Arpit Mittal

Product Manager

India10 yrs 3 mos experience
Most Likely To Switch

Key Highlights

  • Over 10 years of experience in Information Security.
  • Expert in application security strategies and DevSecOps integration.
  • Recognized for identifying severe vulnerabilities across multiple platforms.
Stackforce AI infers this person is a Cybersecurity Specialist with a focus on Application Security and DevSecOps in various industries.

Contact

Skills

Core Skills

Application SecurityDevsecopsRisk ManagementVulnerability AssessmentSecurity Testing

Other Skills

Analytical SkillsApplication Security AssessmentsArchitecture ReviewsCloud SecurityContinuous Integration and Continuous Delivery (CI/CD)Cyber-securityData PrivacyEngineering ManagementGoogle Cloud Platform (GCP)Information SecurityInformation Security ManagementInfrastructure SecurityLeadershipNetwork SecurityOWASP

About

With over 10+ years of experience in the Information Security domain, specializing in Product Security, I excel in implementing application security strategies across diverse industries. As the Product Security Specialist, I establish security goals, objectives, and strategies to effectively address and prioritize security risks. Proficient in conducting security testing and ensuring compliance with regulations and best practices, I develop and enforce security policies, standards, and procedures. Collaborating closely with risk owners, I orchestrate the integration of DevSecOps pipelines and oversee cloud security measures. I foster team growth through mentorship and guidance, enhancing understanding and proficiency in security practices. My expertise extends to providing security expertise for threat modeling, technical security assessments, and custom security solutions. Continuously monitoring emerging threats, I evaluate new technologies and methodologies to stay ahead of risks. With a data-driven approach, I monitor and analyze application security metrics, ensuring continuous enhancement. Strengthening overall security posture, I implement automated workflows and conduct regular security audits to fortify defenses. • Application Security (Web and Mobile) • Web Services Security/API's • Network Security & Infrastructure Audit with CIS Benchmark • Source Code Review • Vulnerability and Threat Management • Threat Modeling / Architecture Review (SDLC) • Vendor Risk Assessment/Risk management • DevSecOps & Cloud Security (AWS) Certifications: • Certified Application Security Practionar (CAP) - 2023 • CompTIA Security+ - 2020 • Azure Security Engineer (AZ-500) - 2020 • Azure Security Fundamentals (AZ-900) - 2020 • Certified Ethical Hacker v9 – 2016 Key Achievements: • Received multiple appreciation certificates, Hall of Fame & bounties from several organizations for finding out severe vulnerabilities on their websites • “Facebook” for Information Disclosure • “intel” for XSS vulnerability • “cloudbuilders.intel.com” for Stored XSS Injection vulnerability • Edmodo” for found Documentation files or configuration files publicly accessible (Directory Listing) • “ESET” for found CMS configuration directory (Directory Listing) • “Heroku” (URL Redirection via Referrer Header) • SOPHOS (CORS Exploitation) • DELL (Sensitive Data Disclosure on GitHub) and from many private websites. Arpit is always interested to hear from colleagues, managers or interesting creative folk, so feel free to contact if you’d like to connect.

Experience

Ltimindtree

Specialist - Cyber Security

Jun 2024Present · 1 yr 9 mos · Hybrid

Application SecurityDevSecOpsProduct SecurityTeam LeadershipVulnerability Management

Persistent systems

Project Security Lead

Aug 2023May 2024 · 9 mos · Pune, Maharashtra, India · Remote

  • Spearheading the definition and development of security goals, objectives, roadmap and strategies to prioritize tasks.
  • Coordinating & overseeing regular security testing (DAST/SAST), including penetration testing & vulnerability assessments.
  • Collaborating with developers to integrate security into project architecture.
  • Preparing and presenting regular security reports to management and stakeholders.
  • Ensuring compliance with security regulations and industry best practices.
  • Developing and maintaining project-specific security requirements and guidelines.
  • Providing mentorship and guidance to enhance team members' security knowledge.
Application SecurityOWASPPenetration TestingProduct SecurityRisk AssessmentRisk Management+6

Null - the open security community

Null Chapter Lead - Null Indore

Apr 2021Jan 2023 · 1 yr 9 mos · Indore, Madhya Pradesh, India

  • Knowledge contribution towards community.
Unix

Acko

Application Security Manager

Feb 2021Aug 2023 · 2 yrs 6 mos

  • Managed security assessment (DAST/SAST) processes with automated/ manual approaches with DevSecOps methodology to enhance the security posture of ACKO.
  • Successfully managed bug bounty program and application security metrics analysis.
  • Staying updated with emerging security threats and recommending new security technologies.
  • Collaborating with compliance and audit teams to ensure regulatory compliance.
  • Monitoring and analyzing application security metrics for improvement.
  • Successfully resolved security issues through collaboration with relevant teams.
  • Automated security workflows including thread modeling, reviewed user authentication & accessed control architecture of implementations across ACKO codebase to perform periodic security audits across functions & own resolution.
OWASPContinuous Integration and Continuous Delivery (CI/CD)Security Architecture DesignInfrastructure SecurityTeam LeadershipSecurity Testing+23

Infosys

Associate Consultant

Sep 2018Feb 2021 · 2 yrs 5 mos · Pune Area, India

  • Conducted Vulnerability Assessment and Penetration Testing for various applications and infrastructure.
  • Led a team of 5 resources, ensuring timely delivery of reports and client updates.
  • Implemented DevSecOps pipeline for automated security assessments.
  • Provided training sessions on vulnerability assessment, penetration testing, and security awareness.
  • Ensured compliance with regulations and standards through effective security measures.
OWASPContinuous Integration and Continuous Delivery (CI/CD)Infrastructure SecurityTeam LeadershipSecurity TestingVulnerability+12

Quick heal

Security Consultant

Jan 2018Jun 2018 · 5 mos · Pune Area, India

  • Led Vulnerability Assessment and Penetration Testing for network, web applications, mobile applications and API’s.
  • Ensured timely delivery of status updates and final reports to clients.
  • Managed client queries & projects related banks, e-commerce, GST vendors etc.
OWASPInfrastructure SecurityTeam LeadershipSecurity TestingVulnerabilityLeadership+7

Network intelligence (i) pvt. ltd.

Cyber Security Analyst

Dec 2016Jan 2018 · 1 yr 1 mo · Mumbai, Maharashtra, India

OWASPSecurity TestingVulnerabilityCyber-securityApplication Security AssessmentsUnix+2

Ctg security solutions™

Information Security Analyst

Aug 2015Nov 2016 · 1 yr 3 mos · Indore, Madhya Pradesh, India

OWASPSecurity TestingUnixSecurity Consulting

Education

Rajiv Gandhi Prodyogiki Vishwavidyalaya

Bachelor’s Degree — Computer Science Engineering

Jan 2011Jan 2015

Stackforce found 100+ more professionals with Application Security & Devsecops

Explore similar profiles based on matching skills and experience