About Me
Product Security Engineer with close to 3 years of hands-on experience securing APIs, web applications, SDKs, and large-scale product ecosystems. I specialize in application security testing, vulnerability assessments, secure code reviews, and automating security workflows.
Key Skills
- VAPT (Web, API)
- Secure Code Review (JS, Python, Bash, etc.)
- SAST, DAST, SCA tools and techniques
- Custom automation for AppSec workflows
- Cloud exposure: AWS, Docker
- Security scripting (Python, Bash, Postman)
- Threat modeling and risk analysis
Highlights
- Built and deployed an automated API security testing framework
- Discovered critical production-level vulnerability in legacy systems
- Standardized internal API documentation to reduce risk from shadow APIs
- Led security assessments for product rollouts across CMS, Automation Hub, Marketplace, and more
- Run BreachForce, a cybersecurity community in Mumbai, organizing monthly meetups and workshops
Looking For
Opportunities in application/product security where I can contribute to secure design, scale security automation, and collaborate across engineering teams to embed security into the SDLC.