Sachin Kumar

Co-Founder

Bengaluru, Karnataka, India3 yrs 2 mos experience

Key Highlights

  • Expert in Cyber Security Engineering and DevSecOps.
  • Proven track record in vulnerability detection and remediation.
  • Passionate about continuous learning and collaboration.
Stackforce AI infers this person is a Cybersecurity and DevSecOps expert with a focus on SaaS solutions.

Contact

Skills

Core Skills

CybersecurityWeb Application SecurityDevsecopsCloud Security

Other Skills

AWSApplication SecurityCI/CDDevOpsEthical HackingIncident ResponseJavaNetwork Security ImplementationOWASP ZAPPayment Card Industry Data Security Standard (PCI DSS)Penetration TestingProduction DeploymentSecurity ImplementationSoftware as a Service (SaaS)SonarCloud

About

Gruß! I'm Sachin Kumar Highly enthusiastic in hands-on experience over Cyber Security, DevOps Security, and Cloud technologies such as AWS. I take pride in my ability to secure systems and deliver actionable insights through my knowledge in Web Application Pentesting, Incident Response, and Security Automation. What Inspires Me I’m driven by a passion for technology and the constant evolution of security in the digital landscape. The ability to secure infrastructures, protect data, and innovate in the face of new challenges inspires me to continually enhance my skills. I firmly believe that through collaboration and continuous learning, I can contribute to shaping the future of secure computing. My Use Case I excel in Cyber Security Engineering, with experience in penetration testing, cloud security, and DevSecOps pipelines. I have practical knowledge in securing infrastructures, automating security processes, and responding to security incidents. My applied competencies span a range of real-world cybersecurity scenarios, making me a strong candidate for roles in: - Web Application and API Security - Cloud Security with AWS (WAF, Shield, CloudFront, EC2, RDS, etc.) - Incident Response and Security Monitoring - DevSecOps Practices with CI/CD pipelines and automation tools like Jenkins My Technologies - Languages: JavaScript, Node, HTML, CSS, Bash - Technologies: Web Application Pentesting, AWS, DevOps Security, GraphQL Security, OpenAI - Tools: Burp Suite, Nmap, Metasploit, MyRecon (self-created), Subfinder, Sqlmap, SSRF, Nuclei, Xssfinder Core Deployments - Penetration Testing: Comprehensive security assessments with a 95% average vulnerability detection rate. - Automation: Streamlined security systems through Python, Bash, and Ansible scripting, enhancing processes by 30%. - AWS Cloud Security: Implemented AWS WAF and Shield to protect against common exploits and DDoS attacks. - Security Incident Monitoring: Built a Metabase dashboard integrating AWS services for real-time attack pattern visualization. My Belief I only claim knowledge of what I’ve implemented practically. I believe that every challenge can be solved through experimentation and iteration. Machines and systems communicate with us, and I aim to master this communication. Teaching is a passion of mine, as guiding others to success brings immense satisfaction. Sharing knowledge creates a collaborative and more secure digital environment. Let's connect and discuss further!

Experience

Coinswitch

Product Security Engineer

Jun 2025Present · 9 mos · Bangalore Urban, Karnataka, India · On-site

Leadsquared

Security Engineer

Aug 2024Jun 2025 · 10 mos · Bengaluru, Karnataka, India · Hybrid

  • Conducted Vulnerability Assessment and Penetration Testing (VAPT) on LeadSquared's core platform, identifying and mitigating security vulnerabilities to enhance platform security.
  • Conducted detailed source code reviews in Java, Python, Node.js, and React.js, pinpointing over 150 critical security flaws.
  • Configured and managed SonarQube for continuous code quality and security analysis, enabling automated static code analysis for early vulnerability detection.
  • Worked closely with development teams to integrate security checks into the CI/CD pipeline, facilitating secure coding practices.
  • DevSecOps Security Integration for Project.
  • Integrated a security-focused CI/CD pipeline for a backend project built with Spring Boot and Gradle to enhance application security and automate vulnerability management.
  • Responsibilities:
  • ● Static Application Security Testing (SAST): Integrated SonarCloud into the CI/CD pipeline to perform static code analysis, identifying vulnerabilities and enforcing secure coding practices.
  • ●Configured automated scans to trigger on every code commit, ensuring real-time feedback to developers on security issues.
  • ●Software Composition Analysis (SCA): Implemented Snyk to scan for known vulnerabilities in
  • third-party libraries and dependencies.
  • ●Developed custom rules to align dependency management with organization standards and mitigate supply chain risks.
  • ● Dynamic Application Security Testing (DAST): Set up OWASP ZAP for real-time dynamic scanning.
  • ○ Configured ZAP to scan the production-like environment, providing a comprehensive report on application vulnerabilities.
  • ○ Automated ZAP report generation and stored reports as artifacts in an AWS S3 bucket for further analysis. Technologies Used:
  • ● Tools: Sonarqube, Snyk, OWASP ZAP
  • ● Languages/Frameworks: Java, Spring Boot
  • ● CI/CD: YAML pipeline with AWS CodePipeline
  • ● Cloud/Infrastructure: AWS Secrets Manager, S3, EC2
CybersecurityNetwork Security ImplementationWeb Application Security AssessmentSecurity ImplementationWeb Application Security

Vulnshields

CEO & Co-Founder

Dec 2023Present · 2 yrs 3 mos · Bangalore Urban, Karnataka, India · Remote

Masai

3 roles

Cyber Security Engineer

Jan 2023Aug 2024 · 1 yr 7 mos · Bengaluru, Karnataka, India

  • ○ Successfully conducted over 75 security assessments on various web,API and mobile applications.
  • ○ Identified and reported 150+ security vulnerabilities, allowing for preemptive risk mitigation and enhanced security.
  • ○ Ensured robust data security through Spring Security, resulting in a notable 50% reduction in data breaches.
  • ○ Reduced the average remediation time for identified vulnerabilities by 30% through effective collaboration with
  • development and IT teams..
  • ○ Enhanced overall security posture by achieving a 88% vulnerability resolution rate in tested applications.
  • ○ Conducted detailed source code reviews in Java, Python, Node.js, and React.js, pinpointing over 150 critical
  • security flaws.
  • ○ Fostered a security-conscious culture within the organization, resulting in a 25% decrease in security incidents and a 15% increase in security awareness among employees.
  • ○ Proficiently created and optimized scripts in Python, Bash, and Perl, resulting in 30% more streamlined security systems and processes.
  • ○ Utilized a diverse toolkit of commercial and open-source tools and manual testing to perform penetration testing, yielding comprehensive security assessments with a 95% average vulnerability detection rate.
  • ● Cloud Security
  • ○ Implemented and configured AWS WAF and Shield to protect web applications from common web exploits
  • and distributed denial of service (DDoS) attacks."
  • ○ Managed AWS IAM policies and roles to ensure least privilege access and enforce security best practices across the organization's cloud infrastructure."
  • ○ Utilized AWS GuardDuty and Detective to continuously monitor AWS environments for security threats and anomalies, reducing incident response time by 30%

Devops | DevSecOps Engineer

Jan 2023Aug 2024 · 1 yr 7 mos · Bengaluru, Karnataka, India

  • Responsibilities and Achievements:
  • Implemented Security Measures:
  • Static Application Security Testing (SAST): Integrated SonarQube into the CI/CD pipeline, automatically scanning the codebase for vulnerabilities with each code commit. Successfully identified and remediated issues such as SQL injection and cross-site scripting (XSS) early in the development cycle.
  • Dynamic Application Security Testing (DAST): Utilized OWASP ZAP and Burp Suite to conduct automated security testing on web applications before deployment. Identified and fixed vulnerabilities including SQL injection, XSS, and insecure server configurations.
DevOpsProduction DeploymentDevSecOpsCloud Security

Cyber Security Engineer(intern)

Mar 2022Dec 2022 · 9 mos · Bengaluru, Karnataka, India

Application Security

Audix technologies

Pentester

Mar 2022Nov 2022 · 8 mos · Mumbai, Maharashtra, India · Remote

Application Security

Hackerone

Ethical Hacker

Jan 2022Aug 2024 · 2 yrs 7 mos · Remote

Education

CV Raman College of Engineering (CVRCE), Bhubaneswar

Bachelor in technology — Computer Science

Jul 2019Jul 2023

Premalok Mission School

12th — Mathematics

Mar 2017May 2019

Stackforce found 100+ more professionals with Cybersecurity & Web Application Security

Explore similar profiles based on matching skills and experience