NV/
NadipenaVarunkumar
0%Click or press Esc to skip
Open to internships & 2026 grad roles

Nadipena Varunkumar

Full-stack developer with a security mindset — I build products end to end, then test them the way an attacker would.

I build full-stack products end to end and test them the way an attacker would. Right now I work on infrastructure and networking as a Technology Intern at Kroll, and spend my own time on web and API security and bug bounty practice.

  • Technology Intern @ Kroll
  • B.Tech IT — 2026
  • APIsec Certified
Next.jsReactTypeScriptNode.jsPostgreSQLLangGraphRAG PipelinesTailwind CSSNext.jsReactTypeScriptNode.jsPostgreSQLLangGraphRAG PipelinesTailwind CSS
Bug BountyOWASP Top 10API SecurityBurp SuitePythonAWSAzureDockerBug BountyOWASP Top 10API SecurityBurp SuitePythonAWSAzureDocker
Selected work

Things I’ve built

A few projects I designed and shipped. Each started as a real problem — so I owned them from data model to deployed UI.

FeaturedJan 2026 – Present

PlagDetect

Multi-modal plagiarism detection for educators

A full-stack platform and Chrome extension that checks text, code and images for plagiarism in real time, then returns a readable similarity report.

What I built — Designed the LangGraph + RAG pipeline, the Postgres schema and the Manifest V3 extension, and added prompt-injection guardrails around the AI calls.

Next.jsPostgreSQLLangGraphRAGGemini APIGuardrails AI
cursors-2k26.vercel.app
PlagDetect
story-craft-one.vercel.app
StoryCraft

StoryCraft

Mar 2025

AI storytelling + an artisan marketplace

A PWA pairing interactive AI storytelling with seller tools for artisans — chat, visual search, and AI-assisted product descriptions.

Next.jsMongoDBSocket.IOLangChain
resto-bar-alpha.vercel.app
RestoBar

RestoBar

Dec 2024

Coffee-shop e-commerce front end

A polished storefront with product catalogue, cart and a payment-flow UI — built to practise interaction design and accessible components.

Next.jsReactTailwind CSSFramer Motion
Capabilities

What I work with

Grouped by how I actually use them — not a wall of logos. Strongest in full-stack product work and application security.

0

Internships

infra · web · security

0×

Hackathon wins

1st place, 100+ teams

0+

Certifications

cloud · security · AI

Cybersecurity & Recon

Finding and reasoning about how systems break.

Web App PentestingAPI Security TestingBug Bounty MethodologyOWASP Top 10IDOR / XSS / SQLi / SSRFAuth Bypass TestingRecon & Enumeration

Full-stack Engineering

Owning features from schema to deployed UI.

Next.jsReactNode.jsExpressDjangoFlaskREST APIs

AI / GenAI

Building and securing LLM-powered features.

LangChainLangGraphRAG PipelinesGuardrails AIPrompt Injection DefenceOWASP LLM Top 10Vector Databases

Backend & Data

APIs, data models, and the auth around them.

PostgreSQLMySQLMongoDBSchema DesignJWTOAuth 2.0RBAC

Languages

Comfortable across the stack and the terminal.

TypeScriptJavaScriptPythonJavaCC++SQLBash

Cloud, DevOps & Tooling

Shipping and operating what I build.

AWSAzureDockerCI/CDGitHub ActionsLinuxBurp SuiteNmapWireshark
Experience

Where I’ve worked

Three internships across infrastructure, secure web development, and security research.

  1. Kroll

    Technology Intern — Infrastructure & Networking

    Feb 2026 – Present Hyderabad

    Supporting enterprise infrastructure and networking operations across cloud and on-prem environments.

    • Work cloud and on-prem infrastructure tickets across AWS and Azure
    • Linux configuration and network troubleshooting — DNS, routing, firewalls
    • Use enterprise networking tools for traffic monitoring and incident response
    AWSAzureLinuxNetworkingIncident Response
  2. Victoire System Solutions

    Web Developer Intern

    Aug 2025 – Jan 2026 Remote

    Built and shipped full-stack web applications with a focus on secure, reliable delivery.

    • Built full-stack apps with Django, Python and PostgreSQL, deployed to production
    • Designed secure REST APIs using JWT, OAuth 2.0 and role-based access control
    • Set up CI/CD with GitHub Actions, including automated SAST scanning
    • Practised DevSecOps — found and helped remediate vulnerabilities with Burp Suite and OWASP ZAP
    DjangoPythonPostgreSQLGitHub ActionsBurp Suite
  3. ResilientShield Cyber Solutions

    Cybersecurity Research Intern

    Jun 2025 – Jul 2025 Remote

    Hands-on security research across traditional web targets and LLM-based systems.

    • Red-teamed AI systems for prompt injection and jailbreaks (OWASP LLM Top 10, MITRE ATLAS)
    • Wrote Python automation for recon and exploit validation to speed up testing
    • Found high-severity issues — SQLi, IDOR, auth bypass — across assessed targets
    • Documented findings as CVSS-scored reports with remediation guidance
    PythonOWASPMITRE ATLASRecon Automation
Security mindset

How I think about
building things

I don’t treat security as a separate hat. The same curiosity that makes me want to understand how a system works makes me want to know how it fails — and building with that in mind is what keeps the things I ship from quietly breaking later.

01

Start from the failure modes

Before I trust a feature, I ask how it gets abused — bad input, broken access control, a token that outlives its purpose. Mapping the failure modes early is cheaper than patching them after launch.

02

Treat input as hostile

User data, third-party APIs, even content scraped from a web page — none of it is trusted until it’s validated. That habit came directly from building AI features where prompt injection is a real threat.

03

Recon is just understanding

Bug bounty work is mostly patient enumeration: what’s exposed, what assumptions the app makes, where the edges are. I automate the repetitive parts so I can spend attention on the interesting ones.

04

Security designed in, not bolted on

Auth, least privilege, and sane defaults belong in the first version, not a later hardening pass. Designing them in keeps the product simpler and the surface smaller.

About

Curious by default,
disciplined by habit

I’m a final-year IT student who likes shipping things that actually work — and then figuring out how they break. Most of my projects start as a real problem I wanted solved, so I tend to own them from data model to deployed UI.

Security is what pulls me deepest. I’m drawn to understanding how systems fail — auth flows, APIs, access control, infrastructure — because knowing the failure modes makes me build sturdier products. I practise this through bug bounty methodology, recon automation, and the OWASP Top 10.

I’m early in my career and honest about that. What I bring is range, fast learning, and a habit of caring about the unglamorous parts: reliability, clear code, and security that’s designed in rather than bolted on. I’m looking for a team where I can contribute real work and grow quickly.

Nadipena Varunkumar

Nadipena Varunkumar

Full-stack developer with a security mindset

Hyderabad, India

Recognition

  • 1st place — Cursors 2k26 Hackathon (100+ teams)
  • 1st place — Cursors 2k25 Hackathon
  • Student Mentor — AITAM Security Club
  • Tech Lead — Avishkaar Season 3

Certifications

  • APIsec Certified PractitionerAPIsec University
  • AWS Certified Cloud PractitionerAmazon Web Services
  • Certified Network Security PractitionerThe SecOps Group
  • Azure Fundamentals (AZ-900)Microsoft
  • OCI AI Foundations AssociateOracle
  • Certified System AdministratorServiceNow

Education

  • B.Tech, Information Technology

    AITAM, Andhra Pradesh · 2022 – 2026 · CGPA 7.78 / 10

Arcade

Stay a while, play a round

Squash the red bugs, skip the teal decoys. 20 seconds on the clock.

Score 020s
Best 0

Ready to hunt?

Red bugs are worth +1. Teal decoys are −2. Tip: turn on sound in the nav for the full effect.

Contact

Let’s build something

I’m looking for internships, new-grad roles, and security-minded engineering work. If you’re hiring or want to collaborate, the fastest way to reach me is email — I reply quickly.

Email me