GRANDHE SAI SANATH

GRANDHE SAI SANATH

Chief Information Security Officer · Cybersecurity Professional · Ethical Hacker · Security Researcher

Alliance UniversityB.Tech CSE (Cyber Security)Bengaluru, Karnataka, India
Find the weakness. Secure the system.

Interesting Fact

Professional motto: “Find the weakness. Secure the system.” Combines hands-on offensive security with building security-focused software like an AI-powered phishing URL detector.

About

Cybersecurity professional focused on ethical hacking, penetration testing, vulnerability assessment and penetration testing (VAPT), web application security, vulnerability research, bug bounty, CTFs, security assessment, and practical offensive security. Experienced in identifying, validating, documenting, and responsibly disclosing security vulnerabilities through hands-on testing, client-oriented VAPT exposure, controlled security labs, CTF environments, and vulnerability disclosure platforms. Also experienced in building security-focused software, including an AI-powered phishing URL detection project, and applying security knowledge across application, network, and system-level scenarios.

Areas of Expertise

CybersecurityEthical HackingPenetration TestingVAPTWeb Application SecurityVulnerability ResearchBug BountyCTFSecurity AssessmentClient-oriented VAPTReconnaissanceEnumerationVulnerability ValidationSecurity ReportingAI in Cybersecurity

Tech Stack

Cybersecurity

Penetration TestingVAPTEthical HackingVulnerability AssessmentVulnerability ResearchBug BountyWeb Application SecurityNetwork SecuritySecurity AssessmentResponsible Disclosure

Web Security

SQL InjectionXSSCSRFAuthentication TestingAuthorization TestingSession SecurityInput ValidationAPI Security TestingSecurity MisconfigurationOWASP Top 10

Security Tools

Kali LinuxBurp SuiteNmapWiresharkMetasploit FrameworkNessusNiktoGobusterHydraJohn the Ripper

Programming & AI Security

PythonPythonBashCCGitGitGitHubGitHubREST APIsREST APIsLinuxWindowsPowerShellMachine Learning

Professional Experience

Chief Information Security Officer

August 28, 2026 – Present

NorthNode Technologies · Bengaluru, Karnataka, India

Provide cybersecurity direction and security-focused technical guidance. Work on security assessment, vulnerability identification, penetration-testing methodologies, and security risk analysis. Apply practical ethical-hacking knowledge to evaluate applications, systems, and potential attack surfaces. Support security testing, vulnerability management, remediation planning, and secure development practices with technical teams.

Practical Cybersecurity / VAPT Experience

Practical Experience

Cyart

Performed practical Vulnerability Assessment and Penetration Testing (VAPT) on client-oriented applications and environments. Conducted reconnaissance, enumeration, service discovery, and security testing based on assessment requirements. Performed web application security testing, used Burp Suite for HTTP request interception and analysis, Nmap for network discovery and port scanning, and Wireshark for packet capture and network traffic analysis. Analyzed identified security weaknesses and contributed to documenting technical findings.

Cybersecurity Training / Internship

2025

NullClass

Completed hands-on cybersecurity training focused on real-time web application hacking. Practiced vulnerability discovery, validation, exploitation techniques, and responsible disclosure in controlled environments. Tested web applications for common OWASP Top 10 vulnerabilities including SQL Injection, XSS, CSRF, authentication and authorization testing, and other web-security scenarios using Kali Linux and penetration-testing utilities.

Featured Projects

AI-Powered Phishing Detector

Machine-Learning Security Application

Developer / Security Researcher

Developed a Python-based phishing URL detection system to identify and classify potentially malicious URLs using machine learning.

  • Built and trained a machine-learning classification model using real-world datasets.
  • Prepared and processed data for model training and evaluation.
  • Implemented feature-based analysis to identify URL characteristics associated with phishing activity.
  • Created the trained model as phishing_model.pkl and evaluated its threat-detection capability.
PythonMachine LearningCybersecurityPhishing DetectionThreat Detection

Path Sentinel

Cybersecurity-Focused Security Project

Developer / Security Researcher

Designed and developed Path Sentinel as a practical cybersecurity-focused project applying security concepts to identify potential risks and improve security visibility.

  • Implemented security-oriented logic and functionality with emphasis on threat identification and handling.
  • Applied practical penetration-testing and vulnerability-assessment knowledge during development.
  • Tested security-related scenarios and refined the implementation around practical cybersecurity requirements.
CybersecuritySecurity TestingVulnerability AssessmentThreat DetectionSecurity Automation

Bug Bounty & Vulnerability Research

Authorized Security Testing

Security Researcher

Performed authorized security testing through bug-bounty and vulnerability disclosure programs on platforms including YesWeHack and Bugcrowd.

  • Conducted reconnaissance, manual testing, vulnerability validation, and impact analysis.
  • Discovered and reported valid security vulnerabilities with structured P4+ severity reports.
  • Prepared technical reports containing reproduction steps, impact analysis, and remediation suggestions.
  • Followed responsible disclosure and ethical-hacking standards throughout the reporting process.
Bug BountyYesWeHackBugcrowdVulnerability ResearchResponsible Disclosure

CTF Challenges & Web Application Security

Capture The Flag / Security Training

Participant / Security Tester

Participated in CTF competitions and controlled environments designed around real-world offensive-security scenarios.

  • Worked on Mr. Robot CTF challenges and practiced reconnaissance, enumeration, exploitation, and problem solving.
  • Applied practical knowledge of SQL Injection, XSS, CSRF, and other OWASP Top 10 vulnerabilities.
  • Used Burp Suite to inspect, intercept, modify, and analyze HTTP requests and responses.
CTFBurp SuiteOWASP Top 10Web Application SecurityEthical Hacking

Awards & Achievements

Zodiak CTF Qualifiers 2026

Rank #135 / 1,252

Participated from 21–23 August 2026, representing THE BITE, as shown on the certificate of participation.

Bug Bounty Success

YesWeHack · Bugcrowd

Discovered and responsibly reported valid vulnerabilities through YesWeHack and Bugcrowd with structured P4+ severity reports.

Security Research

Vulnerability Disclosure

Prepared technical P4+ vulnerability reports with reproduction details, impact analysis, and remediation guidance.

Practical Security Exposure

Offensive Security

Hands-on exposure to web application penetration testing, network analysis, reconnaissance, exploitation, and security reporting.

Certifications

Certified Ethical Hacker (CEH v13)

EC-Council

Cybersecurity Training — Real-time Web Application Hacking

NullClass

Software Foundation Program

IBM

Identity and Access Management (IAM) Training

IBM

Introduction to Penetration Testing

Centri

Introduction to PowerShell

Centri

Certificate of Participation — Zodiak CTF Qualifiers

Zodiak CTF

Leadership & Contribution

Biggest Contribution

Bridge practical penetration testing with software-development understanding when evaluating application security. Support NorthNode teams in identifying security weaknesses, improving security posture, and applying secure development practices across products and systems.

Most Important Achievement

Provide cybersecurity leadership as Chief Information Security Officer. Guide security-focused technical decisions and practical security assessments. Apply offensive-security knowledge to identify attack paths, weaknesses, and security risks. Support vulnerability management, security testing, remediation planning, and secure engineering practices.

Philosophy

Find the weakness. Secure the system.

Personal

Interests

CybersecurityEthical HackingPenetration TestingBug BountyVulnerability ResearchAI in CybersecurityWeb Application SecurityCTFsTechnologySecurity Research

Hobbies

Cybersecurity researchCTF challengesExploring security toolsBuilding cybersecurity projectsLearning new technologiesExperimenting with software and security techniques