Web Application Security Practitioner

12 weeks, one-to-one, until you can test a real application.

By week 12 you can test a web application end to end against the OWASP Top 10 and common API flaws, and write a report a security team would accept. You leave with three graded lab reports, a competency record and a verifiable certificate. Evidence, not a promise.

Next intake: October 2026. A handful of seats — every hour is taught by me, so it stays small.

12weeks, one-to-one
4 hof live sessions a month, plus reviewed labs
₹36,000upfront, or 3 × ₹13,000
3graded lab reports you can show an employer

Fit

Who this is for

Worth being direct before either of us spends time on an application.

This is for you if

  • You've finished a degree, a certification or a course, and applications aren't turning into interviews.
  • You're in IT and want to move into security with proof you can do the work, not another certificate.
  • You're early in a security role and want to get properly good at web and API testing.

This is not for you if

  • You want a batch. Every hour here is one-to-one.
  • You want a recording library. There is work between sessions, and I read it.
  • You want someone to promise you a job. I don't, and nobody honest can.

Need something shaped around you rather than a fixed 12 weeks? The bespoke 1:1 mentorship is planned from your intake instead.

Outcomes

What you'll be able to do

Each of these is demonstrated on a live lab and graded, not ticked off a syllabus.

  • Scope and run a web application assessment with a repeatable methodology.
  • Find and demonstrate the OWASP Top 10 classes in real targets — injection, broken access control, authentication flaws, SSRF and the rest — not just name them.
  • Test APIs: authentication, authorisation, mass assignment, rate limits, business-logic abuse.
  • Write findings the way a client or a hiring manager reads them: impact, reproduction, fix.
  • Talk about your work in an interview with specifics, because you did it.

Structure

How the 12 weeks run

Every week: one live 1:1 session, assignments and labs reviewed, questions answered within a day.

Weeks 1–3

Foundations and method. Pentest fundamentals, the toolchain, how a professional assessment is scoped and documented. First lab.

Weeks 4–8

OWASP Top 10, hands-on. One or two vulnerability classes a week, each on a live lab, each ending in a written finding I review.

Weeks 9–11

API security. Authentication and authorisation flaws, object-level access, mass assignment, rate limiting, logic abuse.

Week 12

Full assessment. You test an application start to finish and deliver a complete report. We review it together, line by line.

Everything is tracked in your own portal — sessions, hours, labs, competencies, certificate.

Proof

What you leave with

Things you can hand to an employer, not a feeling of having covered the material.

  • Three graded lab reports you can show an employer.
  • A competency record — what you demonstrated, at what level, with evidence.
  • A verifiable certificate of completion.
  • A written next-steps plan for the role you're targeting.

Who's teaching

Every hour, with me

Mentorship is a small part of my week. The rest is the work I would be teaching you to do.

  • Sarath G. Application security consultant and international cybersecurity trainer, 9+ years in penetration testing and security training.
  • Web and API assessments, thick-client pentesting and secure-coding enablement for central banks, government bodies, healthcare and Fortune 500 teams, on-site across 10+ countries.
  • A small number of 1:1 students at any time, alongside that work. Lab work runs on ShopEasy and my public labs, free whether or not you enrol.
  • Full profile: clients, engagements and published labs →

Certifications held

CEH Master certification CPENT certification LPT Master certification CHFI certification Certified EC-Council Instructor ISC2 Certified in Cybersecurity WAHS certification

Price

One price, stated up front

Includes all sessions, reviews, labs, the portal and the certificate.

₹36,000 upfront
or 3 × ₹13,000 monthly
  • Booked a paid session with me in the last 30 days? It's credited against your first payment, up to ₹999.
  • 15-day cooling-off: ask within 15 days of your first payment and the unused portion is refunded, no reason needed.
  • 48-hour cancellation rule for individual sessions; with less notice the session counts as delivered.
  • The full terms are public: enrolment agreement and refund policy.

How to start

Two doors, one room

Apply directly, or let a 30-minute readiness check decide it for you.

Apply

Five questions, two minutes. I read every application myself and reply within two working days.

Or check first

A Job Readiness Check — 30 minutes, ₹499. You send your resume and target role; you leave with your 3–5 gaps in writing. Join the programme within 7 days and the ₹499 comes off your first payment.

Enrol

You get a private sign-up link, your portal and your schedule.

Questions

Questions people ask

Including the one everyone wants answered before anything else.

Do I need prior security experience?

No. Weeks 1–3 exist for that. You need basic comfort with a terminal and a browser, and 4–6 hours a week outside sessions.

Is this a job guarantee?

No. Nobody honest can offer one. What I guarantee is that you'll have done the work and can prove it.

Why one-to-one instead of a batch?

Because a batch teaches the syllabus; one-to-one teaches you. Your gaps set the plan.

What if I miss a week?

Sessions reschedule with 48 hours' notice. The plan flexes; the outcome doesn't.

Can I pay monthly?

Yes — 3 × ₹13,000. Paying upfront saves ₹3,000.

What tools do I need?

A laptop that can run a VM and a browser. Everything else is free or provided.

Evidence, not a promise.

Twelve weeks from now you either can test a real application or you can't. This is built so that you can, and so that you can show it.

Not sure which door? The readiness check costs ₹499 and it comes off your first payment if you enrol within 7 days.