Shashank Mudgal, Developer in Alwar, Rajasthan, India
Shashank is available for hire
Hire Shashank

Shashank Mudgal

Bio

Shashank is a cloud security engineer who secures AWS systems using IAM least-privilege, Zero Trust, and secure-by-design principles. He is experienced in web and API penetration testing, bug bounty hunting, smart contract security, and identifying critical vulnerabilities in production. Shashank has completed a postgraduate coursework in cybersecurity, strengthening threat modeling, and secure architecture.

Portfolio

Craw Security
Burp Suite, Penetration Testing, Cloud Security, OWASP Top 10, SecOps...
An Online Freelance Agency
Burp Suite, AWS IoT, AWS Cloud Security, Cloud Security, Penetration Testing...

Experience

  • NMap - 6 years
  • Burp Suite - 6 years
  • Cloud Security Engineering - 5 years
  • Cloud Security - 3 years
  • Postman - 3 years
  • Ansible File Audit - 1 year
  • Terraform - 1 year
  • GitHub Actions - 1 year

Preferred Environment

Linux, Burp Suite, Cloud Security, Cloud Security Engineering, OWASP Zed Attack Proxy (ZAP), Postman, NMap, AWS IoT, Terraform, Ansible, Python

The most amazing...

...thing I've done is secure diverse cloud-based apps on AWS using IAM, least-privilege, and secure-by-design principles.

Work Experience

Penetration Tester

2024 - 2025
Craw Security
  • Executed penetration tests across multiple client environments and identified vulnerabilities in web applications, APIs, and network configurations.
  • Performed security assessments using Burp Suite, Nmap, OWASP ZAP, and Nessus to validate vulnerabilities aligned with OWASP Top 10 risks.
  • Automated reconnaissance and port-scanning workflows for 1,000+ endpoints using Python and Nmap, reducing manual testing time by 20+ hours per project.
  • Assisted in validating and tracking remediation for 10+ security vulnerabilities across client applications and infrastructure environments.
  • Prepared technical vulnerability reports containing proof-of-concept (PoC) steps, impact analysis, and remediation recommendations for identified issues.
Technologies: Burp Suite, Penetration Testing, Cloud Security, OWASP Top 10, SecOps, Certified Ethical Hacker (CEH), Python

IT Security Specialist

2020 - 2025
An Online Freelance Agency
  • Designed and secured AWS cloud architectures with a focus on IAM hardening, network segmentation, least-privilege access, and attack surface reduction.
  • Built and deployed infrastructure using Terraform and Ansible to automate secure provisioning, configuration management, and repeatable deployment workflows.
  • Conducted penetration tests for clients across financial services, healthcare, SaaS, and startup environments under strict NDA requirements.
  • Discovered and responsibly disclosed 30+ high and critical vulnerabilities, including remote code execution (RCE), SQL injection, SSRF, and authentication flaws.
  • Collaborated directly with founders, developers, and engineering teams to identify security gaps early in the development lifecycle and improve overall system resilience.
Technologies: Burp Suite, AWS IoT, AWS Cloud Security, Cloud Security, Penetration Testing, Web App Testing, OWASP Top 10, OWASP Zed Attack Proxy (ZAP), Log Analysis, System Architecture Design, DevSecOps, IT Security, Risk Management, SecOps, Certified Ethical Hacker (CEH), Python

Experience

Secure Cloud Architecture Design on AWS

Designed and architected a comprehensive, security-first cloud infrastructure on AWS for a client engagement. The architecture emphasized compliance, auditability, and defense-in-depth principles across all layers.

KEY CONTRIBUTIONS
• Architected a multi-tier VPC with public, private, and isolated subnets, security groups, and NACLs to enforce strict network segmentation.
• Enabled AWS CloudTrail across all regions for full audit logging of API activity, integrated with S3 for durable, tamper-evident log storage.
• Designed S3 bucket policies with encryption at rest (SSE-S3/KMS), versioning, and access control to meet data security standards.
• Leveraged availability zones (AZs) for high availability and fault tolerance across critical components.
• Incorporated IAM roles and least-privilege access policies to minimize the attack surface.
• Ensured the architecture aligned with industry security frameworks such as CIS AWS Foundations Benchmark and AWS Well-Architected Framework (Security Pillar).

IMPACT
Delivered a production-ready, auditable cloud architecture that reduced security risk exposure and provided a scalable foundation for future infrastructure growth.

Reentrancy Attack Simulation Lab for Smart Contract Security

Designed and developed a hands-on Smart Contract Security Lab simulating real-world reentrancy vulnerabilities in Ethereum-based decentralized applications.

KEY CONTRIBUTIONS
• Built vulnerable and attacker smart contracts in Solidity to demonstrate realistic exploitation scenarios, including unauthorized fund drainage.
• Simulated multiple attack vectors—simple reentrancy and cross-function reentrancy—within EVM environments to study execution behavior.
• Developed PoC exploit flows exposing insecure state handling, risky external call patterns, and improper balance update sequences.
• Conducted in-depth attack-flow analysis covering recursive call chains, transaction execution order, and smart contract state manipulation.
• Applied findings toward smart contract auditing research, vulnerability documentation, and blockchain security education.

IMPACT
Produced a reusable security lab that bridges theoretical vulnerability knowledge with practical exploit simulation, valuable for auditing Solidity codebases and training developers in secure smart contract design.

VulnRecon Automation Framework

VulnRecon, a modular, automated Bug Bounty Reconnaissance Framework (BBRF) built in Bash that consolidates 15+ industry-standard security and reconnaissance tools into a single, cohesive workflow, significantly reducing manual effort and accelerating vulnerability discovery.

KEY CONTRIBUTIONS
• Integrated a curated suite of 15+ security tools, including Assetfinder, Naabu, Arjun, WaybackURLs, Wafw00f, and Nuclei.
• Implemented a modular switch-based execution model allowing selective tool activation.
• Automated critical recon phases, including subdomain discovery, port scanning, parameter enumeration, historical URL collection, WAF detection, and vulnerability scanning, collapsing multi-step manual processes into a single command.
• Designed chained tool execution flows where output from one tool feeds directly into the next, maximizing coverage and minimizing redundant scans across large attack surfaces.

IMPACT
VulnRecon reduced reconnaissance time significantly by automating what would otherwise require manual coordination across dozens of tools, delivering a production-ready framework applicable to real-world bug bounty programs, penetration testing workflows, and continuous attack surface monitoring.

Education

2018 - 2021

Bachelor's Degree in Computer Science

KCRI College - Alwar, Rajasthan

Certifications

APRIL 2025 - PRESENT

The GRC Approach to Managing Cybersecurity

Kennesaw State University

FEBRUARY 2025 - PRESENT

Penetration Testing, Threat Hunting, and Cryptography

IBM

JANUARY 2025 - PRESENT

Networking Devices and Initial Configuration

Cisco

Skills

Tools

OWASP Zed Attack Proxy (ZAP), NMap, Postman, Terraform, Metasploit, AWS IAM, Ansible

Languages

Solidity, Python, JavaScript, SQL, Bash Script

Paradigms

Object-oriented Programming (OOP), Penetration Testing, DevSecOps, HIPAA Compliance

Platforms

Burp Suite, Linux, AWS IoT

Storage

Database Management Systems (DBMS)

Other

Cloud Security, Cloud Security Engineering, Terraform File Audit, Ansible File Audit, IT Security, Certified Ethical Hacker (CEH), GitHub Actions, Computer Networking, Foundry, Risk Management, SecOps, Operating Systems, OWASP Top 10, Source Code Review, System Architecture Design, AWS Cloud Security, Web App Testing, Log Analysis, Cyber Threat Hunting, Penetration Testing Lifecycle, IT Networking, ISO 27001, GRC, PCI DSS

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring