๐Ÿ‡ณ๐Ÿ‡ต Rojan Shrestha

Cybersecurity Professional | VAPT Specialist | Ethical Hacker
๐Ÿ”’ Vulnerability Assessment & Penetration Testing
๐Ÿ“ก shrestharojan025.com.np

About Me

Cybersecurity undergraduate with 11+ months of internship experience in Offensive Security and Vulnerability Assessment and Penetration Testing (VAPT).

Uncovered 30+ vulnerabilities across 8+ web applications, reducing open security issues by 40% through CVSS-rated reporting and remediation re-testing.

Proficient in Burp Suite, Nmap, SQLmap, Metasploit, OWASP ZAP, Wazuh/OSSEC SIEM, and Kali Linux.

๐Ÿ“ง shrestharojan025@gmail.com ๐Ÿ“ž +977 9803845800 ๐Ÿ“ Chapagaun, Lalitpur, Nepal

๐Ÿ› ๏ธ Technical Skills

Burp Suite OWASP ZAP Nmap SQLmap Metasploit Kali Linux Wireshark Wazuh/OSSEC CVSS Scoring Python Bash Git AWS Cloud SIEM

๐Ÿ’ผ Experience

Quality Assurance & VAPT Intern
Xelvian Solutions Pvt. Ltd.
Jan 2026 - April 2026
  • Identified 10+ security weaknesses across 3+ web modules through manual and automated testing.
  • Reduced open security issues by ~40% via CVSS-rated documentation and remediation re-testing.
  • Integrated security compliance into QA cycles within a secure SDLC framework.
Offensive Security Intern
Cryptogen Nepal
Jun 2025 - Nov 2025
  • Uncovered 20+ critical vulnerabilities across 5+ web apps using Burp Suite, Nmap, SQLmap, OWASP ZAP, and Metasploit.
  • Identified OWASP Top 10 flaws including SQLi, XSS, CSRF, Command Injection, and Broken Authentication.
  • Authored 3+ pentest reports with CVSS ratings, PoC documentation, and remediation guidance.

๐Ÿš€ Key Projects

Web Application VAPT โ€” DVWA
Burp Suite ยท Nmap ยท SQLmap ยท Metasploit ยท Kali Linux
  • Exploited 8+ OWASP Top 10 vulnerabilities โ€” SQL Injection, Reflected/Stored XSS, CSRF, Command Injection, File Inclusion, and Broken Authentication.
  • Tested across Low, Medium, and High DVWA security configurations with full PoC documentation.
  • Analyzed mitigation effectiveness and attack vectors mapping to defensive controls.
Wazuh & OSSEC SIEM Deployment
Wazuh ยท OSSEC ยท Ubuntu Linux ยท Kali Linux
  • Architected and deployed HIDS environment on Ubuntu Server integrating Wazuh and OSSEC across 2 monitored endpoints.
  • Configured File Integrity Monitoring (FIM), log collection pipelines, custom alerting, and event correlation rules.
  • Simulated adversarial activities (file modifications, privilege escalation) and investigated 15+ security events.

๐Ÿ“œ Certifications

Ethical Hacker

Cisco Networking Academy ยท 2024

Certified Cybersecurity Educator Professional (CCEP)

RedTeamLeaders ยท 2025

AWS Cloud Practitioner Essentials

Amazon Web Services ยท 2023

Essentials of Security Policies & Procedures (ESSP)

Corp Security ยท 2024

Network Defense

Cisco Networking Academy

๐Ÿ† Achievements

๐ŸŽฏ 2nd Place โ€” CTF 2.0

IIMS-HACK@SEC 2025

๐Ÿ’ฐ Internship

Money Mitra Network ยท Cyber Security

๐Ÿ“˜ Diploma in Computer Application

Fast Track ยท 2019

๐ŸŽ“ Education

Bachelor's in Computer Science (Hons) โ€” Cyber Security Specialization
IIMS College / Taylor's University, Kathmandu
2023 - Present
  • CGPA: 3.70 / 4.00
  • Dean's List