Amit Kumar

Security Engineer

Sydney, New South Wales, Australia8 yrs 6 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Recognized by major tech firms for security issue reporting.
  • Authored a significant Firefox exploit CVE-2017-7783.
  • Led security initiatives at multiple organizations.
Stackforce AI infers this person is a Cybersecurity expert with a focus on security engineering and risk management.

Contact

Skills

Core Skills

Security EngineeringCybersecurityPenetration Testing

Other Skills

AWS SecurityAmazon Web Services (AWS)Application SecurityBug Bounty TriageC (Programming Language)Cloud DevelopmentCloud SecurityCyber DefenseCyber Threat Hunting (CTH)DevSecOpsGRC (Governance, Risk & Compliance)IDSIT Risk ManagementIncidence ResponseInformation Security

About

• Acknowledged by Facebook, Google, Apple, Microsoft, Intel, eBay, US Dept of Defense & other popular services for reporting security issues in their web services. • Author of Firefox Web Browser exploit CVE-2017-7783. • Skill Set: Security Engineering (Primary), Penetration Testing, Bug Bounty Triage, Red Teaming, Incidence Response, Threat Hunting, Competitive Programming, Vulnerability Assessment, GRC (Governance, Risk & Compliance) etc. Blog: CyberCriminals.net

Experience

Google

Security Engineer

Aug 2022Present · 3 yrs 7 mos · Sydney, New South Wales, Australia

  • Focused on Identity & Authentication Security
  • Tackling cookie theft problem by binding hardware-backed certificates with authentication tokens.
  • Winner Q1, 25 - Google Core Tech Impact award.
Security EngineeringCybersecurity

Aefm international

Fitness Model

Jul 2022Present · 3 yrs 8 mos · Sydney, New South Wales, Australia

  • Experienced in live shoots, commercial advertisements, and event promotions, delivering results under tight timelines.
  • Collaborated with industry-renowned photographers, including Jared Taylor (jvvo.com), who has shot for global brands like Puma, Speedo, and Powerade.
  • Consistently maintained peak physical conditioning (7% body fat, lean muscle mass + athletic versatility) to meet diverse client requirements.

Deriv

2 roles

Security Team Lead

Promoted

Mar 2021Jul 2022 · 1 yr 4 mos

  • Built the security function from the ground up, scaling the team and securing critical trading infrastructure.
  • Management: Lead a team of about 10 individuals to build & improve the cybersecurity capabilities of the company. Followed OKR's based approach to define team vision & strategy.
  • Penetration Testing: Conducted penetration testing and security audit review on Web Application (Whitebox/BlackBox), Network, Mobile & Thick Client.
  • Bug Bounty: Managed Bug Bounty Triaging for Binary.com via HackerOne and Deriv.com via Intigriti and a private program. Contributed towards the improvement of programs by updating policy, scope and reward structure.
  • Cloud Security: Secured production and development systems by performing configuration reviews on AWS utilising services such as AWS Security hub and AWS Config to discover flaws such as S3 public access, overly permissive security groups etc.
  • Engineering: Built and automated security tools and processes for critical infrastructure monitoring, protection, and mitigation.
  • GRC (Governance, Risk & Compliance): Gained experience with setting up AWS config compliance monitoring rules, CIS Benchmarking and fulfiling the regulatory requirements for ISO 27001, PCI, GDPR, MFSA etc by implementing, auditing & documenting security controls & policies.
  • Security Awareness: Conducted cyber security awareness training for over 100 new joiners.
  • Public Speaking: Taught cybersecurity module in the company’s graduate program BeSquare to a class of ~50 students.
AWS SecurityCloud SecurityCybersecurityDevSecOpsIT Risk ManagementPenetration Testing

Security Researcher

Jan 2020Mar 2021 · 1 yr 2 mos

Ey

3 roles

Associate Consultant

Promoted

Sep 2018Nov 2019 · 1 yr 2 mos

  • Consulted various fortune 500 clients and performed 50+ security assessments involving Penetration Testing, Red Teaming, Blue Teaming, Configuration Reviews etc.
  • Threat Hunting: Worked as a part of SOC Team and performed daily hypothesis based threat hunting utilising frameworks such as MITRE ATT&CK, Cyber Kill Chain etc.
  • Penetration Testing: Experience performing penetration tests on web applications (Whitebox/BlackBox), Network, Mobile, Thick Client & SAP systems.
  • Red Teaming: Performed Adversary simulation/Red Teaming assessment for various leading companies in Telecom, FMCG & Banking sector.
  • Configuration Reviews: Supported engineering teams during SDLC by performing threat modelling using STRIDE and configuration reviews of network devices such as Firewalls, Switch, Routers etc by evaluating them against CIS benchmark using Nessus.
  • Vulnerability Assessment: Experience working with vulnerability management tools such as Qualys, Nessus, OpenVas etc.

Cyber Security Analyst

Jul 2017Sep 2018 · 1 yr 2 mos

Intern (Cyber Security)

May 2017May 2017 · 0 mo

Unilever

Cyber Threat Hunter

Sep 2018Sep 2019 · 1 yr

  • • Operated from 24x7 SOC to perform Threat Hunting using SIEM, EDR and IDS systems.

Education

Uttarakhand Technical University

Bachelor of Technology - BTech — Computer Science

Jan 2013Jan 2017

Stackforce found 100+ more professionals with Security Engineering & Cybersecurity

Explore similar profiles based on matching skills and experience