Kochi, Kerala · Remote engagements worldwide

Cybersecurity engineer for apps that ship fast.

What this is

Abin Antony is an independent cybersecurity engineer in Kochi, Kerala, providing mobile, web, API and cloud penetration testing, secure code review and threat modelling. Engagements are fixed-scope and fixed-price, follow OWASP MASVS and ASVS, and include a free retest of every fixed finding.

  • OWASP MASVS
  • OWASP ASVS
  • API Top 10
  • CVSS 4.0
Abin Antony, Cybersecurity Engineer & Application Security Consultant
Available for new engagements
Years building production software
5+
Apps shipped to public app stores
50+
Reported findings retested free
100%
Typical report turnaround
5 days

Services

Engagements I take on

Fixed-scope, fixed-price assessments with a written report, a remediation call and a free retest of every fixed finding.

Mobile App Penetration Testing

Mobile app penetration testing is a manual security assessment of an Android or iOS application, its local storage, its runtime and the APIs behind it. Testing follows th...

2–3 weeks · from ₹85,000

Web Application Penetration Testing

Web application penetration testing is a manual assessment of a live web application performed with real user accounts, targeting broken access control, injection, authen...

2–3 weeks · from ₹75,000

API Security Testing

API security testing is a manual assessment of REST, GraphQL or gRPC endpoints against the OWASP API Security Top 10. It targets broken object and function level authoris...

1–2 weeks · from ₹60,000

Secure Code Review

Secure code review is a manual inspection of source code focused on the paths where security actually fails: authentication, authorisation, payment handling, cryptography...

1–3 weeks · from ₹65,000

Cloud Security Assessment

A cloud security assessment reviews IAM permissions, network exposure, storage access, secrets management and CI/CD pipeline trust boundaries across AWS, GCP or Azure. Fi...

1–2 weeks · from ₹70,000

Threat Modelling & Security Architecture Review

Threat modelling is a structured design review that maps data flows and trust boundaries, enumerates how each component can be abused, and ranks the controls worth buildi...

1 week · from ₹45,000

Developer Security Training & DevSecOps

Developer security training is a hands-on workshop where a team exploits vulnerabilities in its own application and then fixes them, followed by wiring the matching check...

1–2 days on-site, plus setup · from ₹35,000 per day

Compare all services and what each one covers →

Method

Offensive work, defensive outcomes

Every finding lands with a proof of concept, a business-impact rating and a fix a developer can merge — because I spent five years on the other side of that pull request.

  1. 01

    Scope & authorisation

    Targets, test windows, data handling and a signed authorisation. Nothing outside the agreed scope is touched.

  2. 02

    Recon & threat model

    Attack surface mapping and abuse cases, so testing hours go where the real risk lives.

  3. 03

    Manual exploitation

    Tool-assisted, human-driven testing. Findings are chained to prove genuine impact.

  4. 04

    Report & free retest

    Reproduction steps, remediation walkthrough, and a retest of every fix at no extra cost.

  • Burp Suite
  • Frida
  • MobSF
  • Ghidra
  • Semgrep
  • Nuclei
  • ScoutSuite
  • Docker
  • AWS
  • Android
  • iOS
  • Flutter

Service areas

On-site across Kerala, remote everywhere else

Kickoff workshops and developer training happen in person where travel makes sense. Testing itself is remote by default, which keeps travel off your invoice.

Blog

Writing from the work

18 posts on mobile, web, API and cloud security — what turns up in assessments, and the structural fixes for it.

All 18 posts →

Tell me what you want tested

Scope and a fixed quote within two working days. First consultation is free.