Engineer

CGI

June 2025 – Present
  • Leading 7–8 end-to-end penetration testing engagements across web applications and APIs, covering the full attack lifecycle from reconnaissance to retest.
  • Identified and validated 5–7 critical vulnerabilities (SQL injection, account takeover, authentication bypass) and multiple high-risk issues, prioritised using CVSS and business impact.
  • Performing manual penetration testing and source code review to uncover business logic, authorization, and data-handling flaws beyond automated tools.
  • Leveraging Burp Suite, SQLmap, and Nmap to support exploitation, session analysis, and input validation testing.
  • Contributing to bug bounty programmes and delivering high-quality reports with reproducible PoCs, enabling effective remediation and validation.

Senior Associate Consultant

Infosys

December 2022 – June 2025
  • Conducted manual web and mobile penetration testing and DAST assessments, identifying and exploiting 70+ vulnerabilities across multiple client environments.
  • Performed manual source code review and dynamic analysis to uncover business logic flaws, authentication weaknesses, and data exposure issues.
  • Applied a bug bounty–driven approach, focusing on real-world exploitability and chaining vulnerabilities to demonstrate high-impact attack scenarios.
  • Delivered risk-based vulnerability reports with reproducible PoCs, contributing to a 30% reduction in security risks.
  • Improved triage efficiency by reducing false positives and collaborated with development teams on secure code reviews, achieving a 90% reduction in recurring vulnerabilities.
  • Trained new joiners on SAP vulnerability management using Onapsis and Security Bridge tools.

Associate

Cognizant Technology Solutions

January 2020 – December 2022
  • Conducted manual VAPT across web and mobile applications, identifying critical vulnerabilities across diverse platforms.
  • Performed manual testing and validation, supported by Burp Suite, SQLmap, Nmap, and OWASP ZAP, to uncover issues in authentication, session management, input validation, and business logic.
  • Delivered risk-based vulnerability reports with detailed PoCs, contributing to a 30% reduction in security risks.
  • Reduced 60% of false positives from automated scanners through in-depth analysis, improving triage accuracy and remediation efficiency.
  • Collaborated with 10+ development teams to remediate vulnerabilities, accelerating resolution and strengthening application security posture.
04 — Projects

Tools I've built to sharpen the craft.

XSS Scanner

Python · Security Tool

Advanced Cross-Site Scripting (XSS) detection tool with comprehensive scanning capabilities across query parameters, path segments, POST data, headers, cookies, and the DOM.

  • PyQt5 desktop GUI for ease of use
  • Headless browsing and multithreaded scan engine
  • Pause/resume, progress tracking, save/load scan sessions
  • Detailed reporting and real-time Telegram alerts
  • Python
  • PyQt5
  • Selenium
  • BeautifulSoup

Vulnerability Report Generator

Python · Reporting Tool

Automated tool for generating professional penetration testing reports in PDF, Word, Excel, and HTML formats from a single interface — saving security teams hours on documentation.

  • Built with Python, Tkinter GUI, ReportLab & FPDF2
  • Severity highlighting, vulnerability templates, smart defaults
  • Multi-format export from one source of truth
  • Python
  • Tkinter
  • ReportLab
  • FPDF2
View on GitHub
05 — Credentials

Validated by the people who set the bar.

Certified Ethical Hacker logo

CEH Master

Certified Ethical Hacker — EC-Council

Microsoft Azure Security Engineer logo

Azure Security Engineer

Microsoft Certified

Purdue University logo

Applied Cybersecurity Essentials

Hybrid Intensive — Purdue University

06 — Education

Where the foundation was laid.

Bachelor of Technology

Jawaharlal Nehru Technological University, Hyderabad (JNTUH)

2015 – 2019

Coursework: Java, Computer Networks, Algorithms, Database Management Systems, Principles of Programming Languages, Operating Systems, Information Security.

07 — Contact

Let's explore if we're aligned.

Open to senior penetration testing roles, bug bounty collaborations, freelance engagements, and advisory work across finance, healthcare, and other regulated industries. Drop a line about what you're building — I'll get back within a day.