Koushik Komar Paul
Mymensingh Polytechnic Institute • Mymensingh, Bangladesh
Proactively uncovering zero-day vulnerabilities, OWASP Top 10 penetration testing, API bug auditing, and ensuring watertight client digital assets.
Engineering Background & Focus
Koushik is Nexora's offensive security lead and red-team penetration tester. Grounded in rigorous computer science principles from Mymensingh Polytechnic Institute (CST), he approaches digital products from the exact mindset of an adversary to expose weaknesses before they can ever be exploited.
His technical expertise spans OWASP Top 10 vulnerability verification, Broken Object Level Authorization (BOLA) hunting in modern REST/GraphQL APIs, Server-Side Request Forgery (SSRF) prevention, Cross-Site Scripting (XSS), SQL Injection (SQLi), and business logic flaw remediation.
Koushik has participated in responsible bug bounty programs, responsibly discovering and reporting critical vulnerabilities across global web properties. At Nexora, he subjects every client web application to rigorous stress tests, fuzzing, and penetration audits prior to public launch.
Professional Philosophy
“To defend a fortress effectively, you must think, probe, and attack like the enemy outside the gates. We uncover the invisible cracks in your application's armor long before malicious actors have the chance to find them.”
Core Domain Expertise & Specializations
A rigorous breakdown of technical areas where Koushik engineers production solutions.
OWASP Top 10 Deep Penetration Testing
Exhaustive manual and automated testing for Injection (SQLi/NoSQLi), Broken Authentication, Sensitive Data Exposure, XML External Entities (XXE), and Security Misconfigurations.
REST & GraphQL API Vulnerability Auditing
Specialized in finding API vulnerabilities: IDOR/BOLA, mass assignment, unauthenticated administrative endpoints, rate limit bypasses, and improper asset management.
Vulnerability Assessment & Threat Reporting
Generating comprehensive executive and developer-level remediation reports with CVSS v3.1 scoring, proof-of-concept exploits, and step-by-step patch verification.
Bug Bounty Methodology & Reconnaissance
Advanced passive and active OSINT reconnaissance, sub-domain takeover discovery, directory brute-forcing, and zero-day threat vector simulation.
Key Architectural Milestones & Deliverables
Proven platforms, infrastructure, and audit projects delivered with verified outcomes.
Nexora Pre-Launch Red-Team Security Audit
Lead Penetration TesterConducted black-box and grey-box penetration testing across Nexora's web ecosystem, APIs, and authentication endpoints.
Client Fintech Platform Security Certification
Ethical Hacker & Security AuditorPerformed end-to-end penetration audit on client payment gateway integration and user credential vault.
Responsible Vulnerability Disclosure Research
Independent Ethical HackerEngaged in authorized bug bounty programs identifying critical authorization flaws and data leak vectors.
Collaborate Directly
Need Koushik's specialized expertise on your web application architecture, security audit, or design sprint?
Technical Arsenal
Penetration Testing Tools
Application Attack Surfaces
Reconnaissance & OSINT
Reporting & Verification
Academic & Credentials
Mymensingh Polytechnic Institute
Focusing on computer systems architecture, data communications, network protocols, cryptography, and operating systems.
Cyber Security & Red Teaming Specialization
Extensive hands-on laboratories and practical examinations covering web application attacks, API security, and ethical vulnerability disclosure.