Swapneil Kumar Dash — Software Engineer
- Specialised in web, mobile, API and network penetration testing. I also have knowledge on performing threat modelling of applications and architecture reviews. I am active in bug hunting and have been awarded with hall of fame and bounty from various organisations. I also actively participate in CTF challenges to upscale my skill sets. - In my current role, I manage the application security vertical at Paytm and handle a team of 10+ memebers and work on setting up the DAST and SAST process in place across all the verticals. - I also work towards evangelization of security to fellow developers and devops through flyers and security trainings on code reviews and security guidelines that needs to be followed. - I also work towards introduction of the Secure SDLC worflow across verticals at paytm by hooking in mandatory design and architecture reviews and change management involving DAST and SAST activities before any go lives. - I have also contributed to vulnhub by development of a box named Amaze. https://www.vulnhub.com/entry/amaze-1,573/ - I also work towards improving the CICD pipeline by introduction of security tools at every stage and defining process around the same eg. introducing SAST scans in block mode at PR requests for source code repos, OSS scans, image registry scanning, Vulnerability Management etc. In my free time I like to do blogging and below are links to some of my blogs: - https://medium.com/@swapneildash/deep-dive-into-net-viewstate-deserialization-and-its- exploitation-54bf5b788817 - https://medium.com/@swapneildash/understanding-insecure-implementation-of-jackson- deserialization-7b3d409d2038 - https://medium.com/@swapneildash/understanding-java-de-serialization-ee96054da15d - https://medium.com/@swapneildash/snakeyaml-deserilization-exploited-b4a2c5ac0858 - https://swapneildash.medium.com/installing-kubernetes-the-hard-way-a97457793122 - https://swapneildash.medium.com/introduction-to-kubernetes-43d0a2febbc0
Stackforce AI infers this person is a Cybersecurity Specialist with expertise in Application Security and Vulnerability Management.
Location: Bengaluru, Karnataka, India
Experience: 11 yrs 6 mos
Skills
- Application Security
- Cicd Security
- Vulnerability Management
- Threat Modeling
Career Highlights
- Led application security initiatives at Paytm.
- Developed security training programs for developers.
- Contributed to open-source security projects.
Work Experience
FalconX
Application Security Engineer (2 yrs 7 mos)
Paytm
Principal Security Engineer (1 yr 10 mos)
Flipkart
Cyber Security Analyst (2 yrs 1 mo)
Synack Red Team
Member of Synack Red Team (6 yrs 8 mos)
Optiv Inc
Security Consultant (1 yr)
PwC India
Consultant (1 yr 5 mos)
Infosys Pvt Limited
Senior Systems Engineer (11 mos)
System Engineer (1 yr 10 mos)
Education
B-Tech at Indira Gandhi Institute of Technology (IGIT), Sarang
at MGM English School ,Rourkela