Sarthak Giri
Cybersecurity Engineer · Ethical Hacker · Full-Stack Developer
Summary
Builder who thinks like an attacker. I ship full-stack products with TypeScript and Next.js, harden the cloud infrastructure they run on, and pull AI into the loop when it earns its place. Three years of hands-on web application security work — OWASP Top 10 grounded, lab tested, responsibly disclosed.
Experience
- 2024 — Present
Cybersecurity Engineer · Builder
Independent · Stockxie + tools- Designed and shipped Stockxie, an AI-powered stock-battle and market discovery app on Next.js / Supabase / AI SDK.
- Integrated LLMs end-to-end with strict latency budgets, deterministic prompting, and zero-trust handling of user data.
- Wrote a hardened deploy story on Vercel + Cloudflare for production AI workloads.
- 2023 — Present
Web Application Security · Lab Work
Self-directed · Responsible Disclosure- Owned an OWASP Top 10 personal lab series — controlled targets, written-up findings + remediations.
- Reported and helped patch authentication, IDOR, and SSRF issues across third-party products via coordinated disclosure.
- Daily-driver tooling: Burp Suite, OWASP ZAP, Wireshark, Docker, Linux.
- 2022 — 2023
IT & Technical Operations
Operations role- Linux administration, network triage, and infrastructure automation across production systems.
- Bridged dev + ops workflows; built scripts that moved manual processes into version control.
- 2021 — 2022
Frontend / Full-Stack Apprenticeship
Freelance · Client projects- Shipped marketing sites and small product apps with React, MongoDB, Express.
- Owned client communication, deploys, and post-launch reliability for ~8 production projects.
Selected Projects
Stockxie
— AI stock battle & market discoveryA head-to-head AI battle interface that ranks any two tickers on fundamentals, momentum, and sentiment, then explains the verdict in plain English.
Next.jsTypeScriptSupabaseAI SDKTailwindVercelNet Zero Waste
— Sustainability platform & guidance engineA mobile-first PWA that identifies the right bin for any item, tracks impact over time, and nudges sustainable habits with real-time guidance.
ReactPWATypeScriptVercel24-7Jobs
— MERN job platform with role-aware matchingA MERN job platform with role-aware matching, faster apply flows, and recruiter tooling that prioritises signal over volume.
MongoDBExpressReactNode.jsSecurity Labs
— Web AppSec research & responsible disclosureA personal lab series — controlled targets covering OWASP Top 10 categories, written up as walkthroughs with the fix alongside the finding.
Burp SuiteOWASP ZAPDockerLinux
Skills
Cybersecurity
- ·Web Application Security
- ·OWASP Top 10
- ·Vulnerability Assessment
- ·Burp Suite · ZAP
- ·Threat Modeling
- ·Network Security
- ·Responsible Disclosure
Development
- ·TypeScript
- ·React · Next.js (App Router)
- ·Node.js
- ·Supabase · SQL
- ·Tailwind CSS
- ·REST / GraphQL APIs
Cloud & Tools
- ·Vercel · Edge
- ·Cloudflare
- ·GitHub Actions
- ·Linux Administration
- ·Docker
- ·Observability basics
AI & Product
- ·AI-Assisted Development
- ·AI SDK
- ·Prompt Engineering
- ·Automation & Scripting
- ·Rapid Prototyping
- ·Product Thinking
Education
- 2020 — 2024
Bachelor of Information Technology
Computer Science focusSelf-directed cybersecurity track alongside coursework.
Certifications
- +CompTIA Security+ (in progress)
- +AWS Cloud Practitioner
- +Web AppSec — OWASP-aligned self-study
References available on request.