Prajal Kulkarni

CEO

Bengaluru, Karnataka, India15 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Founding member of Flipkart's security team.
  • Delivered multiple security trainings at industry conferences.
  • Recognized in Hall of Fame for major tech companies.
Stackforce AI infers this person is a seasoned cybersecurity expert with extensive experience in vulnerability assessment and penetration testing.

Contact

Skills

Other Skills

Application SecurityBacktrackCCNACEHComputer SecurityElasticSearchFirewallsIPSISO 27001Information SecurityInformation Security ManagementInfrastructureLinuxMetasploitNessus

About

• I was fortunate to be one of the early members which formed the Flipkart security team. Helped grow the team in several security verticals making it one of the most decorated security teams in Indian infosec ecosystem handling complex security problems for Flipkart and its group companies. • Associated with PayPal India Ltd as a Security Engineer, since October 2013. • Associated with PriceWaterhouseCoopers-SDC as a Software Engineer Core Security, Jan 2013 to October 2013. • Associated with Microland Bangalore as Analyst – Professional Services in the department of Vulnerability Assessment and Penetration Testing from October 2010 to Nov 2012. • CEH Certified security professional. • CVE-2012-4002, CVE-2012-4003 CVE-2012-4062, CVE-2013-1761. • In the Hall of Fame for Facebook, Twitter, Google, and Adobe/BugGinie/RedHat/Tuenti/Microsoft/GLPI/Ebay/Acquia/ConstantContacts/37Signals/Owncloud/Ifixit Acknowledgement pages. Skill Summary: • Discovered several vulnerabilities in Core components of GLPI (CVE-2012-4002, CVE-2012-4003), discovered several issues in OCS Inventory (CVE-2012-4062), discovered Local File inclusion vulnerability in one of the core components of Bug Ginnie. • Web Application and Infrastructure Vulnerability Assessment and Penetration testing tools [Acunetix vulnerability scanner, Nmap, Metasploit, Backtrack, Nessus, Nexpose, Paros Web Proxy, WebScarab, Burp Suite, Web Developer etc] Key Projects: Vulnerability Assessment, Penetration Testing, Wireless Network Security Assessment, Web Application Penetration Testing, Threat Modelling, Source Code Review, Vulnerability Research, Web application Firewall (ModSecurity, NAXSI), Log Analysis using Elastic Search/Logstash/Kibana. Security Trainings Delivered: NullCon 2015 - https://nullcon.net/website/goa-15/training/attack-monitoring-using-elasticsearch-logstash-kibana.php NullCon 2016 - https://nullcon.net/website/nullcon-2016/training/attack-monitoring-using-elasticsearch-logstash-kibana.php NullCon 2018 - https://nullcon.net/website/goa-2018/training/attack-monitoring-using-elastic-stack.php C0c0n 2018 - https://is-ra.org/c0c0n/workshop/pre-conference-workshop/#tab4 NullCon 2019 - https://archive.nullcon.net/website/goa-2019/training/building-an-attack-monitoring-solution.php NullCon 2020 - https://archive.nullcon.net/website/goa-2020/training/building-enterprise-grade-security-analytics-platform-using-elastic-stack.php

Experience

Black hat

Blackhat Advisory Board - Financial Summit (EU)

Oct 2025Present · 5 mos

  • As part of the advisory board I help curate a solid lineup of security topics and review speaker submissions.

Groww, india

Chief Information Security Officer

Jan 2023Present · 3 yrs 2 mos · Bengaluru, Karnataka, India · On-site

Cleartrip

Business Information Security Officer

Nov 2021Jan 2023 · 1 yr 2 mos · Bengaluru, Karnataka, India

  • My responsibility as a BISO for Cleartrip I am responsible to lead the entire security charter for the company.
  • Here are few functional areas I lead as a BISO :
  • Drive strategic security programs to enhance the security maturity across the organisation. Conduct periodic information security council meetings in the respective business units involving senior leadership and other relevant stakeholders.
  • Develop an in-depth understanding of business processes, systems, technologies, data, customers, and vendor partners.
  • Design, implement and sustain the Information Security Policies and Standards across Cleartrip
  • Act as the primary security contact/ adviser for the business, leadership, engineering, product, IT, HR, Finance, and Legal.
  • Partner with compliance, legal and other stakeholders to achieve the objectives of the information security program and be compliant with required regulatory and statutory requirements.
  • Own and oversee cyber security program implementation required to meet business objectives.
  • Proactively identify information security non-compliance and areas of potential improvement, and facilitate the development and deployment of remediation solutions.

Flipkart

5 roles

Senior Security Architect

Promoted

Jul 2021Jan 2023 · 1 yr 6 mos

  • Taking care of Flipkart production security consisting of 300+ internet facing assets, hybrid cloud infra, secure CI-CD, and anything and everything touching flipkart online customers.
  • I also play the head of security role for Flipkart acquired Cleartrip. Drafting, executing and spearheading the strategic security projects for the organisation.

Security Architect

Promoted

Jul 2018Jun 2021 · 2 yrs 11 mos

  • At Flipkart, I have been the founding member of the nascent AppSec team and has helped it grow and cater to the growing complexity of micro-services / applications.
  • Over the years, I have introduced several working streams inside the team to further strengthen the security practices and offerings for the rest of the developer community within the Org. I have spearheaded the effort to move the security awareness in the org, through various evangelization initiatives like Braindead - Capture The Flag events as well as Secure Coding best practices, developer training sessions.
  • Ideated several red-team tooling which has strengthened the attack arsenal engine responsible to detect any security anomalies in Flipkart's internet facing endpoints.
  • Mentored my team in developing and open-sourcing security toolkits (Astra, Red Team Arsenal - RTA, WatchDog, and Kurukshetra) which have received very good uptake in the open-source / security community.

Security Analyst 4

Jul 2017Jul 2018 · 1 yr

Security Analyst 3

Jan 2016Jul 2017 · 1 yr 6 mos

Security Analyst 2

May 2014Jan 2016 · 1 yr 8 mos

  • Web application Security, Vulnerability Assessments, Penetration Testing, Designing Attack Monitoring Solutions, ElasticSearch Logstash kibana (ELK), threat modeling.

Paypal

Security Engineer level 3

Oct 2013Apr 2014 · 6 mos · Bangalore

  • Was leading PayPal's public bug bounty project consisting of all PayPal's internet facing endpoints and it's of subsidiaries. Handled internal security assessment projects and penetration testing efforts. Conducted several developer training session on secure code and Secure SDLC practices.
  • Delivered a training session at GraceHopper 2014 Bangalore on "Hacking Demystified" which touched upon real-world attack scenarios and underground dark web information trading techniques.
  • Also delivered a technical presentation at Confidence 2014 Poland, on a research topic related to WordPress Security.

Pwc

Sr Security Engineer

Jan 2013Oct 2013 · 9 mos · Bangalore

  • Was part of the core security team at PWC-SDC India, handling security projects for SDC clients.
  • Also conducted security training sessions for developers on secure code, wireless security, mobile pentesting and secure SDLC.

Microland limited

2 roles

Senior Security Engineer

Promoted

Jan 2012Nov 2012 · 10 mos · Bangalore

Security Engineer

Oct 2010Dec 2011 · 1 yr 2 mos · Bangalore

  • Was part of the Microland's Red-team which carried out multiple security red-team projects across the globe. Was responsible to carry out pen-testing projects related to network,web-applications, mobile-apps and wireless networks. Handled client engagement for many offshore and onshore projects from the very initial stage of requirements gathering to end execution of projects.
  • Designed and implemented a network of Intrusion Detection Systems and reporting utilities.

Education

Goa Engineering College - Government of Goa

B.E — Electronics & Telecommunication Engineering

Jan 2006Jan 2010

Shree Damodar Higher Secondary School of Science

Pre - University

Jan 2004Jan 2006

The New Educational Institute

10th

Jan 2004Present

Stackforce found 100+ more professionals with Application Security & Backtrack

Explore similar profiles based on matching skills and experience