HMMNM
Initializing
Cyber Security Consultant

Prabhu Kalyan Samal

Securing the digital world, one vulnerability at a time.

Security Researcher & Consultant

I write about what I break — and how to fix it.

Hello! I'm Prabhu Kalyan Samal, a Cyber Security Consultant at Tata Consultancy Services (TCS) — one of the world's largest IT services and consulting firms. With a deep passion for cybersecurity, I specialize in identifying vulnerabilities in web applications, APIs, and enterprise systems before malicious actors can exploit them.

My day-to-day work involves conducting comprehensive security assessments, performing penetration testing, and working closely with development teams to integrate security into every stage of the software development lifecycle. I believe that security isn't a checkbox — it's a culture that needs to be embedded from the first line of code to the last deployment.

Beyond my corporate role, I run hmmnm.com, where I share in-depth articles on cybersecurity topics including Cross-Site Scripting (XSS), Server-Side Template Injection (SSTI), HTTP Request Smuggling, ransomware defense strategies, and ethical hacking best practices. My goal is to make advanced security concepts accessible to developers, security enthusiasts, and fellow professionals.

0
Certifications
0
Articles Published
TCS
Current Role
0
Industries Served

Skills & Tools

Offensive Security

Web Pentest API Security Burp Suite OWASP Top 10 SSTI XSS / CSRF SQL Injection Authentication Testing

Cloud & DevSecOps

Azure Security Google Cloud CI/CD Pipelines SAST / DAST SCA CIS Benchmarks

Tools & Platforms

Microsoft Sentinel Microsoft Defender Nmap Postman Wireshark Linux / Bash

Communication

Vulnerability Reports Risk Assessment Technical Writing Client Presentations Agile / Scrum

Certifications

Continuous learning is at the core of my professional growth. These certifications span cloud security, offensive methodologies, and agile practices.

CISP

Certified Information Systems Security Professional

Expertise across eight domains of information security.

SC-200

Microsoft Security Operations Analyst

Threat detection, response, and hunting using Sentinel & Defender.

SC-900

Microsoft Security, Compliance & Identity

Foundational knowledge of Microsoft cloud security services.

PSPO 1

Professional Scrum Product Owner I

Agile product management and stakeholder collaboration.

GCP

Google Cloud Certification

Google Cloud security and infrastructure competence.

Security isn't a checkbox — it's a culture that needs to be embedded from the first line of code to the last deployment.

Think Like an Attacker

Understanding offensive techniques is the foundation of effective defense.

Shift Left

Catching vulnerabilities early in the SDLC is orders of magnitude cheaper than fixing them in production.

Share Knowledge

A stronger security community means a safer internet for everyone.

Experience

Cyber Security Consultant

Tata Consultancy Services
Current
Web Application Penetration Testing

OWASP Top 10 analysis, business logic flaw identification, and authentication/authorization testing.

API Security Assessment

REST and GraphQL API testing — BOLA, injection vulnerabilities, and excessive data exposure.

DevSecOps Integration

Embedding SAST, DAST, SCA scanning into CI/CD pipelines for automated security.

Security Reporting & Remediation

Actionable vulnerability reports with risk ratings, PoC exploits, and remediation guidance.

Cloud Security Review

Azure and GCP configuration assessment against CIS benchmarks.

Let's Connect

Whether you're looking to collaborate on security research, discuss vulnerability disclosures, or simply exchange ideas — my inbox is always open.

This site uses AI tools for content enhancement. No personal data is sent to AI services. Learn more