F

Faiz Ahmed Zaidi

CEO

Bengaluru, Karnataka, India9 yrs 5 mos experience

Key Highlights

  • Registered 6+ CVEs and discovered zero-day vulnerabilities.
  • Built security programs reducing risks by 45%.
  • Speaker at OWASP and Defcon on emerging threats.
Stackforce AI infers this person is a Cybersecurity expert with a focus on vulnerability research and application security.

Contact

Skills

Core Skills

Penetration TestingCloud SecurityApplication SecurityInformation SecuritySecurity Research

Other Skills

API SecurityBacktrackBlockchain securityCC++CSSClear VisionCommunicationComputer SecurityContainer SecurityCross-functional Team LeadershipCybersecurityEthical HackerHTML5ISO 27001

About

I specialize in securing web, mobile, cloud, and blockchain systems. Recognized by Apple, Microsoft, Intel, Facebook, and Bosch for responsible vulnerability disclosures, I’ve registered 6+ CVEs and discovered zero-day vulnerabilities. As the OWASP Project Leader for Maritime Security and a contributor to the OWASP Top 10 API Security Risks 2023, I set global standards for secure systems. I’m also a speaker at OWASP and Defcon, sharing insights on emerging threats. What I Do Vulnerability Research: Finding and fixing security gaps. Penetration Testing: Uncovering risks, providing solutions. Blockchain Security: Protecting crypto, NFTs, and smart contracts. Leadership: Building and mentoring top-tier security teams. Key Wins Acknowledged by tech giants for responsible disclosures. Certifications: CISM, CEH, ISO 27001 Lead Auditor. Built security programs that reduced risks by 45% and secured $10M+ crypto investments. Let’s connect and build it more securely.

Experience

Zebpay

Head of Security

Sep 2025Present · 6 mos · Delhi, India · On-site

Miraiedge

Co-Founder

Apr 2025Sep 2025 · 5 mos

Wityliti

Director

Apr 2025Sep 2025 · 5 mos

Owasp® foundation

OWASP Project Leader

Jun 2024Present · 1 yr 9 mos · Remote

  • This project aims to develop an OWASP Top 10 list specifically tailored to the maritime industry. Currently, maritime cybersecurity lacks well-defined standards, and this project leverages the OWASP framework to address this gap.
  • The project will identify the ten most critical security vulnerabilities facing the maritime sector:
  • Gathering and analyzing existing maritime vulnerability data.
  • Prioritizing the most frequent and impactful threats.
  • Developing detailed descriptions for each vulnerability in the OWASP Top 10 for Maritime list.
  • https://owasp.org/www-project-top-10-for-maritime-security/

Cyfiniti labs

Co-Founder

Nov 2023Sep 2025 · 1 yr 10 mos

Cyfai technologies pvt ltd.

Chief Technology Officer

Nov 2023Apr 2025 · 1 yr 5 mos

Chingari

Head of Security

May 2022Oct 2023 · 1 yr 5 mos

TeamworkPenetration TestingClear VisionSecurity Information and Event Management (SIEM)Cloud SecuritySmart Contracts+11

Halodoc id

Security Engineer

Jun 2021May 2022 · 11 mos · India

  •  Worked on end-to-end implementation of AWS-managed web application firewall for dev and prod environment, including researching, testing, and patching WAF loopholes.
  •  Worked on Summologic SIEM solution, created dynamic dashboards and alerts for multiple log volumes, including AWS Cloudtrail, AWS WAF, Okta auth, and production machines
  •  Handled companywide security awareness training, secure coding training and monthly security newsletters
  •  Handled security incidents and Microsoft device compliance management.
TeamworkClear VisionSecurity Information and Event Management (SIEM)Cloud SecurityProduct SecurityCross-functional Team Leadership+4

Colortokens, inc.

Security Engineer

Dec 2019May 2021 · 1 yr 5 mos · Greater Bengaluru Area

  •  Worked on RASP (Runtime application self-protection) based application security product’s (Colortokens XSecure) capabilities and improved signatures and behavioral methods for detecting security vulnerabilities.
  •  Worked on Docker security and Kubernetes security tools like Clair, docker-bench, kube-bench, kube-hunter, anchore-cli, cilium, etc
  •  Worked on serverless security penetration testing (OWASP top 10 for serverless)
  •  Worked as a security engineer to perform web application penetration testing on multiple clients
  • locations and found critical vulnerabilities, including Privilege escalation, SQL injection, Insecure
  • direct object reference, XSS, CSRF, File upload, Remote command injection, etc.
  •  Worked on multiple open-source applications for increasing application security coverage and
  • reported multiple vulnerabilities, including SSRF, CSRF, Host header injection, Clickjacking, and XSS. (CVE-2019-12425 (Apache Ofbiz),
TeamworkClear VisionSecurity Information and Event Management (SIEM)Cloud SecurityProduct SecurityCross-functional Team Leadership+6

Pwc india

Consultant

Feb 2019Dec 2019 · 10 mos · Gurgaon, India

  •  Delivered information security projects as part of an integrated team of Advisory professionals.
  •  Defined technical and business requirements for information security solutions.
  •  Defined information security processes and policies which secure and enable the business.
  •  Enforced business, privacy, and security policies.
  •  Implemented IT and information security-related technology products.
  •  Review, assess, benchmark, and develop issue remediation action plans for all aspects of
  • information security programs and technologies.
  •  Developed information security strategies, architectures, and implementation plans.
  •  Performed essential supervisory duties to mentor and coach junior staff.
  •  Developed people through effectively delegating tasks and guiding staff.
  •  Assign and review the work of more junior employees and assist in preparing the final work
  • products to confirm that the work is performed with the highest quality standards.
  •  Received PwC Above and Beyond Award.
TeamworkClear VisionTesting ToolsApplication SecurityCommunicationThreat Modeling+2

Provensec llc

2 roles

Penetration Testing Practice Lead

Promoted

Feb 2017Feb 2019 · 2 yrs

  •  Managed the cycle of project continuity, reviewed the team’s technical work, and ensured the quality of service deliverables.
  •  Participate in the hiring process (conducting technical cybersecurity interview rounds).
  •  Perform infrastructure and application penetration tests and physical security reviews for our global clients.
  •  Perform application penetration tests across public and private networks.
  •  Develop testing scripts and procedures.
  •  Develop and leverage custom exploits.
  •  Have worked on OSSEC
  •  Work on improvements for provided security services, including continuously enhancing existing methodology material and supporting assets.
  •  Perform web application, mobile application, and network penetration tests.
  •  Develop processes and implement tools and techniques to perform ongoing security assessments
  • of the environment.
  •  Providing technical consultation on Security Tools and Technical Controls.
  •  Experience performing application security assessments, including web applications, mobile
  • applications, and web services.
  •  Examine assets to determine if vulnerabilities exist and, if vulnerabilities are found, propose
  • remediation strategies that can be applied to mitigate them.
TeamworkClear VisionTesting ToolsApplication SecurityCommunicationThreat Modeling+2

Cyber Security Researcher

Jul 2016Jan 2017 · 6 mos

  • I worked as a Security Researcher and found various bugs in various applications.
TeamworkApplication SecuritySecurity Research

Education

Rajiv Gandhi Prodyogiki Vishwavidyalaya

Engineer's Degree — Computer Science and Engineering

Jan 2012Jan 2016

Little Flower H.S School

10+2

Jan 2011Present

Stackforce found 100+ more professionals with Penetration Testing & Cloud Security

Explore similar profiles based on matching skills and experience