
Interesting Fact
“Professional motto: “Find the weakness. Secure the system.” Combines hands-on offensive security with building security-focused software like an AI-powered phishing URL detector.”
GRANDHE SAI SANATH
Chief Information Security Officer · Cybersecurity Professional · Ethical Hacker · Security Researcher
“Find the weakness. Secure the system.”
Interesting Fact
“Professional motto: “Find the weakness. Secure the system.” Combines hands-on offensive security with building security-focused software like an AI-powered phishing URL detector.”
About
Cybersecurity professional focused on ethical hacking, penetration testing, vulnerability assessment and penetration testing (VAPT), web application security, vulnerability research, bug bounty, CTFs, security assessment, and practical offensive security. Experienced in identifying, validating, documenting, and responsibly disclosing security vulnerabilities through hands-on testing, client-oriented VAPT exposure, controlled security labs, CTF environments, and vulnerability disclosure platforms. Also experienced in building security-focused software, including an AI-powered phishing URL detection project, and applying security knowledge across application, network, and system-level scenarios.
Areas of Expertise
Tech Stack
Cybersecurity
Web Security
Security Tools
Programming & AI Security
Professional Experience
Chief Information Security Officer
August 28, 2026 – PresentNorthNode Technologies · Bengaluru, Karnataka, India
Provide cybersecurity direction and security-focused technical guidance. Work on security assessment, vulnerability identification, penetration-testing methodologies, and security risk analysis. Apply practical ethical-hacking knowledge to evaluate applications, systems, and potential attack surfaces. Support security testing, vulnerability management, remediation planning, and secure development practices with technical teams.
Practical Cybersecurity / VAPT Experience
Practical ExperienceCyart
Performed practical Vulnerability Assessment and Penetration Testing (VAPT) on client-oriented applications and environments. Conducted reconnaissance, enumeration, service discovery, and security testing based on assessment requirements. Performed web application security testing, used Burp Suite for HTTP request interception and analysis, Nmap for network discovery and port scanning, and Wireshark for packet capture and network traffic analysis. Analyzed identified security weaknesses and contributed to documenting technical findings.
Cybersecurity Training / Internship
2025NullClass
Completed hands-on cybersecurity training focused on real-time web application hacking. Practiced vulnerability discovery, validation, exploitation techniques, and responsible disclosure in controlled environments. Tested web applications for common OWASP Top 10 vulnerabilities including SQL Injection, XSS, CSRF, authentication and authorization testing, and other web-security scenarios using Kali Linux and penetration-testing utilities.
Featured Projects
AI-Powered Phishing Detector
Machine-Learning Security Application
Developer / Security Researcher
Developed a Python-based phishing URL detection system to identify and classify potentially malicious URLs using machine learning.
- Built and trained a machine-learning classification model using real-world datasets.
- Prepared and processed data for model training and evaluation.
- Implemented feature-based analysis to identify URL characteristics associated with phishing activity.
- Created the trained model as phishing_model.pkl and evaluated its threat-detection capability.
Path Sentinel
Cybersecurity-Focused Security Project
Developer / Security Researcher
Designed and developed Path Sentinel as a practical cybersecurity-focused project applying security concepts to identify potential risks and improve security visibility.
- Implemented security-oriented logic and functionality with emphasis on threat identification and handling.
- Applied practical penetration-testing and vulnerability-assessment knowledge during development.
- Tested security-related scenarios and refined the implementation around practical cybersecurity requirements.
Bug Bounty & Vulnerability Research
Authorized Security Testing
Security Researcher
Performed authorized security testing through bug-bounty and vulnerability disclosure programs on platforms including YesWeHack and Bugcrowd.
- Conducted reconnaissance, manual testing, vulnerability validation, and impact analysis.
- Discovered and reported valid security vulnerabilities with structured P4+ severity reports.
- Prepared technical reports containing reproduction steps, impact analysis, and remediation suggestions.
- Followed responsible disclosure and ethical-hacking standards throughout the reporting process.
CTF Challenges & Web Application Security
Capture The Flag / Security Training
Participant / Security Tester
Participated in CTF competitions and controlled environments designed around real-world offensive-security scenarios.
- Worked on Mr. Robot CTF challenges and practiced reconnaissance, enumeration, exploitation, and problem solving.
- Applied practical knowledge of SQL Injection, XSS, CSRF, and other OWASP Top 10 vulnerabilities.
- Used Burp Suite to inspect, intercept, modify, and analyze HTTP requests and responses.
Awards & Achievements
Zodiak CTF Qualifiers 2026
Rank #135 / 1,252
Participated from 21–23 August 2026, representing THE BITE, as shown on the certificate of participation.
Bug Bounty Success
YesWeHack · Bugcrowd
Discovered and responsibly reported valid vulnerabilities through YesWeHack and Bugcrowd with structured P4+ severity reports.
Security Research
Vulnerability Disclosure
Prepared technical P4+ vulnerability reports with reproduction details, impact analysis, and remediation guidance.
Practical Security Exposure
Offensive Security
Hands-on exposure to web application penetration testing, network analysis, reconnaissance, exploitation, and security reporting.
Certifications
Certified Ethical Hacker (CEH v13)
EC-Council
Cybersecurity Training — Real-time Web Application Hacking
NullClass
Software Foundation Program
IBM
Identity and Access Management (IAM) Training
IBM
Introduction to Penetration Testing
Centri
Introduction to PowerShell
Centri
Certificate of Participation — Zodiak CTF Qualifiers
Zodiak CTF
Leadership & Contribution
Biggest Contribution
Bridge practical penetration testing with software-development understanding when evaluating application security. Support NorthNode teams in identifying security weaknesses, improving security posture, and applying secure development practices across products and systems.
Most Important Achievement
Provide cybersecurity leadership as Chief Information Security Officer. Guide security-focused technical decisions and practical security assessments. Apply offensive-security knowledge to identify attack paths, weaknesses, and security risks. Support vulnerability management, security testing, remediation planning, and secure engineering practices.
Philosophy
Find the weakness. Secure the system.
Personal
Interests
Hobbies