Rewanth Tammana

Co-Founder

Dubai, United Arab Emirates10 yrs 4 mos experience
Most Likely To SwitchAI ML Practitioner

Key Highlights

  • Contributed 17,000+ lines of code to Nmap.
  • Speaker at multiple international security conferences.
  • Recognized as MVP researcher on Bugcrowd.
Stackforce AI infers this person is a Cybersecurity expert specializing in DevSecOps and Cloud Security.

Contact

Skills

Core Skills

DevsecopsSecurity Architecture & EngineeringThreat ResearchFull-stack DevelopmentSecurity ResearchSecurity Engineering

Other Skills

AIAPIASP.NETAmazon Web Services (AWS)AngularJSApplication SecurityArchitectural reviewsAutomated web vulnerability scannerBashBootstrapCC#C++CloudNative technologyContainers and Kubernetes security

About

Rewanth Tammana is a security ninja, open-source contributor, and an independent consultant. Previously, Senior Security Architect at Emirates NBD. He is passionate about DevSecOps, Cloud, and Container Security. He added 17,000+ lines of code to Nmap (famous as the Swiss Army knife of network utilities). Holds industry certifications like CKS (Certified Kubernetes Security Specialist), CKA (Certified Kubernetes Administrator), etc. Rewanth speaks and delivers training at multiple international security conferences around the world including DEFCON, Hack In The Box (Dubai and Amsterdam), CRESTCon UK, PHDays, Nullcon, Bsides, CISO Platform, null chapters, and multiple others. He was recognized as one of the MVP researchers on Bugcrowd (2018) and identified vulnerabilities in several organizations. He also published an IEEE research paper on an offensive attack in Machine Learning and Security. He was also a part of the renowned Google Summer of Code program. Specialties: Containers & Kubernetes Security, Security Architecture & Engineering, DevSecOps, Security Automation, DevOps, Application Security. W: https://rewanthtammana.com E: hello@rewanthtammana.com

Experience

Clutch security

2 roles

Research Team

Mar 2025Jul 2025 · 4 mos · Israel · Remote

  • One of the pioneering team members to join during stealth mode (first 10 people)
  • Thought Leadership - built open source products, lead threat research, technical research, etc.
  • Collaborate with marketing to transform research outcomes into thought leadership & content
  • Built custom LLMs to integrate with the product (AI), ML models security & more
  • Shipped critical security features for the product from scratch
  • Built a comprehensive index of Non Human Identities for cloud & various SaaS services - https://www.nonhuman.id/
  • Responsible for leading entire tech research section - https://www.clutch.security/blog,, https://www.clutch.security/rotation-debunking & more (upcoming soon)
  • Product Roadmap
  • Development
  • Lead Detection Engineering - Non Human Identities
  • Lead Threat Research - Non Human Identities
Open source productsThreat researchTechnical researchAIML models securitySecurity Architecture & Engineering+1

Independent Consultant

Mar 2024Mar 2025 · 1 yr · Israel · Remote

Aws cloud security user group - middle east

Co-Founder and Co-Chair

Jan 2024Nov 2025 · 1 yr 10 mos · Dubai, United Arab Emirates

  • This is the official AWS Cloud Security User Group in Middle East. It's a community filled with developers, devops, security enthusiasts & many others. The group is mixed with wide range of passionate people - professional experts, students, co-founders, CXOs, freelancers, consultants, managers, etc. coming together to make new connections, learn & share new interesting things.

Uptycs

Subject Matter Expert [CNAPP, Lead Detection Engineering & Threat Research, Thought Leadership,etc]

Apr 2023Jan 2024 · 9 mos · United States · Remote

  • Thought Leadership
  • Lead Detection Engineering - Containers & Kubernetes
  • Lead Threat Research - Containers & Kubernetes
  • DevSecOps
  • Software Supply Chain Security
  • Public speaking - several international conferences & private events
  • CNAPP
  • Product Roadmap
  • Development
  • Mentoring
  • SE
  • Marketing at Kubecon
Thought LeadershipLead Detection EngineeringDevSecOpsSoftware Supply Chain SecuritySecurity Architecture & Engineering

Giant swarm

Platform Engineer

Nov 2022Apr 2023 · 5 mos · Germany · Remote

Stealth startup

Independent Consultant

Oct 2022Present · 3 yrs 5 mos · Remote

  • Working on numerous areas including Security, DevSecOps, CloudNative technology, open-source development, product development, etc.
  • Lead teams in integrating security into their workflows to enhance overall security posture.
  • Active speaker and researcher in the cybersecurity community, with speaking engagements at Gitex, DevSecCon, AWS Community Day, BlackHat Asia, BlackHat USA, etc.
SecurityDevSecOpsCloudNative technologyOpen-source developmentProduct developmentSecurity Architecture & Engineering

Packt

Technical Reviewer

Jan 2022Jan 2024 · 2 yrs · United Kingdom · Remote

Emirates nbd

2 roles

Senior Security Architect

Jun 2021Oct 2022 · 1 yr 4 mos · Dubai, United Arab Emirates

  • Designing, building, and managing PaaS & its security.
  • Leading DevOps team.
  • Containers and Kubernetes security.
  • Integration of automation and DevSecOps.
PaaS securityDevOpsContainers and Kubernetes securitySecurity Architecture & Engineering

Security Architect

Nov 2020Jun 2021 · 7 mos · Dubai, United Arab Emirates

  • Responsible for architectural and design reviews of new integrations and projects.
  • Responsible for end-to-end security review of projects developed by multiple squads.
  • Perform source code review, penetration testing, container review, etc.
  • Developed open-source projects extending Kubernetes functionalities.
Architectural reviewsEnd-to-end security reviewSource code reviewPenetration testingSecurity Architecture & Engineering

Payatu

Security Consultant

Jul 2018Nov 2020 · 2 yrs 4 mos · Pune Area, India

  • Perform Docker and Kubernetes security assessments
  • Implemented end-to-end workflow for DevSecOps service offerings
  • Perform security assessment of web and android applications (both black box and white box)
  • Collaborate with experts while performing infrastructure assessments
  • Perform source code review to discover new vulnerabilities
  • Responsible for end-to-end client delivery
  • Published IEEE research paper on Machine Learning and security
  • Speaker at multiple international security conferences
  • >>>> Hack In The Box (HITB), Dubai
  • >>>> Bsides, Egypt
  • >>>> CRESTCon, London
  • >>>> Hack In The Box (HITB), Amsterdam
  • >>>> PHDays, Moscow, Russia
  • >>>> DEFCON, Las Vegas
  • Trainer at Nullcon India (Android Application Security)
Docker security assessmentsKubernetes security assessmentsDevSecOps service offeringsSecurity Architecture & Engineering

Google summer of code

Nmap Developer

May 2017Aug 2017 · 3 mos · Remote

  • One among the only 4 people to get selected world-wide. My contribution during this period - 17,000+ lines of code.
  • Authored script to fetch smb enum services from remote windows machine.
  • Authored script for enumerating (iOT)devices running on OpenWebNet protocol.
  • Authored punycode and idna libraries for nmap to handle unicode input.
  • Refactored http-enum script for optimization purposes.
  • Made ncat enhancement to limit data using a delimiter while transferring data.
  • Fixed issues related to cve-2014–3704 nse script.
  • Enhancements made to cve-2014–3704 nse script.
  • Removed redundant parsing functions by making enhancements from few libraries.
  • Autocomplete feature for --script-args parameter in nmap. Due to lack of compatibility issues with Windows OS and zsh shell, it is not merged yet.
  • Colored output for nmap.
  • Added missing ip protocols to netutil.cc.
  • Complete report - https://medium.com/@rewanthcool/gsoc-2017-with-nmap-security-scanner-80d9bd54a97a
Website security assessmentSecurity Architecture & Engineering

Provensec

Associate Security Researcher Intern

Jun 2016Sep 2016 · 3 mos · Remote

  • Developed automated web vulnerability scanner using Python, selenium and PhantomJS worth $2000 USD/year along with 3 other employees.
  • Authored and integrated plugins to the vulnerability scanner.
  • Developed module to save screenshot of the website when the payload is executed as a POC.
  • Worked as a penetration tester as well.
Web developmentAngularJSBootstrapFull-Stack Development

Appyfest

Full Stack Web Developer Intern

Jun 2016Jul 2016 · 1 mo · Gurgaon, India

  • Added new functionalities and features to the website while optimizing the existing features in the present website.
  • Worked on AngularJS, Bootstrap during the course of internship.
security assessingpatching vulnerabilitiesSecurity Engineering

Oxcean

Security Advisor & Security Engineer Intern

Mar 2016Aug 2016 · 5 mos · Remote

  • Security assessing of company's website and patching the vulnerabilities.
  • Discovered and patched critical payment gateway bugs which saved thousands of dollars to the company.
  • Worked on handling the security of cloud services and servers as well.
  • Impressed with my work they added my name to their About-Us page (I was only an intern there).
  • View me @ http://oxcean.com/About-us
automated web vulnerability scannerpenetration testingSecurity Research

Gawds

Web developer

Sep 2015May 2018 · 2 yrs 8 mos · NIT Kurukshetra

  • Group of students who are passionate in Web Development.
  • Developed websites for the college fests.
  • Freelanced few projects under this organization.
Automated web vulnerability scannerPenetration testingSecurity Architecture & Engineering

Education

National Institute of Technology, Kurukshetra, Haryana

B.Tech — Computer Engineering

Stackforce found 100+ more professionals with Devsecops & Security Architecture & Engineering

Explore similar profiles based on matching skills and experience