Harshit Shah

Security Engineer

Delhi, India5 yrs 8 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • 4+ years of experience in security engineering and full stack development.
  • Expertise in vulnerability assessment and penetration testing across multiple platforms.
  • Passionate about secure SDLC and developer training.
Stackforce AI infers this person is a Fintech and SaaS security expert with full stack development capabilities.

Contact

Skills

Core Skills

Vulnerability Assessment And Penetration Testing (vapt)Security AutomationSecure Code ReviewAutomation

Other Skills

Active DirectoryAlgorithmsApplication SecurityBurp SuiteCC++Competitive ProgrammingCryptographyData StructuresDevSecOpsExpress.jsHTMLHypertext Transfer Protocol Secure (HTTPS)JavaJavaScript

About

Security Engineer & Full Stack Developer with 4+ years of experience specializing in Web, API, Mobile, and Network Penetration Testing, Secure Code Reviews, and Security Automation. I’ve conducted advanced VAPT assessments for fintech, SaaS, and enterprise platforms (including Paytm), managed bug bounty programs, and developed in-house security tools that scale across CI/CD pipelines. With a strong foundation in OWASP Top 10, SAST/DAST tools, and DevSecOps, I bring a unique blend of offensive security expertise and full stack development (React, Node.js, Django) to help organizations secure their applications end-to-end. 🔐 Passionate about secure SDLC, developer training, and building automation to enable security at scale. 📩 Let’s connect if you’re building secure apps, need VAPT services, or just want to nerd out about exploit chains and API fuzzing.

Experience

Paytm

Security Engineer

Apr 2022Present · 3 yrs 11 mos

  • Performed comprehensive Penetration Testing across Web, API, Android, and Thick Client apps, identifying and mitigating critical security flaws.
  • Led Secure Code Reviews across high-impact fintech modules, reducing critical vulnerabilities.
  • Developed internal tools to automate vulnerability triage and reporting; integrated with CI/CD.
  • Managed Bug Bounty triage, collaborated with Dev teams for resolution.
  • Conducted security workshops and training sessions to raise SDLC maturity.
Burp SuiteSecure Code ReviewVulnerability Assessment and Penetration Testing (VAPT)Security AutomationApplication SecurityDevSecOps

Safe security

2 roles

Security Associate

Jul 2020Apr 2022 · 1 yr 9 mos

  • Conducted black, grey, and white-box VAPT for web, Android, and internal systems across BFSI and media domains.
  • Delivered remediation guidance, technical risk reports, and presentation decks to stakeholders.
  • Automated scanning pipelines and report generation to reduce turnaround time by 30%.
Vulnerability Assessment and Penetration Testing (VAPT)AutomationTechnical Risk Reports

Information Security Analyst

Jan 2020Jul 2020 · 6 mos

Education

Hack The Box

Jan 2021Present

The LNM Institute of Information Technology

B.TECH.

Jan 2016Jan 2020

dps

12 — science

Jan 2006Jan 2016

Stackforce found 100+ more professionals with Vulnerability Assessment And Penetration Testing (vapt) & Security Automation

Explore similar profiles based on matching skills and experience