Chandan Bhattacharya

CEO

Ghaziabad, Uttar Pradesh, India13 yrs 3 mos experience
Highly Stable

Key Highlights

  • Expert in Security Architecture and Threat Modeling.
  • Led multiple cybersecurity initiatives at Deloitte.
  • Strong background in Application Security and Vulnerability Management.
Stackforce AI infers this person is a Cybersecurity Architect with expertise in Application Security and Threat Management.

Contact

Skills

Core Skills

Security ArchitecturePenetration TestingProject ManagementApplication SecurityThreat ModelingProduct Security

Other Skills

Burp SuiteCybersecurityDesign ReviewMetasploitNessusNetwork SecurityPersonal FinanceRequest for Proposal (RFP)Secure Code ReviewSecure architecture reviewsSecurity Architecture DesignVulnerability AssessmentVulnerability ManagementWeb Application SecurityWeb Application Security Assessment

About

I am an experienced outcome-driven professional carrying a diverse background in Cyber Security in various disciplines such as Application Security, Threat Modeling, DevSecOps, Security Architecture, Secure Software Development Lifecycle (SSDLC), Vulnerability Management, & Penetration Testing.

Experience

Luein analytics

Chief Cybersecurity Architect

Sep 2024Present · 1 yr 6 mos

  • As the Chief Cybersecurity Architect, I have successfully delivered multiple client engagements by:
  • Conducting design and architecture reviews for applications, infrastructure, and data flows.
  • Assessing architectures against security frameworks such as NIST, OWASP, CSA, and CIS.
  • Identifying architectural flaws, insecure design patterns, and high-risk trust boundaries.
  • Defining reference security architectures and embedding security-by-design principles into product roadmaps.
  • Guiding development, DevOps, and product teams in implementing recommended security controls.
  • Leading Threat Modeling workshops using STRIDE and attack tree methodologies.
  • Performing Secure Code Reviews using both manual analysis and automated SAST tools.
  • Eliminating common application vulnerabilities such as injection, XSS, SSRF, and deserialization flaws.
  • Conducting Penetration Testing of applications, APIs, and cloud infrastructure.
  • Translating assessment and testing findings into actionable remediation guidance.
  • Designing and deploying cybersecurity monitoring solutions such as SIEM and SOAR platforms.
  • Building use cases, correlation rules, and dashboards for real-time detection of threats.
Security Architecture DesignProduct SecurityThreat ModelingSecure Code ReviewPenetration TestingSecurity Architecture

Deloitte

2 roles

Manager

Promoted

Jun 2023Aug 2024 · 1 yr 2 mos

  • As a Manager in Deloitte’s Cyber Risk Advisory practice, I led security initiatives for
  • multiple clients across technical and managerial domains.
  • Technical
  • Defined and optimized Secure Architecture Review processes, identifying
  • opportunities for automation.
  • Developed API security standards to improve consistency and coverage across
  • services.
  • Created and maintained Threat Modeling standards; integrated tooling into CI/CD
  • pipelines.
  • Performed SAST, DAST, and SCA to detect and address application security issues.
  • Conducted penetration testing of applications, networks, and infrastructure to
  • uncover vulnerabilities
  • Managerial
  • Oversaw quality assurance processes to ensure accuracy and completeness of
  • deliverables.
  • Led project teams, handled resource planning, risk tracking, and progress reporting.
  • Managed project budgets and ensured alignment with delivery goals.
Design ReviewSecure architecture reviewsProduct SecurityPenetration TestingApplication SecurityThreat Modeling+3

Senior Solution Advisor - Cyber & Strategic Risk

May 2021Jun 2023 · 2 yrs 1 mo

  • Advising clients to secure their applications and infrastructure through the following:
  • Secure by design implementations
  • Application Security Program maturity assessments
  • Threat Modeling
  • SAST/DAST
  • Software Composition Analysis
  • Vulnerability Assessment
  • Penetration testing
Design ReviewSecure architecture reviewsProduct SecurityApplication SecurityPenetration TestingThreat Modeling+1

Synophic systems pvt. ltd.

Senior Information Security Analyst

Mar 2020Mar 2021 · 1 yr · Gurugram, Haryana, India

  • As a Product Security Champion, I led a team of analysts to help product teams by:
  • Driving product security awareness and training initiatives across engineering teams.
  • Facilitating threat modeling sessions to identify design-stage risks and recommend
  • mitigations.
  • Executing regular SAST and DAST scans to uncover and resolve security issues.
  • Performing SCA to assess risks from third-party libraries and dependencies.
  • Auditing OS-level configurations against CIS benchmarks and recommending
  • improvements.
  • Scanning and reviewing OS images to ensure security readiness prior to
  • deployment.
Design ReviewSecure architecture reviewsProduct SecurityApplication SecurityPenetration TestingThreat Modeling+1

Bank of america

Analyst - Application Security

Dec 2017Feb 2020 · 2 yrs 2 mos · Gurgaon, Haryana, India

  • I contributed to application security initiatives by:
  • Performing manual and automated security testing to identify vulnerabilities and recommend mitigations.
  • Driving process improvements and developing proof-of-concept solutions to enhance testing capabilities and delivery quality.
Product SecurityApplication SecurityPenetration TestingWeb Application Security

Ibm india private limited

Security Specialist

Apr 2016Dec 2017 · 1 yr 8 mos · Gurgaon, India

  • I provided Application and Infrastructure Security services for multiple clients by:
  • Conducting end-to-end Application Security assessments, including architecture reviews, configuration hardening, and both manual and automated testing.
  • Performing penetration tests on external-facing applications and APIs to identify potential attack vectors.
  • Leading vulnerability assessments of network infrastructure and supporting timely remediation efforts.
  • Evaluating and enhancing vulnerability management processes based on existing tooling and practices.
  • Testing newly deployed applications to uncover and address critical security weaknesses before go-live.
Secure architecture reviewsProduct SecurityApplication Security

Imsi india pvt. ltd.

Application Security Analyst

Apr 2015Apr 2016 · 1 yr · Gurgaon

  • I supported multiple clients by:
  • Conducting comprehensive application security assessments, including architecture reviews, configuration audits, and manual/automated testing.
  • Leading network vulnerability assessments and coordinating with stakeholders to ensure timely remediation
Secure architecture reviewsProduct Security

Ib technology solutions ltd

System Administrator - Information Security

Mar 2014Apr 2015 · 1 yr 1 mo · Gurugram, Haryana, India

  • Key responsibilities included:
  • Designing, implementing, and maintaining the vulnerability management solution to improve risk visibility.
  • Performing vulnerability scans, managing dashboards, and coordinating remediation with asset owners.
  • Hardening systems to ensure they met security requirements prior to production deployment.

Innobuzz knowledge solutions private limited

Information Security Analyst

Aug 2012Mar 2014 · 1 yr 7 mos · Greater Delhi Area

  • Key responsibilities included:
  • Delivering cybersecurity and digital forensics training to government agencies to enhance cybercrime response capabilities.
  • Conducting security audits of internal networks and applications to identify and address security gaps.

Education

Dr. MGR University

Bachelor of Technology (B.Tech.) — Computer Science and Engineering

Jan 2008Jan 2012

Raisina Bengali Senior Secondary School

12th Standard — Science

Jan 2006Jan 2007

Raisina Bengali Senior Secondary School

10th Standard — Science

Jan 2004Jan 2005

Udacity

Nanodegree program — Mentorship

Jan 2021Jan 2021

Stackforce found 100+ more professionals with Security Architecture & Penetration Testing

Explore similar profiles based on matching skills and experience