Neeraj Sonaniya

Security Engineer

Shujalpur, Madhya Pradesh, India7 yrs 6 mos experience
AI EnabledHighly Stable

Key Highlights

  • Expert in Product Security Engineering across multiple industries.
  • Proficient in automation and security assessments.
  • Strong communication and management skills.
Stackforce AI infers this person is a Product Security Engineer with expertise in Cybersecurity and Application Security in the edTech and Travel sectors.

Contact

Skills

Core Skills

It Security AssessmentsApplication SecurityProduct SecurityAutomationCyber-securityInfrastructure Security

Other Skills

AI SecurityAlgorithmsAmazon Web Services (AWS)Application Security ArchitectureArchitecture ReviewsAutomate SASTBug Bounty HuntingBug Bounty Program ManagementBurp SuiteCC++Cloud SecurityCode ReviewCommunicationCreative Problem Solving

About

Experienced in Product Security Engineering with a demonstrated history of working in the edTech and Travel industry. Skilled in Hacking, Linux, Algorithms, Python (Programming Language), Secure SDLC, Automation, Product Security, Secure Code Review, Threat Modelling, Penetration Testing, Mobile App Security, DevSecOps, OWASP etc. Strong Communication and Management skills with a Bachelors of Technology - BTech focused in Mathematics and Computer Science.

Experience

Godaddy

Senior Security Engineer

Dec 2023Present · 2 yrs 3 mos · Remote · Remote

  • Enterprise Security Assessment
  • Third Party Risk Management
  • Exception Management
  • Secure Manual Code Review for Authentication System.
  • Slack Security Assessment.
  • AI Security
Enterprise Security AssessmentThird Party Risk ManagementException ManagementSecure Manual Code ReviewAI SecurityIT Security Assessments+1

Unacademy

3 roles

Lead Product Security Engineer

Apr 2023Dec 2023 · 8 mos

Senior Product Security Engineer

Promoted

Oct 2021Jun 2023 · 1 yr 8 mos

  • Automate SAST and managed the findings.
  • Code Review, Pentest, Design Review.
  • Automating complex stuffs.
  • Effective cross team communication.
  • Security Research to find critical and complex issues in bulk.
Automate SASTCode ReviewPentestDesign ReviewSecurity ResearchProduct Security+1

Product Security Engineer

Oct 2020Oct 2021 · 1 yr

  • Developed a scalable solution for Secrets Hunting/Management in the repositories.
  • New features - pentesting, code review, design review.
  • Automation for proactive actions.
Secrets HuntingPentestingCode ReviewAutomationApplication SecurityProduct Security

Redbus

2 roles

Senior Security Engineer

Apr 2020Oct 2020 · 6 mos

  • Payment Fraud Analysis
  • Application Security
Payment Fraud AnalysisApplication SecurityCyber-security

Security Engineer

Sep 2018Apr 2020 · 1 yr 7 mos

  • Application Security:
  • Development of new security automation tools like red: Assassin, Subdomainizer (open source), AWS S3 Bucket Scanner, etc.
  • Managing bug bounty program - Verification of reported issue, exploring the issue for more critical impact, assignment the issue to a developer with mitigation steps, and rewarding bounty to the reporter.
  • Collaboration with teams over security considerations of new features being developed.
  • Penetration testing and security assessment of new features, reporting security issues to teams, and collaborate with the corresponding team to fix them in a timely manner.
  • Scanning public sources like GitHub, GitLab, etc. for any erroneous leakage of information, data, code, etc.
  • Static Code Review of Go applications.
  • Infrastructure/Network security:
  • Regularly checking for AWS S3 buckets misconfiguration.
  • Monitoring Akamai for different kinds of threats and acting accordingly.
  • Monitoring public security sources to update systems instantly when new security patches available.
  • Monitoring all domains/subdomains to secure them from getting exposed publicly if they're not intended to.
  • Monitoring WiFi networks for weak password/open Access Points.
Security Automation ToolsBug Bounty Program ManagementPenetration TestingStatic Code ReviewApplication SecurityInfrastructure Security

Education

Indian Institute Of Information Technology Allahabad

Master of Technology - MTech — Mathematics and Computer Science

Jan 2018Jan 2018

Madhav Institute of Technology and Science, Gwalior

Bachelor of Technology (B.Tech.) — Computer Science

Jan 2014Jan 2018

Lady Ansuiya Singhania Educational Academy (LASEA) Jhalawar, Rajasthan

High School — Mathematics

Jan 2012Jan 2014

Stackforce found 100+ more professionals with It Security Assessments & Application Security

Explore similar profiles based on matching skills and experience