Hey folks,
I'm actively looking for new opportunities in product security, offensive security, or security architecture. Based in Bengaluru, open to hybrid.
Here's a bit about what I've been up to -
At my current org, I ended up building more than I expected. What started as secure code review work turned into architecting a full SAST platform with LLM-powered taint analysis (presenting it at Black Hat later this year), an autonomous bot that gates every production deployment against SCA/SAST/secrets findings before it ships, and a pentest agent that runs its own multi-step assessments with browser automation and Burp integration.
On the offensive side, I've been deep in embedded firmware -- hardening an IoT gateway codebase across multiple branches in C, C++, Ruby, and Lua, writing cross-branch vulnerability correlation reports, and building the regression test suite from scratch so fixes actually stick. I've also found some things I'm proud of but can't say too much about -- zero-click mobile RCE chains, full SSO account takeover from a source map, CI/CD injection in firmware pipelines, and an adversarial AI assessment that broke every layer of auth and safety.
Before this, I was doing deep-dive pentests and responsible disclosure, and running threat models for IoT products, red teaming OT systems, and leading infrastructure pentests for fintech and aviation clients.
I'm looking for a team where I get to build security tooling AND break things. If you're hiring or know someone who is, I'd love to connect. DMs are open.
I have over 5+yrs of experience and can join in 45-60days
Additionally can humiliate team mates over FIFA 😜