Aaditya P.

DevOps Manager

Mountain View, California, United States6 yrs 7 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • 22 CVEs attributed to his findings.
  • Awarded by Prime Ministers for global CTF success.
  • Contributed to hall of fames for major tech companies.
Stackforce AI infers this person is a Cybersecurity Expert with extensive experience in offensive security and application security.

Contact

Skills

Core Skills

Generative AiArtificial Intelligence (ai)Penetration TestingWeb Application SecurityCryptographyNetwork SecurityMalware Analysis

Other Skills

AI AgentsAPI DevelopmentAndroidCC++CEHCSSCloud ComputingComputer ForensicsConfidential ComputingEthical HackingExploit AuthorFirewallsInformation SecurityJava

About

Aaditya Purani is a Senior Security Engineer at Amazon Web Services (AWS) where he leads collaborative pentesting efforts, develops tooling for fellow testers, and drives shift-left initiatives to scale and enhance security testing. Aaditya's primary areas of expertise are web/mobile/blockchain/GenAI application penetration testing, product security reviews, and source code review including reverse engineering. Previously, he was a Senior Security Engineer at Tesla for 3 years. He actively contributes to responsible disclosure programs and is included in the hall of fames for Google, Apple, and AT&T. Aaditya also participates in security capture the flag (CTF) from Perfect Blue which is globally ranked top-1 CTF team and is one of the founding members of UTC (United Texas Coalition). As a researcher, his most famous findings include BTCPay Pre-Auth RCE, Mattermost RCE, and Akamai Zero Trust RCE. As a writer, Aaditya has authored articles for InfoSec Institute, Buzzfeed, Hackin9, and DailyO. He also has 22 CVEs attributed to his findings. He was awarded by Hon. Prime Minister of India Narendra Modi and Hon. Prime Minister of Srilanka Ranil Wickremesinghe in 2017 for winning a global event GCCS 2017 hacking CTF. Aaditya has 7 years of professional experience as a security engineer operating at senior level, within a 12-year active involvement in the security community, with top companies like Tesla, Palo Alto Networks, Bishop Fox, and Amazon Web Services (AWS). Aaditya enjoys doing research & development into offensive and niche appsec subjects. He has also spoken about his collaborative research ("ElectroVolt: Pwning popular desktop apps while uncovering new attack surface on Electron") at most prestigious cyber-security conferences: - Black Hat USA 2022 - DEFCON 30 Interviewed by Forbes, Reuters, and Vice, Aaditya is a recognized SME in cybersecurity and has built a following of 7,000 on X (formerly Twitter), where he shares insights and developments in the field. Aaditya continues to push the boundaries of cybersecurity through innovative research, knowledge sharing, and active community engagement.

Experience

Amazon web services (aws)

2 roles

Senior Security Engineer

Promoted

Jul 2025Present · 8 mos · Virtual - California · Remote

  • Focused on GenAI security @ AWS since 2024.
  • Overseeing security for flagship products (Bedrock, AGI, ARG) and serving as technical lead on org-wide automation projects with leadership visibility. Driving offensive research, including novel discoveries in agentic systems.
  • 🏆 Notable work securing: Nova Models (1P), Nova Act, Bedrock Guardrails, Kiro, Q Developer, Inference Infra, OpenAI support on AWS, AgentCore, Custom Model Fine-Tuning/Deployment.
Artificial Intelligence (AI)Machine LearningGenerative AIAI Agents

Penetration Testing Engineer (SecEng)

Oct 2022Jul 2025 · 2 yrs 9 mos · Virtual - California · Remote

  • Full-stack hacking, leading collaborative pentests, and spearheading automation projects to scale and enhance security measures that protect AWS and its customers
  • Consistently delivering results, tackling complex and ambiguous challenges, and enabling metrics-driven, data-informed decisions. Actively mentoring junior engineers, contributing to the hiring process, sharing knowledge, creating runbooks, and presenting novel TTPs to boost team efficiency and growth.
  • Won 3 back-to-back Amazon Internal CTFs as a solo player competing against teams.
Mobile ApplicationsPenetration TestingCloud ComputingWeb Application SecurityConfidential ComputingGenerative AI+1

Tesla

2 roles

Senior Security Engineer

Promoted

Mar 2021Sep 2022 · 1 yr 6 mos

  • Demonstrated offensive penetration testing competence and ownership in diverse areas for year long, large scale projects: Manufacturing Audit (2019-2020), Energy Audit (2020-2021), and Vehicle system Audit (2021-2022). Findings were presented to the VP and Board of Directors.
  • Ensured that Tesla's mission critical releases were as secure as possible by performing end-to-end security reviews on over 150+ features. Notable work on securing: BTC+DOGE payment release, SentryCam, Non-Tesla Supercharging, Tesla Auth, etc.
  • Discovered and reported 0days in multiple third party vendors such as Akamai Zero Trust, ObserveIT, Avaya, etc.
  • Performed successful Red Team engagements to challenge the security posture of numerous crown jewels and provided guidance for the remediation by going above and beyond for my role.
  • Helped strengthen Tesla's defenses by collaborating with blue team to build robust signals during purple team activities.
  • Proactively reconstructed 1-days/n-days through patch-diffing and led offensive testing efforts to perform company-wide scanning for critical emerging vulnerabilities such as log4j, spring4shell, etc. Always stayed on top of emerging threat landscape, this resulted into Tesla being unaffected during such major incidents.
  • Created documentation for onboarding, workflow for incident handling, testing methodologies/ checklist and third party audit flows that are regularly used by 4 security engineering teams.
  • Developed multiple tooling for security teams and developers which saved over 2000+ human hours every year.
  • Managed many reports submitted to Tesla’s Bug Bounty Program. As a follow up to a report, I led entire end-to-end remediations and conducted internal pentest to identify the breadth of impact and to fix similar issues throughout Tesla before anyone else would find.
  • Designed training programs targeted at developers and led training and awareness initiatives that were attended by over 1,000 employees in 3 years.
CryptographyReverse EngineeringPenetration TestingSecure Code ReviewThreat ModelingWeb Application Security

Security Engineer

Oct 2019Mar 2021 · 1 yr 5 mos

  • Red Team - Offensive Security, AppSec, Vulnerability Research (VR), and Incident Handling - Hacking all the things and keeping Tesla and its customers secure!

Perfect blue

Capture The Flag (CTF) Team Member

Aug 2019Present · 6 yrs 7 mos

  • Perfect Blue is a Capture The Flag (CTF) Team comprising of students and professionals mainly from US and other parts of the world. It is ranked on CTFTime as world’s best hacking team for the year 2020, 2021, and 2023.
  • perfect blue has won the most challenging and prestigious hacking competitions (CTF) events across the world consistently such as GoogleCTF, PlaidCTF, HITCON CTF, DEFCON Quals.
  • As of 2023, perfect blue is playing under “Blue Water”.
  • https://blog.perfect.blue/perfect-blue-finishes-top-1-on-CTFtime-2020
CryptographySolidityComputer ForensicsNetwork SecurityMobile SecurityWeb Application Security

Palo alto networks

Threat Research Engineer Intern

May 2018Aug 2018 · 3 mos · Santa Clara, California

  • Worked alongside with App-ID team to develop manual signatures for Web/Mobile/Thick Client applications by fully understanding the network flow, identifying patterns, testing and deploying on a Palo Alto Networks Firewall.
  • Developed 20+ signatures with applications using HTTP/2, a latest web protocol at that time and built an analyzer
  • Instrumented malware analysis with full reverse engineering of most complex samples and emulated threat in an air-gapped environment to write signatures for detecting and blocking them. Collaborated with Unit42 regularly.
  • Worked on an Internal project (also my Intern project) along with my mentor to automate and enhance signature generation productivity by 100% with minimal false-positives using Machine Learning algorithms.

Bishop fox

Security Analyst Intern

May 2017Jul 2017 · 2 mos · Phoenix, Arizona Area

  • Aaditya Purani was a Security Analyst at Bishop Fox, a security consulting firm providing services to the Fortune 500, global financial institutions, and high-tech startups. Aaditya's primary area of expertise are web application penetration testing, mobile application penetration testing, product security reviews, and source code review.
CryptographyMalware Analysis

Independent

Security Researcher

Jan 2013Present · 13 yrs 2 mos

  • Self-motivated security professional since 2013
  • Diverse skillset: Expertise ranging from Web to Reverse Engineering, capable of tackling any challenge.
  • Awarded bug bounties from over 100 companies worldwide.
  • Active in CTFs as a member of world ranked #1 teams since 2016 (previously with dcua, currently with perfect blue/Blue Water).
  • Researching niche AppSec topics and advancing the field through innovative research.
  • Developing tools for auditing blockchain security.
  • Conducting vulnerability research by reproducing n-days and hunting 0-days in well-known products.
  • Presented at Black Hat USA 2022 and DEFCON 30 on “ElectroVolt: Pwning popular desktop applications while uncovering new attack surface on Electron,” a collaborative research effort.

Education

The University of Texas at Arlington

Bachelor’s Degree — Computer Engineering

Jan 2016Jan 2019

Stackforce found 100+ more professionals with Generative Ai & Artificial Intelligence (ai)

Explore similar profiles based on matching skills and experience