
Prashant Dangi
Verified Expert in Engineering
Offensive Security Expert and Developer
Bengaluru, Karnataka, India
Toptal member since September 9, 2026
Prashant is an offensive security professional specializing in VAPT, cloud security, and red teaming, with 3 years of hands-on experience as an independent consultant and corporate subject matter expert (SME). He has executed 20+ end-to-end pentests across web apps, APIs, networks, and major cloud platforms. A holder of an ISO 27001 Lead Security Auditor certification, Prashant pairs technical exploit discovery with enterprise GRC alignment, compliance, and custom cyber-range architecture.
Portfolio
Experience
- Penetration Testing - 3 years
- Bash - 3 years
- Git - 3 years
- Linux - 3 years
- Python - 3 years
- Risk Management - 2 years
- AWS IAM - 2 years
- Docker - 2 years
Preferred Environment
AWS IAM, Linux, Python, Bash
The most amazing...
...thing I've done is reverse-engineer a complex Java application to analyze bytecodes, bypass obfuscation, and fix critical zero-day bugs.
Work Experience
SME, Cybersecurity
Scaler Academy
- Designed and delivered an end-to-end offensive security curriculum directly mapped to SOC, VAPT, and GRC roles. Integrated web, API, and network penetration testing, red team TTPs, Active Directory attack paths, and complete MITRE ATT&CK alignment.
- Architected and deployed cloud-native lab environments on AWS using custom Windows and Linux images. Authored one-click Bash automation scripts to provision full-stack scenarios for Linux kernel security, Windows hardening, and lateral movement.
- Engineered Python automation scripts for rapid question generation and assessment workflows. Designed and deployed an AI chatbot following core system-design principles to minimize Claude API overhead while accelerating curriculum engineering.
- Provided dedicated Tier 3 support and live class troubleshooting across complex networking, Linux system internals, and Active Directory environments.
- Partnered with DevOps teams to author the Forward Deployed Engineer (FDE) curriculum. Designed and hosted competitive Capture the Flag (CTF) challenges to systematically validate and measure hands-on domain mastery.
Expert Cybersecurity Professional
An Online Freelance Agency
- Enhanced security frameworks and compliance guardrails across the Azure cloud infrastructure to protect critical workloads.
- Conducted extensive end-to-end vulnerability assessments and penetration tests across web applications and network environments.
- Implemented reverse engineering strategies on Java applications to develop robust software protection mechanisms.
- Formulated actionable risk assessment models and compliance strategies to streamline client security postures.
- Authored and delivered structured cybersecurity training presentations to educate technical teams and foster security-first practices.
Cybersecurity Analyst
Ascella InfoSec
- Implemented governance, risk, and compliance (GRC), risk assessment, risk management, policies, and procedures for CheckMed.
- Conducted web application penetration testing (WAPT) and reported 10+ vulnerabilities on an Azure-hosted web app.
- Developed and implemented a comprehensive risk management framework, ensuring secure API integrations and compliance with industry standards.
Experience
Real-time High-risk CVE Monitoring from CISA KEV and NVD
A Python 3.12 ETL job pulls KEV, enriches each CVE via the NVD REST API 2 with API key rate limits, retries, and backoff, and writes a static JSON feed. GitHub Actions refreshes that feed hourly and deploys a zero-back-end dashboard on GitHub Pages. The front end, built with Vanilla JavaScript, HTML, and CSS, adds time-window and CVSS filters, vendor, product, and CVE search, ransomware-use tags, federal patch due dates, and a live CISA fallback if the static feed is missing or stale.
The result is a continuously updated public radar for today's in-the-wild threats, critical scores, and affected vendors, with no application server to operate.
Education
Bachelor's Degree in Computer Science
Bennett University - Greater Noida, India
Certifications
Certified Ethical Hacker (CEH)
EC-Council
Skills
Tools
AWS IAM, Azure Network Security Groups, Terraform, NMap, Metasploit, Sqlmap, SonarQube, Splunk, Wireshark, Git, GitHub, Kubernetes Operators, CodeQL
Paradigms
Penetration Testing, Secure Code Best Practices, HIPAA Compliance, Role-based Access Control (RBAC), DevSecOps, REST
Industry Expertise
Cybersecurity
Languages
Kusto Query Language (KQL), CSS, Python, Verilog, Bash, JavaScript, Java, Bash Script
Platforms
Azure, Google Cloud Platform (GCP), Docker, Linux, Azure Web Apps, AWS IoT, Windows, Kubernetes, Cloud Run
Other
IT Security, Security Architecture, Application Security, Certified Ethical Hacker (CEH), Ethical Hacking, Agentic AI, AI Agents, Security, OWASP Top 10, GitHub Security, Static Application Security Testing (SAST), AWS Cloud Security, Data Governance, Risk Management, Risk Assessment, AWS Identity and Access Management, Threat Modeling, Cloud Security, Compliance, IT Audits, IT Contracts, NIST, External Audits, Identity & Access Management (IAM), AI Security, AI Trust, Risk and Security Management (AI TRiSM), Artificial Intelligence (AI), Large Language Models (LLMs), Prompt Injection, Multi-agent Systems, Azure Government, Microsoft Azure, Wiz Cloud Security Platform, Azure CLI, Governance, Data Protection, Incident Response, Information Security, AI Governance, Consumer Data Rights (CDR), Open-source Intelligence (OSINT), Nikto, Hydraulic Engineering, Assembly (MIPS), Security Groups, Security Engineering, Azure Cloud Security, Access Control, IT Infrastructure, Vulnerability Assessment, Network Security, Reverse Engineering, GRC, ISO 27001, Threat Analysis and Risk Assessment (TARA), Information Security Management Systems (ISMS), Offensive Security, Security Operations Centers (SOC), AI Chatbots, AI Red Teaming, Reconnaissance & Footprinting, Network & Infrastructure Scanning, Vulnerability Analysis, System Hacking, Web Application & Server Hacking, Evasion Techniques, APIs, IT Operations Management (ITOM), Azure Resource Manager (ARM)
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring