U

Utkarsh Tiwari

CEO

Bengaluru, Karnataka, India9 yrs 7 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Built a 20-member security engineering team from scratch.
  • Led security assessments for over 300 projects.
  • Recognized by major organizations for vulnerability disclosures.
Stackforce AI infers this person is a Security Engineering Leader in E-commerce with expertise in Product Security and Compliance.

Contact

Skills

Core Skills

Product SecurityDevsecopsWeb Application SecurityRisk AssessmentSecurity TrainingPenetration TestingProject Management

Other Skills

AI SecurityAPI SecurityASP.NETAgile Software Development with Scrum MethodologyArchitecture ReviewC#Cloud Security (AWS, GCP) & WAF (Cloudflare, AWS & Akamai)ComplianceCompliance(ISO 27001 & TPRM)CybersecurityDeveloper Training & Security AwarenessFraud Detection & PreventionInfrastructure SecurityLeadershipNetwork & Infrastructure Security

About

Security Engineering Leader with 9+ years of experience building and scaling product security programs from the ground up. Proven track record of transforming security from a reactive function into a proactive, embedded discipline across SDLC, powered by automation, threat modeling, and secure design. Experienced across application security, infrastructure, cloud, and compliance. Currently exploring AI/ML security vectors including prompt injection and model exploitation in LLMs. Currently leading Product Security at Meesho, one of India’s largest e-commerce platforms, where I built the security engineering team from inception to a 20-member unit covering Application Security, Infrastructure, DevSecOps, Compliance, and Threat Intelligence. I’ve personally led and delivered security assessments for over 300 projects, driving significant risk reduction and enabling secure product velocity. Recognized by leading organizations like Google, Amazon, Bugcrowd, PortSwigger, MakeMyTrip, etc. for responsible vulnerability disclosures through active participation in global bug bounty programs. Core Competencies - Security (Web, Android, iOS) - AI Security - Secure SDLC & DevSecOps - Threat Modeling & Secure Architecture Reviews - Cloud Security (AWS, GCP) & WAF (Cloudflare, AWS & Akamai) - Network & Infrastructure Security - Red Teaming & Social Engineering (Vishing, Phishing) - Source Code Review & Automation - API & Thick Client Security Testing - Risk Assessments & Security Program Management - Fraud Detection & Prevention - Developer Training & Security Awareness - Compliance(ISO 27001 & TPRM) Views expressed here are personal and do not represent the views of my employer unless explicitly stated.

Experience

Meesho

3 roles

Head - Product Security Engineering & Compliance

Promoted

Jul 2023Present · 2 yrs 8 mos · Hybrid

  • Founding Member and Leader: Established and led the Security Engineering team, growing it from a nascent group to a robust team of 20 specialists covering diverse domains.
  • Proactive Security Initiatives: Pioneered and managed multiple security programs, including conducting Quarterly security assessments, integrating security review in release cycle, implementing a Bug Bounty Program, conducting Threat Modeling, Prd & Architecture Reviews, introducing Security On-Call rotations, performing Third Party Vendor Reviews, and working with cross org teams on Fraud Detection & Prevention.
  • Infra Security Enhancements: Optimized existing rules in AWS WAF and on-boarded a robust solution like Cloudflare & Akamai to ensure zero downtime caused by security attacks like DDoS and common OWASP attacks on websites.
  • Secure Coding Practices: Developed and enforced organization-wide secure coding guidelines to elevate code quality and adherence to industry standards.
  • Shift Left Program: Collaborated with cross-functional teams to integrate security technologies into the CI pipeline, advancing the Shift Left approach to security.
  • Security Awareness and Training: Conducted security training and awareness programs, including language-specific secure coding training and monthly security quizzes, fostering a security-aware culture and minimizing human error risks.
  • Threat Intelligence and Skill Development: Stayed abreast of emerging security threats and technologies, ensuring the organization remained protected, while providing mentorship and guidance to team members to advance their careers in security engineering.
  • Security Strategy Planning, Development and Alignment: Successfully creating and presenting security engineering team's OKRs to senior leadership, demonstrating alignment with organizational goals and showcasing measurable progress toward key milestones.
LeadershipTeam ManagementProduct SecurityComplianceInfrastructure SecurityDevSecOps+1

Tech Lead - Security Engineering

Promoted

Jan 2022Jun 2023 · 1 yr 5 mos · Hybrid

  • All Things Security @ Meesho
Product SecurityTeam ManagementComplianceDevSecOpsPenetration Testing

Senior Security Engineer III

Jul 2021Dec 2021 · 5 mos · Hybrid

  • All Things Security @ Meesho
Product SecurityDevSecOpsComplianceInfrastructure SecurityPenetration Testing

Myntra

Senior Security Engineer

Jun 2020Jul 2021 · 1 yr 1 mo · Bangalore · On-site

  • Security Integration and Testing: Led security integration throughout the entire development lifecycle, performed testing of Web apps, Mobile apps, Network, APIs, Infra, and Code. Implemented security measures in the CI/CD pipeline and utilized automation to enhance security practices.
  • Responsible Disclosure and Vendor Assessments: Managed the Responsible Disclosure program, fostering responsible vulnerability reporting. Collaborated with the GRC team to conduct Third-Party Vendor Assessments, ensuring security compliance throughout the supply chain.
  • Security Awareness and Training: Organized and conducted security awareness training for diverse teams, cultivating a culture of security awareness. Created secure coding resources to empower developers with best practices.
  • Application Security Standards: Developed and established robust standards and procedures for application security, ensuring consistent and comprehensive security measures across projects.
  • Risk Assessment Support: Provided technical expertise and support for risk assessments, contributing to the implementation of secure architecture and risk mitigation strategies.
  • Security Program Development and Implementation: Designed, developed, and successfully implemented information security programs, bolstering the organization's security posture.
Penetration TestingAPI SecurityWeb Application SecurityRisk AssessmentSecurity Integration & Testing

Traveloka

Security Engineer

May 2019Jun 2020 · 1 yr 1 mo · Bangalore · On-site

  • Security Assessments and Architecture Review: Conducted comprehensive security assessments and architecture reviews of new and existing products, ensuring the identification and remediation of vulnerabilities and potential risks.
  • Bug Bounty Program Management: Successfully managed the Bug Bounty program on BugCrowd, triaging reported issues and guiding developers through the resolution process to ensure effective closure.
  • Security Training and Awareness: Delivered engaging security sessions on various topics and organized security awareness sessions for new employees, fostering a security-conscious culture across the organization.
  • Application Security Incident Response: Provided valuable support to multiple departments by participating in Application Security Incident Response activities, addressing security incidents promptly and effectively.
  • SOP Development: Developed standardized operating procedures (SOPs) for various organizational processes, streamlining security practices and ensuring consistency in security-related workflows.
Penetration TestingAPI SecurityWeb Application SecurityArchitecture ReviewSecurity Training

Network intelligence

2 roles

Senior Cybersecurity Analyst

Promoted

Oct 2018May 2019 · 7 mos · On-site

  • Vulnerability Assessment and Penetration Testing (VAPT): Conducted VAPT for multiple clients, evaluating the security of their Web applications, APIs, Network, and Mobile Applications to identify and mitigate vulnerabilities.
  • Project Management: Successfully managed end-to-end projects for various clients, from initial planning to final delivery, ensuring timely and effective execution of security initiatives.
  • Security Testing Framework: Developed a Security Testing Framework, streamlining the security testing process and enhancing the efficiency and consistency of security assessments.
  • Mentoring and Leadership: Mentored and guided newly hired personnel, providing technical and personal development support to help them grow and excel in their roles.
  • Onsite Collaboration with Client's Internal Security Team: Collaborated with the internal security team of a prominent bank in Dubai to integrate security testing seamlessly into the Agile development model. Led end-to-end security initiatives, ensuring security requirements were considered throughout the development lifecycle, and driving the adoption of secure coding practices and security testing automation. Resulted in enhanced security posture and accelerated development cycles while maintaining compliance with industry standards and regulatory requirements.
Penetration TestingAPI SecurityWeb Application SecurityProject ManagementLeadership

Cybersecurity Analyst

Apr 2017Oct 2018 · 1 yr 6 mos · On-site

  • Conducting Vulnerability Assessment and Penetration Testing for Web Applications, Networks, and Mobile Platforms.
Penetration TestingAPI SecurityWeb Application Security

Torrid networks limited

Associate Security Analyst

Jun 2016Apr 2017 · 10 mos · Noida Area, India · On-site

  • Vulnerability Assessment and Penetration Testing (VAPT): Conducted VAPT on multiple clients' Web applications, APIs, Network, and Mobile applications, identifying and remediating security vulnerabilities.
  • CERT-In Examination Success: Played a crucial role in helping the organization pass the CERT-In (Computer Emergency Response Team of India) examination, demonstrating compliance with security standards and best practices.
  • Note: Torrid Networks was merged with Network Intelligence (I) Pvt. Ltd in 2017.
Penetration TestingAPI SecurityWeb Application Security

Techdefence pvt. ltd

Intern

Jun 2015Jul 2015 · 1 mo · Ahmedabad Area, India · On-site

  • Training and Internship Overview:
  • Completed the TechDefence Certified Cyber Security Expert v3 program, a career-oriented hands-on training focused on Advanced Ethical Hacking, Cyber Crime Investigation, Cyber Forensics, and Information Security.
  • Achieved an 85% score in the Certified Cyber Security Expert certification exam.
  • Gained practical experience through a 2-month internship at TechDefence Pvt. Ltd., Ahmedabad.
Penetration TestingAPI SecurityWeb Application Security

Hewlett packard enterprise

Summer Trainee

Jun 2014Jul 2014 · 1 mo · Dehradun · On-site

  • Training Overview:
  • Completed a one-month summer training program with HPES, India at the Dehradun Nodal Center.
  • As part of the program, successfully developed and submitted the City Without Crime project, built in ASP.NET using C#.
ASP.NETC#Project Management

Education

Dr. A.P.J. Abdul Kalam Technical University

B Tech(Bachelor of Technology) — Computer Science & Engineering

Jan 2012Jan 2016

St. Thomas School,Gopiganj

High School & Intermediate

Jan 2008Jan 2012

Stackforce found 100+ more professionals with Product Security & Devsecops

Explore similar profiles based on matching skills and experience