Summary
Overview
Work History
Education
Skills
Languages
Accomplishments
Certification
Timeline
Adrika Mukherjee

Adrika Mukherjee

Bangalore

Summary

Senior Cybersecurity Engineer with 6 + years of experience securing enterprise-scale cloud architectures, API endpoints and global web applications. Specializing in offensive security operations and automated defence with expertise in Web and API Penetration Testing (BOLA/BBP) and "Shift-Left" security integration within high-velocity DevSecOps environments. Expert at navigating the intersection of Cloud Security, API integrity (qAPI), and AI Governance. Expert in orchestrating CNAPP (Wiz/Prisma) to eliminate "Toxic Combinations" and hardening the CI/CD "pipe" against sophisticated supply-chain attacks.

Overview

7
7
years of professional experience
1
1
Certification

Work History

Senior Cybersecurity engineer

Decathlon Sports India
Bangalore
02.2025 - Current

1. Web & API Offensive Security Operations

  • Lead Full-Lifecycle Penetration Tests on internal Decathlon web applications and global API endpoints, utilizing Burp Suite Professional and Kali linux to identify critical-risk vulnerabilities.
  • Advanced API Security Auditing: Leveraged Postman and Swagger to perform deep-dive assessments on micro services, identifying high-impact Broken Object Level Authorization(BOLA) flaws.

2. Cloud & AI Security Posture Management

  • Orchestrated agentless deep-cloud assessments using Wiz (CNAPP) to identify and remediate critical "Toxic Combinations," directly improving the Global Digital Security Posture score.
  • Established an AI Security Framework to track weighted adherence to OWASP Top 10 for LLM & ML, ensuring the security health of the enterprise AI estate and improving AI security posture score.
  • Optimized Edge Security by leveraging Cloud flare WAF to identify and block evolving malicious payloads, significantly reducing the attack surface of public-facing web applications.
  • Designed performance-driven security monitoring in SplunkCloud and PrismaCloud, correlating resource utilization with security events to ensure high availability during peak traffic.

3. DevSecOps & API Orchestration

  • "Hardened the Pipe" by implementing strict access controls and identity-based permissions within CI/CD pipelines (Jenkins, GitHub Actions), preventing malicious code injection at the source.
  • Automated API Discovery using qAPI’s AI-driven engine, generating codeless test scripts and intelligent "assertions" that helped identify risks and reduce manual testing time.
  • Synchronized SAST/DAST integration within the SDLC to drastically reduce false positives and ensure developers focused on high-priority vulnerabilities.
  • Maintained regulatory integrity by ensuring all automated pipeline logs met stringent PCI-DSS and SOC2 standards for audit-readiness.

4. Strategic Leadership & Risk Governance

  • Directed Security Steering Committees, advising stakeholders on threat mitigation strategies and long-term posture improvements.
  • Bridged the technical-business gap by conducting risk assessments and delivering actionable remediation feedback to cross-functional teams (Engineering, Cloud, and Product). Analysed VAPT reports to identify open vulnerabilities in third-party vendor management.
  • Managed Global Phishing & Training programs, developing bespoke materials to prevent "human misuse" alerts across multiple international business units.
  • Overhauled Incident Response by on boarding third-party vendors and integrating the XMCO platform to consolidate vulnerability monitoring and closing alerts within given SLAs.

Senior Security Professional

Lexmark
Kolkata
02.2022 - 02.2025
  • Lead and execute comprehensive security assessments on web applications, API endpoints, and thick client applications, identifying vulnerabilities and providing actionable recommendations for remediation.
  • Conduct manual and automated penetration testing, and network scans via Nmap and Tenable.io.
  • Working on security assessment tools like Burp Suite Pro, Postman, Kali Linux, Metasploit, msfvenom, Hydra, Process Monitor, Wireshark, etc.
  • OWASP Top 10 concepts and implementations.
  • Collaborate with development and operations teams to integrate security best practices into the software development life cycle (SDLC), and agile model.
  • Maintained up-to-date knowledge of latest developments in information technology and cybersecurity trends. In monthly newsletters broadcast globally.
  • Monitored performance metrics to identify areas of improvement.

Senior Analyst

Capgemini
Mumbai
04.2019 - 02.2022
  • Mapped processes to holistically examine business flow and identify improvement opportunities.
  • Knowledge about OWASP top 10.
  • Running application security testing on Qualys Guard tool, burp suite, webinspect, etc.
  • Cybersecurity concepts, TCP/UDP, TLS/SSL protocol, 3 triads of security.
  • Decision-making, analytical skills.
  • Maintained updated knowledge base on industry trends and best practices.
  • Collaborated with IT teams on new tools and technologies.

Education

B.tech - Information Technology

B.P.Poddar Institute of Management and Technology, Kolkata, India
06.2018

Skills

  • Web App Pentesting: OWASP Top 10, Manual pentesting, Auth/Session Management, XSS/SQLi/CSRF, Business Logic Exploitation, security misconfigurations, IDOR
  • API Security: REST/GraphQL/SOAP, Broken Object Level Authorization (BOLA), JWT/OAuth 20, Mass Assignment
  • Tools: Burp Suite Professional (Advanced), Postman, Kali Linux, Swagger, SQLmap, Metasploit, Nmap, Wireshark, tenable io
  • Cloud & AI: Wiz (CNAPP), Prisma Cloud, Splunk cloud, OWASP Top 10 for LLM
  • DevSecOps: Jenkins, GitHub Actions, SAST/DAST automation, qAPI AI-driven assertions

Languages

  • English
  • Bengali
  • Hindi

Accomplishments

  • Won the best Kubernetes deployment team award at the prestigious Dine with DevOps event in Shangri-La, Bangalore We received an award for "Best Kubernetes Deployment Team (Retail & e-commerce)" on behalf of Decathlon Sports India in one of the flagship events for the DevOps industry.
  • Successfully participated and ran in The TCS World 10K Bengaluru 2025 which took place on Sunday, April 27, 2025. The TCS World 10K Bengaluru 2025 seems to have been a memorable and inspiring event, blending the thrill of competition with a strong sense of community and purpose.
  • Officially felicitated by Lexmark CEO Allen Waugerman for identifying and reporting a vulnerability in our Lexmark printer and ESF devices in the 2024 F2F Lexploit, my team had been very supportive, and we together reported many major vulnerabilities throughout our Lexmark printer devices.

Certification

  • The Certified Ethical Hacker (CEH) v12 certification from EC-Council

Timeline

Senior Cybersecurity engineer - Decathlon Sports India
02.2025 - Current
Senior Security Professional - Lexmark
02.2022 - 02.2025
Senior Analyst - Capgemini
04.2019 - 02.2022
B.P.Poddar Institute of Management and Technology - B.tech, Information Technology
Adrika Mukherjee