Skip to content
amansploit@sec:~$
AVAILABLE FOR ENGAGEMENTS — Q3 2026

I BREAK THINGSTO BUILD THEM SAFER.

I'm Aman Sonkamble — a security engineer and full-stack developer. I penetration-test web apps and APIs, build security automation that catches real incidents, and ship software that assumes it will be attacked.

CEH MasterCompTIA Security+Certified Network DefenderECSS
Burp Suite ·Nmap ·Metasploit ·Wireshark ·Kali Linux ·Python ·Next.js ·TypeScript ·Supabase ·PostgreSQL ·GitHub Actions ·Docker ·Tor ·Cloudflare Zero Trust ·AWS ·Terraform ·
// WHERE THE WORK COMES FROM

employer · internship · degrees · certifications — not a client list

LTS
Former employer
Security Analyst, 2026 — SOC tooling and automation
InLighnX Global
Internship
Offensive security — web, API, mobile, thick client
EC-Council
Certifying body
CEH Master · CND · ECSS
CompTIA
Certifying body
Security+
Coventry University
Degree
BSc (Hons) Cybersecurity
EC-Council University
In progress
MSc Cyber Security
// SERVICES

Hire the person who attacks systems to build yours.

Four ways to engage. Every one ends with a deliverable you can act on — not a slide deck of vague advice.

01

Web & API Penetration Testing

Full-scope offensive assessment of your web apps, REST APIs, and infrastructure — OWASP Top 10 and beyond: IDOR, auth/session flaws, injection, misconfigurations.

  • Report-grade findings with reproduction steps
  • Severity-ranked remediation guidance
  • Free retest & verification round
02

Security Automation & SIEM Tooling

Custom monitoring and detection engineering: log-pipeline health monitors, alert automation, dark-web exposure monitoring — the tooling that catches incidents before your clients do.

  • Production Python tooling, documented
  • Severity-classified alerting & reporting
  • Least-privilege access design
03

Secure Full-Stack Development

Web applications built security-first: Next.js/TypeScript + Supabase/PostgreSQL with server-side authorization, Row Level Security, secret scanning in CI, and hardened deployments.

  • Security-reviewed, production-ready code
  • CI/CD with secret scanning (Gitleaks)
  • Threat-modeled architecture
04

AI / ML Engineering

Applied machine learning with a security bent: malware classification, sequence models, embeddings, anomaly detection — built, evaluated, and shipped with honest metrics.

  • Trained & evaluated models (AUC, CM)
  • Clean data pipelines
  • Deployment-ready inference
// SELECTED WORK

Proof, not promises.

// HOW IT WORKS

A clear engagement. No surprises.

01

Scope

A short call. We define targets, rules of engagement, and what success looks like. You get a fixed quote — no surprises.

02

Execute

The work happens: testing, building, or both. You get progress updates in plain language, not jargon.

03

Report

Findings with reproduction steps and prioritized fixes — or shipped code with documentation. Deliverables you can hand to your team as-is.

04

Verify

I retest what you fixed, free. The engagement ends when the risk is actually gone, not when the invoice is sent.

// ENGAGEMENTS

Clear scope, fixed price.

Starting points, not a menu you have to fit into. Every engagement is quoted after a short scoping conversation — but you should know the rough shape before you spend time on a call.

Web App Assessment

A single web application or dashboard

from₹45,000
≈ $530 · 4–6 days
  • Manual testing — not an automated scan
  • Full OWASP Top 10 coverage
  • Authentication & authorisation testing
  • Report with reproduction steps and fixes
  • One free retest after you fix things
Estimate my scope
Most common

Web + API Assessment

A product with a REST API and multiple user roles

from₹85,000
≈ $1,000 · 7–10 days
  • Everything in Web App Assessment
  • REST API testing (authz, IDOR, rate limits)
  • Role-matrix and privilege-escalation testing
  • Business-logic abuse cases
  • Executive summary for non-technical stakeholders
  • One free retest after you fix things
Estimate my scope

Security Engineering

Tooling, automation, SIEM work, or secure builds

from₹9,000/ day
≈ $105/ day · Retainer or project
  • Custom detection & monitoring tooling
  • SIEM/log-pipeline engineering
  • Secure full-stack development
  • CI/CD hardening & secret scanning
  • Documented, handover-ready code
Estimate my scope
Introductory rates

These are roughly half the going rate for methodology-driven testing in India, because I'm building my independent client list. What you get is not reduced — every engagement is hands-on testing with a written report and a free retest, never a scanner export with a logo on it. These rates will rise as the calendar fills, and anyone who starts on them keeps them.

Non-profit, pre-revenue startup, or student project? Say so — the price moves again.

Read a sample report (PDF)

12 pages, fictional target — so you can judge the writing before you commit.

// SCOPE & ESTIMATE

Get a number before you talk to anyone.

Pick what you have. You get an indicative range and timeline immediately, and can send the scope straight to me — no form, no follow-up sequence, no call required to find out roughly what this costs.

1 · What needs testing
2 · How big is it
3 · Anything else
Indicative range
₹1,28,000₹1,72,000
≈ $1,500 – $2,025 · about 8 working days

An estimate, not a quote — the real number comes after a short scoping conversation, and it is fixed before any work starts.

Replies within 24 hours, usually sooner.

// WORKING WITH ME

What you're actually buying.

Hiring a freelance security engineer is mostly an exercise in trust — you are paying someone to find the things you could not. Here is exactly how I work, so you can decide before we ever get on a call.

You work with me. Not a team you never meet.

The person who scopes your engagement is the person who tests it and the person who writes the report. Nothing is handed to a junior, and nothing is subcontracted without telling you first.

A fixed quote before anything starts.

You get a scope, a price, and a delivery date up front. If the work turns out to be smaller than expected, the price comes down. It does not go up mid-engagement.

The retest is included.

Finding problems is the easy half. After you fix things, I test them again at no extra cost — because an engagement that ends with an unverified fix has not actually reduced your risk.

I will tell you when you do not need me.

If a scan would answer your question, or the real problem is a configuration you can change this afternoon, I will say so. That is worth more to both of us than an invoice.

You can read my writing before you buy.

A penetration test is ultimately a document. There is a full sample report on this site — a real one in every respect except that the target is fictional — so you can judge the depth and clarity before you commission anything.

Your data stays yours.

Findings are stored as evidence, not as copies of your data. Secrets and personal information get masked at capture. Everything is deleted on request when the engagement closes.

Credentials
  • CEH MasterEC-Council
  • CompTIA Security+CompTIA
  • Certified Network DefenderEC-Council
  • ECSSEC-Council
  • Top 1% — TryHackMeTryHackMe
Experience & education
LTSSecurity Analyst, 2026 — SOC tooling and automation
InLighnX GlobalOffensive security — web, API, mobile, thick client
EC-CouncilCEH Master · CND · ECSS
CompTIASecurity+
Coventry UniversityBSc (Hons) Cybersecurity
EC-Council UniversityMSc Cyber Security

Currently a Security Analyst building multi-client SOC tooling, on the AWS cloud-security track, and available for freelance engagements alongside it.

// LIVE SELF-SCAN

Everything above is my word for it.

This part isn't. The checks below run against this domain when you load the page, using the same logic as the free tools. Whatever they return is what you see — including, one day, a failure I have not noticed yet.

amansploit.com
ALL CHECKS PASSING
Content-Security-Policypassing
script-src 'self' 'nonce-MGY1MDI0NGItODc0NC00MWI5LTk2OTItMjRmNGFlMzEyM2Q2'
Strict-Transport-Securitypassing
max-age=63072000; includeSubDomains; preload
X-Frame-Optionspassing
DENY
X-Content-Type-Optionspassing
nosniff
Referrer-Policypassing
strict-origin-when-cross-origin
Permissions-Policypassing
camera=(), microphone=(), geolocation=(), interest-cohort=()
SPFpassing
v=spf1 -all
DMARCpassing
v=DMARC1; p=reject;

What's genuinely live: the CSP is read off the header set attached to this exact request, nonce included — it is the policy your browser is enforcing right now. SPF and DMARC are public DNS lookups performed server-side on every load.

What isn't: the static headers render from the same array the server config uses, not from a fetch of this page. I don't scan this site from itself, because the host answers scanner-shaped requests with a 403 and I'd be grading the edge network rather than the application. For an independent check, run the domain through securityheaders.com or my own spoofability checker.

// ABOUT

The person you actually want on a hard problem.

Most security freelancers either break things or build them. I do both — which means when I test your app, I understand the code underneath it, and when I build your app, I already know how it gets attacked.

I work with startups, MSSPs, and product teams who want senior-grade work without a senior-grade headcount. Clear scope, honest reporting, and deliverables your team can use the day I hand them over.

aman@sec: ~
> whoami
Aman Sonkamble — offensive security background, builds the things he breaks.
> specialties
offensive security · security automation · secure full-stack · applied AI/ML
> current
Independent. Building secure web applications, automation and security
tooling. Top 1% on TryHackMe. Shipping software that assumes it will be
attacked.
> philosophy
Certs open doors. Evidence gets you hired. Everything I claim, I can show.
 
// START A PROJECT

Got something that needs to be built or broken?

Tell me what you're working on. I reply within 24 hours with honest scope and a fixed quote — no sales calls, no fluff.

Pune, India · Remote worldwide · LinkedIn

Not sure what you need? Use the scope estimator first.