API Security Engineer and Trainer
Led API security assessments and penetration testing aligned to OWASP API Top 10 and OWASP Web Top 10, identifying weaknesses across authentication, authorization, and business logic. Executed reconnaissance, endpoint enumeration, fuzzing, and exploit validation using Swagger/OpenAPI specifications and security testing workflows. Improved cloud API security posture across AWS and Azure by applying IAM hardening, gateway protections, logging, and encryption controls while translating findings into remediation guidance. • Conducted structured API penetration testing including reconnaissance, fuzzing, and exploit validation • Evaluated API architectures for security misconfigurations, BOLA, and excessive data exposure • Researched LLM/NLP API threats such as prompt injection, data leakage, and model abuse • Co-facilitated and mentored 250+ participants in hands-on API security training labs and secure design practices