
Shashank Mudgal
Verified Expert in Engineering
Cybersecurity Developer
Alwar, Rajasthan, India
Toptal member since May 11, 2026
Shashank is a cloud security engineer who secures AWS systems using IAM least-privilege, Zero Trust, and secure-by-design principles. He is experienced in web and API penetration testing, bug bounty hunting, smart contract security, and identifying critical vulnerabilities in production. Shashank has completed a postgraduate coursework in cybersecurity, strengthening threat modeling, and secure architecture.
Portfolio
Experience
- NMap - 6 years
- Burp Suite - 6 years
- Cloud Security Engineering - 5 years
- Cloud Security - 3 years
- Postman - 3 years
- Ansible File Audit - 1 year
- Terraform - 1 year
- GitHub Actions - 1 year
Preferred Environment
Linux, Burp Suite, Cloud Security, Cloud Security Engineering, OWASP Zed Attack Proxy (ZAP), Postman, NMap, AWS IoT, Terraform, Ansible, Python
The most amazing...
...thing I've done is secure diverse cloud-based apps on AWS using IAM, least-privilege, and secure-by-design principles.
Work Experience
Penetration Tester
Craw Security
- Executed penetration tests across multiple client environments and identified vulnerabilities in web applications, APIs, and network configurations.
- Performed security assessments using Burp Suite, Nmap, OWASP ZAP, and Nessus to validate vulnerabilities aligned with OWASP Top 10 risks.
- Automated reconnaissance and port-scanning workflows for 1,000+ endpoints using Python and Nmap, reducing manual testing time by 20+ hours per project.
- Assisted in validating and tracking remediation for 10+ security vulnerabilities across client applications and infrastructure environments.
- Prepared technical vulnerability reports containing proof-of-concept (PoC) steps, impact analysis, and remediation recommendations for identified issues.
IT Security Specialist
An Online Freelance Agency
- Designed and secured AWS cloud architectures with a focus on IAM hardening, network segmentation, least-privilege access, and attack surface reduction.
- Built and deployed infrastructure using Terraform and Ansible to automate secure provisioning, configuration management, and repeatable deployment workflows.
- Conducted penetration tests for clients across financial services, healthcare, SaaS, and startup environments under strict NDA requirements.
- Discovered and responsibly disclosed 30+ high and critical vulnerabilities, including remote code execution (RCE), SQL injection, SSRF, and authentication flaws.
- Collaborated directly with founders, developers, and engineering teams to identify security gaps early in the development lifecycle and improve overall system resilience.
Experience
Secure Cloud Architecture Design on AWS
KEY CONTRIBUTIONS
• Architected a multi-tier VPC with public, private, and isolated subnets, security groups, and NACLs to enforce strict network segmentation.
• Enabled AWS CloudTrail across all regions for full audit logging of API activity, integrated with S3 for durable, tamper-evident log storage.
• Designed S3 bucket policies with encryption at rest (SSE-S3/KMS), versioning, and access control to meet data security standards.
• Leveraged availability zones (AZs) for high availability and fault tolerance across critical components.
• Incorporated IAM roles and least-privilege access policies to minimize the attack surface.
• Ensured the architecture aligned with industry security frameworks such as CIS AWS Foundations Benchmark and AWS Well-Architected Framework (Security Pillar).
IMPACT
Delivered a production-ready, auditable cloud architecture that reduced security risk exposure and provided a scalable foundation for future infrastructure growth.
Reentrancy Attack Simulation Lab for Smart Contract Security
KEY CONTRIBUTIONS
• Built vulnerable and attacker smart contracts in Solidity to demonstrate realistic exploitation scenarios, including unauthorized fund drainage.
• Simulated multiple attack vectors—simple reentrancy and cross-function reentrancy—within EVM environments to study execution behavior.
• Developed PoC exploit flows exposing insecure state handling, risky external call patterns, and improper balance update sequences.
• Conducted in-depth attack-flow analysis covering recursive call chains, transaction execution order, and smart contract state manipulation.
• Applied findings toward smart contract auditing research, vulnerability documentation, and blockchain security education.
IMPACT
Produced a reusable security lab that bridges theoretical vulnerability knowledge with practical exploit simulation, valuable for auditing Solidity codebases and training developers in secure smart contract design.
VulnRecon Automation Framework
KEY CONTRIBUTIONS
• Integrated a curated suite of 15+ security tools, including Assetfinder, Naabu, Arjun, WaybackURLs, Wafw00f, and Nuclei.
• Implemented a modular switch-based execution model allowing selective tool activation.
• Automated critical recon phases, including subdomain discovery, port scanning, parameter enumeration, historical URL collection, WAF detection, and vulnerability scanning, collapsing multi-step manual processes into a single command.
• Designed chained tool execution flows where output from one tool feeds directly into the next, maximizing coverage and minimizing redundant scans across large attack surfaces.
IMPACT
VulnRecon reduced reconnaissance time significantly by automating what would otherwise require manual coordination across dozens of tools, delivering a production-ready framework applicable to real-world bug bounty programs, penetration testing workflows, and continuous attack surface monitoring.
Education
Bachelor's Degree in Computer Science
KCRI College - Alwar, Rajasthan
Certifications
The GRC Approach to Managing Cybersecurity
Kennesaw State University
Penetration Testing, Threat Hunting, and Cryptography
IBM
Networking Devices and Initial Configuration
Cisco
Skills
Tools
OWASP Zed Attack Proxy (ZAP), NMap, Postman, Terraform, Metasploit, AWS IAM, Ansible
Languages
Solidity, Python, JavaScript, SQL, Bash Script
Paradigms
Object-oriented Programming (OOP), Penetration Testing, DevSecOps, HIPAA Compliance
Platforms
Burp Suite, Linux, AWS IoT
Storage
Database Management Systems (DBMS)
Other
Cloud Security, Cloud Security Engineering, Terraform File Audit, Ansible File Audit, IT Security, Certified Ethical Hacker (CEH), GitHub Actions, Computer Networking, Foundry, Risk Management, SecOps, Operating Systems, OWASP Top 10, Source Code Review, System Architecture Design, AWS Cloud Security, Web App Testing, Log Analysis, Cyber Threat Hunting, Penetration Testing Lifecycle, IT Networking, ISO 27001, GRC, PCI DSS
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring