Vivekananda Reddy Murugesh

Cybersecurity Engineer — web, API, cloud & network security

I secure applications and APIs, break them to find weaknesses, and work directly with customers and product teams to fix what I find. 3+ years across penetration testing, vulnerability research, and security automation — currently at Citta Core Technologies, based in New York.

vivek31337@gmail.com GitHub Twitter New York, USA Résumé (PDF)

Open to Forward Deployed Engineer, Security Engineer, Solutions Engineer & Application Security roles

Experience

Cybersecurity Engineer · Citta Core Technologies

Jun 2026 — Present

  • Partner with customers to assess security requirements and implement practical, risk-prioritized solutions.
  • Perform web, API, cloud, and infrastructure security assessments and validate remediation end to end.
  • Automate repetitive security workflows with Python, scripting, and APIs.
  • Translate technical risk into business impact for stakeholders and product teams.

Cybersecurity Analyst · Galaxy i Technologies

2025 — 2026

  • Performed penetration tests and security assessments across web applications, APIs, cloud configurations, and internal/external networks.
  • Used Nessus, Nmap, Metasploit, and Burp Suite to simulate real-world attacks and identify weaknesses.
  • Delivered risk-rated findings with actionable remediation, tailoring approaches per client.

Cyber Security Analyst / Penetration Tester · Capgemini

2021 — 2023 · Bangalore, India

  • Delivered penetration testing services on web apps, thick & thin clients, networks, and APIs.
  • Conducted IT Health Checks following established methodologies, using Nessus, Nmap, Metasploit, and Burp Suite.
  • Prepared thorough, actionable reports with risk assessments and remediation guidance.

Projects

Penetration Testing of an In-House Banking Application

Oct 2024 — Dec 2024

End-to-end web application penetration test of an in-house banking platform. Combined black-box and grey-box techniques aligned with OWASP Top 10, and paired every finding with secure coding recommendations so fixes shipped developer-ready.

Burp Suite Pro · DAST · OWASP Top 10 · Manual testing

Skills

Web app security
Burp Suite Pro, DAST, black & grey box testing, OWASP Top 10
Network pentesting
Nessus Professional, Qualys, Nmap, Metasploit, black box assessments
API security & VM
API security testing, Postman, Fiddler, Qualys, Archer, vulnerability management
Programming
Python, Bash, REST APIs, Git, Linux
Customer-facing
Technical troubleshooting, solution design, cross-functional collaboration, documentation

Education & certifications

M.S. Cyber Security

Yeshiva University, New York

Aug 2023 — May 2025

B.E. Electrical & Electronics Engineering

Siddharth Institute of Engineering, Tirupati, India

Aug 2017 — May 2021

CEH — Certified Ethical Hacker

EC-Council

Sep 2021 — Dec 2021

API Security Testing

Professional course

Jul 2021 — Nov 2021

Beyond the job

Attending cybersecurity conferences, reading blog posts and write-ups on vulnerabilities, and keeping up with how attackers evolve.