Arjan Chaudhary

    15 yo · Security Engineer · Offensive Security Researcher

    Cybersecurity professional with expertise in penetration testing, vulnerability research, and application security. Ethically hacked Google, EA, MIT, Stanford, Shopify, Twitch, NBA, MSI & more. At 12, launched my first startup which failed before launch. At 13, co-founded GlowTech, scaling it to five-figure monthly revenue.

    Experience

    Security Engineer

    Oct 2025 - Present

    Stealth Startup · Remote, UK

    • Performing comprehensive security assessments and developing proof-of-concept exploits
    • Contributing to cutting-edge offensive security research initiatives

    Bug Bounty Hunter

    Jan 2025 - Present

    HackerOne, Bugcrowd, Private Programs

    • Hacked Google, EA, MIT, Stanford, Shopify, Twitch, NBA, MSI & disclosed 50+ vulnerabilities
    • #2 in Twitch Security Researchers Hall of Fame
    • Top 3 in multiple private programs · Youngest in multiple Halls of Fame
    • Specialized in IDOR, Account Takeover, API misconfigurations, Broken Access Control

    Offensive Security Researcher

    Jun 2025 - Oct 2025

    Cyber Alert Nepal · Remote

    • Executed internal pentests discovering 20+ critical vulnerabilities
    • Developed exploitation chains and coordinated remediation with engineering teams
    • Authored SOPs for API, Web & Mobile Application Pentesting

    Offensive Security Researcher

    Feb 2025 - May 2025

    PathMate · Internship · Remote

    • Conducted pentesting on web & mobile applications implementing OWASP frameworks
    • Performed code reviews and threat modeling · Collaborated on vulnerability remediation

    Founder & Lead

    May 2025 - Present

    Arniko Hack Club · Biratnagar, Nepal

    • Founded and lead Eastern Nepal's tech community with 400+ active members
    • Organized free workshops · Organizing Nepal's biggest teen hackathon
    • Partnered with APIsec University providing ACP certifications ($325+ value) free to members

    Co-Founder

    Oct 2024 - Present

    Glow Tech · Self-employed

    • Got few clients in the first month · Took a client's page to 20 million+ views
    • Built and optimized high-performing digital campaigns, blending content strategy with analytics
    • Gained experience in social growth, monetization strategies, client management, and paid media
    • Scaled it up to 5 figure/month revenue
    • Co-founder started another venture, got busy with bug bounty and job · Currently working to revive it

    Key Achievements

    CVE-2025-51588

    Youngest person (14 yo) to be assigned a CVE

    Daydream Biratnagar

    Organized & led Asia's biggest teen hackathon at daydreambiratnagar.com

    APIsec Ambassador

    Official APIsec University ambassador

    Technical Expertise

    Tools & Technologies

    Burp Suite, Frida, MobSF, Nuclei, Custom Security Tools, Bash Scripting, API Fuzzing, Exploitation Frameworks, MITRE ATT&CK, NIST Framework, Python

    Security Testing

    Web Application Pentesting, API Security & Testing, Mobile Application Security, Vulnerability Assessment, Internal Pentesting

    Specializations

    Authentication/Authorization Bypass, Access Control Issues, Injection Vulnerabilities, Session Management, API Endpoint Testing, Cloud Security, PoC Development

    Certifications

    ACP (API Security Certification Professional), CASA (Certified API Security Analyst), CCEP (Certified Cybersecurity Educator Professional), COSJ, NSE 1, Pursuing OSWE

    Contact