I am Ishan Saha, a security professional with 8+ years of experience specializing in offensive security, red teaming, cloud security (Azure and AWS), and web & mobile application assessments. I have worked with clients across finance, IT, manufacturing, energy & oil, auto manufacturing, retail, healthcare, telecom, and more. I am passionate about helping organizations reduce risk through practical, result-driven security programs. I have earned OSCP, CISA, ISO 27001, CRTP, CEH certifications and have Python coding experience including publishing CVEs; I also enjoy building tooling to automate assessments and improve overall security posture.

Ishan Saha

I am Ishan Saha, a security professional with 8+ years of experience specializing in offensive security, red teaming, cloud security (Azure and AWS), and web & mobile application assessments. I have worked with clients across finance, IT, manufacturing, energy & oil, auto manufacturing, retail, healthcare, telecom, and more. I am passionate about helping organizations reduce risk through practical, result-driven security programs. I have earned OSCP, CISA, ISO 27001, CRTP, CEH certifications and have Python coding experience including publishing CVEs; I also enjoy building tooling to automate assessments and improve overall security posture.

Available to hire
See more

Experience Level

Expert
Expert
Expert
Expert
Intermediate
Intermediate

Work Experience

Security Consultant at Dehaat
July 1, 2025 - January 1, 2026
Conducted offensive security assessments including red team exercises, attack surface mapping, penetration testing (web, API, mobile, network VAPT), secure code review, and cloud infrastructure testing to identify vulnerabilities per OWASP Top 10; triaged false positives/negatives; managed CI/CD vulnerability pipeline and maintained risk records; reinforced security posture during change management; protected data and mitigated loss; evaluated cloud architecture gaps; promoted security awareness and provided social engineering simulations and training.
Security Engineer at Shyftlabs
April 1, 2024 - June 1, 2025
Conducted offensive security tests (red team, attack surface mapping, penetration testing, secure code review, web/api/mobile/network VAPT) on web apps and cloud infrastructure; identified and rectified vulnerabilities per OWASP Top 10; distinguished false positives/negatives; managed vulnerabilities from CI/CD pipeline; managed security posture for change management; fortified networks and applications; assessed cloud architecture security; promoted security awareness and provided cybersecurity training and social engineering programs.
Consultant at KPMG Assurance & Consulting
March 1, 2021 - March 1, 2024
Led offensive security and red team activities; developed Python-based tooling and exploits for security assessments; performed risk assessments and risk management; threat modeling; managed Offensive Security, Red Teaming, Purple Teaming, DAST & SAST for applications, including targeting critical devices within the PDU network; provided actionable remediation recommendations; fostered security awareness; delivered social engineering training; supported SOC, ITGC & ISO audits; built vendor risk management solutions in Python FastAPI; created exploit scripts; performed user access reviews (RBAC, PBAC) and asset management.
Associate Consultant at Deep Logic Tech India Pvt Ltd
March 1, 2020 - March 1, 2021
Assessed cybersecurity risks and guided risk management implementations; performed offensive security activities including application, network, and mobile app penetration tests across public and private networks; executed Red Teaming, Grey Box, Black Box, and Purple Teaming within telecom and production environments; analyzed vulnerability data to identify trends and drive remediation; developed processes and tools to continually assess security and improve offerings.
Associate Consultant at Sisa Infosec Pvt Ltd
April 1, 2019 - March 1, 2022
Conducted offensive security activities such as Vulnerability Assessments and Web & Mobile Application Penetration Testing for financial applications to ensure PCI DSS compliance; ensured adherence to minimum baseline security standards and compliance requirements; analyzed vulnerability data for trends and developed actionable remediation metrics; supported risk management practices and security improvements.
Associate Consultant at Astound Technologies Pvt Ltd
January 1, 2018 - April 1, 2019
Conducted offensive security tests (Red team, attack surface mapping, penetration testing, secure code review, web/api/mobile, network VAPT) on web applications and cloud infrastructure to identify and rectify vulnerabilities per OWASP Top 10; ensured adherence to minimum baseline security standards and compliance requirements; managed offensive security activities on applications and product builds for external infrastructure.

Education

Add your educational history here.

Qualifications

OSCP
January 11, 2030 - June 27, 2026
CISA
January 11, 2030 - June 27, 2026
ISO 27001
January 11, 2030 - June 27, 2026
CRTP
January 11, 2030 - June 27, 2026
CEH
January 11, 2030 - June 27, 2026

Industry Experience

Financial Services, Software & Internet, Manufacturing, Energy & Utilities, Healthcare, Telecommunications, Retail, Professional Services