whoami

NAVEEN
JAGADEESAN

Security Analyst CRTP Certified Red Teamer Security Researcher
Naveen Jagadeesan

I'm Naveen Jagadeesan, known online as TheVillageHacker. I'm a passionate Security Analyst, CRTP-certified Red Teamer, and cybersecurity researcher with over 6+ years of experience in application and network security.

My journey into hacking began with a curiosity for how things break — and more importantly, how to secure them. From humble beginnings as an IoT developer, I've worked through pentesting roles at leading security firms and financial institutions, performing over 350+ penetration tests and 60+ secure code reviews across Web, API, Mobile, and Thick Client platforms.

My professional experience spans organizations like Societe Generale and SISA Information Security, where I've led critical security assessments, mentored junior analysts, and developed automation tools to improve testing efficiency.

When I'm not breaking into applications ethically, I contribute to the community by reporting vulnerabilities, mentoring aspiring hackers, and sharing practical insights from the field.

Experience
2024 –
Present
Societe Generale Global Solution Center, Bangalore
Senior Cyber Security Analyst
Application security assessments, and security tooling development for a global financial institution.
2021 –
2024
SISA Information Security, Bangalore
Senior Specialist
Performed 250+ penetration tests and 50+ code reviews. Mentored junior analysts and built automation tooling for testing efficiency.
2019 –
2021
KGiSL - GSS, Coimbatore
Information Security Engineer
Conducted penetration testing for Web, Mobile, and Thick Client applications, ensuring compliance and vulnerability mitigation.
2019 –
2019
MGK Enterprise Systems, Coimbatore
IoT Developer → Security Researcher
Started as an IoT developer. Security curiosity led to a full career pivot into offensive security and bug bounty research.
Expertise
Offensive Security
  • Web Application Pentesting
  • API Security Assessment
  • Mobile Pentesting (iOS & Android)
  • Thick Client / Desktop Apps
  • Secure Code Review
  • Network Penetration Testing
Research Focus
  • Business Logic Vulnerabilities
  • Authentication & ATO chains
  • Encryption Reverse Engineering
  • Injection Attacks (SQLi, CMDi, XSS)
  • Product Security
  • OSINT & Reconnaissance
Tools & Tech
Burp Suite
sqlmap
Frida
Metasploit
subfinder
dnsx
Ghidra
MOBSF
APKTool
objection
dirsearch
IDA Pro
Python
OWASP ZAP
MicroFocus Fortify
Semgrep
Gitleaks
Trufflehog
NMAP
Wireshark
SysinternalSuite
SonarQube
OWASP Dependency Check
Snyk
Terrascan
Prowler
Nessus
Connect