Vaibhav Gupta

Founder

Dublin, Ireland15 yrs 7 mos experience
Highly Stable

Key Highlights

  • 14 years of experience in security engineering roles.
  • Active community contributor at major security conferences.
  • Developed open-source tool for container security.
Stackforce AI infers this person is a seasoned security engineer with expertise in SaaS and Fintech sectors.

Contact

Skills

Other Skills

Application SecurityCEHCryptographyInformation SecurityMalware AnalysisNetwork SecurityPenetration TestingReverse EngineeringSecure Code ReviewSecurity Architecture DesignSecurity AuditsSecurity EngineeringThreat ModelingVulnerability AssessmentVulnerability Management

About

|| Professional with ~14 years of experience in security engineering roles || • Threat modelling enterprise scale apps and cloud architectures • Enabling cross product team’s collaboration to reduce re-invention of secure engineering problems • Automating security: Vulnerability detection at scale, Improving processes • Mentoring and training team of security researchers/architects • Promoting team’s visibility and cultivating security culture in the company by conducting security sessions, trainings, CTFs, etc. • Interviewing candidates for technical and functional fit • Handled 0-days and responsibly disclosed vulnerabilities via Adobe PSIRT • Performed VA/PT/Config audits on apps. and infra nodes • Active community contributor: Speaker/Trainer - BlackHat USA, DefCon USA, OWASP AppSec EU, NullCon, BSides Vegas, Academia, etc. • Developed open-source tool on container security: ArmourBird CSF • Few CVEs credited: CVE-2012-1058, CVE-2016-9981, CVE-2016-6042

Experience

Appfend

Founder

May 2024Present · 1 yr 10 mos · County Dublin, Ireland

  • Building Appfend. We are empowering developers with secure engineering skills using our hands-on cloud based labs and security knowledge guides.

Amazon

Product Security Engineering - Amazon Payments

Feb 2021Jun 2023 · 2 yrs 4 mos · Dublin, County Dublin, Ireland

Adobe

Security Architect

May 2013Jan 2021 · 7 yrs 8 mos

  • Conducted 100+ small to enterprise grade application architecture security reviews and threat modelling. Few notable products:
  • .... o Licensing framework used by all Adobe desktop products
  • .... o Central compute platform for hosting all Adobe’s ML web-services
  • .... o AWS federated authN/Z provider used by all Adobe employees
  • .... o Sandboxing of desktop app shipped with all Adobe products
  • .... o Central code signing framework for all Adobe desktop products
  • Conducted AWS & Azure deployments’ security reviews
  • Researching on secure design patterns and architectures
  • Contributing and driving security standards across company (AWS Security, & Container Security)
  • Solving security engineering problems at scale – creating re-usable artefacts like guidelines/trainings, creating automation scripts, etc.
  • Assisted on multiple security frameworks development (Vulnerability detection at scale, 3rd party libs’ vulnerability management, etc.)
  • Handling externally reported product vulnerabilities: Technical assessment & remediation guidance
  • Worked on investigating 0-days: Decoupling malware payload, De-obfuscation & Debugging, Root cause analysis, Creating MAPP signatures
  • Community participation by sharing knowledge in InfoSec conferences (BlackHat/DefCon USA, OWASP AppSec EU, NullCon, BSides Vegas) along with active involvement in local chapters and academia
  • Mentoring team of security researchers/architects to raise bar of security reviews
  • Promoting team’s visibility and developing internal security engineering community by conducting security sessions, trainings, CTFs, etc.
  • As an interview panel member, I am responsible ensuring the technical and functional fit to the organisation

Fidelity national information services

Senior Information Security Engineer

Jun 2011May 2013 · 1 yr 11 mos · Gurgaon, India

  • Manual/Automated application security penetration tests
  • Manual/Automated infrastructure VA/PT (PCI and Non-PCI)
  • Network devices (router, firewalls, etc.) configuration security audit
  • Vulnerability research to create POC exploits
  • Guiding development and infrastructure teams for vulnerabilities remediation
  • Assisted in ISO 27001 internal audits

Xiarch solutions pvt ltd

InfoSec Consultant - Malware Analyst

Sep 2010May 2011 · 8 mos · New Delhi Area, India

  • [Freelance/Part-time]
  • Worked on malware analysis & incidence response assignments
  • Executed corporate application security trainings

Aks information technology services

Web Application Security Auditor

Jun 2010May 2011 · 11 mos · Noida Area, India

  • [Freelance/Part-time]
  • Executed AppSec assessments for variety of government and private org.’s web applications (Thin client/Thick client/PKI)
  • Consulted vulnerability remediation to the external development teams

Metawing group of companies

Information Security Consultant

Jun 2009May 2010 · 11 mos · New Delhi Area, India

  • [Freelance/Part-time]
  • Handled security assignments and information security trainings
  • Led secure SDLC process and SEO for customer facing in-house applications

Innobuzz knowledge solutions private limited

Information Security Trainer

Jun 2008Aug 2008 · 2 mos · New Delhi Area, India

  • [Freelance/Part-time]
  • Conducted Information Security & Application Security trainings for academia

Education

Stanford University School of Engineering

Stanford Advanced Computer Security Certificate

Guru Gobind Singh Indraprastha University

Bachelor of Technology - BTech — Computer Science

Ramjas School Pusa Road

Stackforce found 100+ more professionals with Application Security & CEH

Explore similar profiles based on matching skills and experience