Amol Naik

CEO

Bengaluru, Karnataka, India21 yrs 11 mos experience

Key Highlights

  • Over 20 years in Information Security.
  • Developed world-class security programs at Unacademy.
  • Led security initiatives at GOJEK and Flipkart.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in building security programs and teams across various industries.

Contact

Skills

Core Skills

Enterprise SecurityDevsecopsCloud SecuritySecurity AutomationRisk ManagementCybersecurity

Other Skills

AJAXApplication SecurityBacktrackCEHComplianceCompliance (GRC)Computer SecurityData SecurityEthical HackingFirewallsGeneral Data Protection Regulation (GDPR)GovernanceISO 27001Information SecurityInformation Security Awareness

About

Amol has been working in the Information Security field for over 20 years concentrating on a wide range of areas including offensive security and development & transformation of Cybersecurity program. He has extensive experience in building world class information security teams, product security engineering, devsecops, information/cybersecurity security frameworks, system and network security, risk, compliance, web/mobile/network penetration testing, vulnerability management, and cloud security. Joining Unacademy in 2020, he developed a new Information Security program from the ground up and built & developed a world class information security organisation. Working across the business functions, the Information security program included areas such as development of security policies, new security business processes embedded across business units, development of annual cybersecurity roadmaps, and successful execution of numerous security projects, adherence to audit and due diligence, architecturing security requirements into products and services, and development and execution of an overall information security strategy. Before joining Unacademy, Amol worked at GOJEK as Head of Information Security building security team and programs from the ground up. His experience for GOJEK included building product security and devsecops teams which helped secure GOJEK’s cloud infrastructure and web/mobile applications. Amol also worked at Flipkart, Mercedes-Benz Research & Development India Pvt Ltd, Persistent Systems, MIEL e-Security Pvt. Ltd in the past as information security consultant focusing on building information security teams and consulting with customers to secure their organisations. Career Highlights: - Security Research: https://www.exploit-db.com/search?e_author=Amol%2Bnaik - Bug Bounty: Google, Facebook, PayPal, Nokia - 0-day research in Browsers: https://amolnaik4.blogspot.com/p/advisories.html - First Real-world self-xss: https://amolnaik4.blogspot.com/2011/03/exploitation-of-self-only-cross-site.html - GOJEK ProdSec journey: https://blog.gojek.io/how-to-secure-a-superapp/ - Bodhi: https://github.com/amolnaik4/bodhi - Nullcon Review Panel: https://nullcon.net/review-panel/amol-naik

Experience

Hugohub

Security @ HugoHub

Dec 2024Present · 1 yr 3 mos

ISO 27001SOC 2Enterprise SecurityApplication SecurityDevSecOpsStrategic Roadmaps+1

Mpokket

Virtual CISO

Mar 2024Jul 2024 · 4 mos · Bengaluru, Karnataka, India · On-site

  • Identified RBI Master Directives applicable to NBFCs and prepared information security roadmap to comply to the regulation
  • Identified frauds from Telegram groups, investigated user onboarding process and built business case to deprecate cKYC flow to mitigate the frauds
  • Assisted with vendor identification, product evaluation and negotiation for cloud security product
  • Conducted application pentest for Web & Mobile app with the help of 3rd party vendor
  • Prioritised security initiatives within AOP planning for 2 quarters
  • Evangelised Security at leadership level with continuous security reporting
  • Audited code for secrets and security vulnerabilities using SAST tools, communicated findings to engineering team and help them prioritised
  • Automated Employee account audits highlighting ex-employee active accounts across cloud, Google Workspace and other business applications
  • Documented Information Security policies and conducted IR drill for cloud environment
  • Managed to reserve 10% developer bandwidth for security work
Strategic RoadmapsSecurity AutomationCloud SecurityInformation Security AwarenessGovernanceRisk Management+1

Career break

Career transition

Apr 2023May 2025 · 2 yrs 1 mo

Unacademy

Chief Information Security Officer

Jun 2020Mar 2023 · 2 yrs 9 mos · Bengaluru, Karnataka, India

CybersecurityProduct SecurityRisk ManagementISO 27001Information Security ManagementEnterprise Security+4

Gojek tech

2 roles

Head Of Information Security

Promoted

Apr 2018Jun 2020 · 2 yrs 2 mos

  • Security Operations:
  • Asset management
  • Vulnerability management
  • Attack alert & monitoring
  • Bug bounty management
  • Product Security:
  • Mobile app/API/web application pentest
  • Secure product design review
  • Micro-service authentication
  • 3rd party integration
  • Security Automation:
  • Cloud security (AWS & GCP)
  • API scanners
  • Credential management
  • Server audits/hardening
  • Secure code review
  • Code Dependency Scanning
  • Enterprise Security:
  • Endpoint Protection
  • Mobile Device Management
  • GSuite Security configurations
  • Threat Intelligence
  • Other Relevant Experience:
  • Preparing security team goals for each quarter
  • Setting up OKRs & managing progress
  • Timely updates to leadership team
  • Participation in mitigation discussions with tech leads
CybersecurityRisk Management

Vulnerability Researcher

Jul 2016Apr 2018 · 1 yr 9 mos

Self

Vulnerability Researcher

Mar 2016Jun 2016 · 3 mos · Bengaluru Area, India

Flipkart

Security Analyst III

Aug 2014Feb 2016 · 1 yr 6 mos · Bengaluru Area, India

Mercedes-benz research and development india

Web Application Pentester

Jun 2012Aug 2014 · 2 yrs 2 mos · Bengaluru Area, India

Persistent systems

2 roles

Team Lead - Security Practice

Jan 2011Jun 2012 · 1 yr 5 mos

  • Involved in creation of techno-commercial proposal, customer interactions for requirement analysis.
  • Team Managerment
  • Independently executed Cert-In Empanelment offline & online tests
  • Involved in setting “Network Penetration Testing” methodology
  • Executing Proof of Concepts for various clients
  • Ensuring high quality project deliverables
  • Conducted internal presentations on Basic Networking concepts, Clickjacking, Detailed SQL injection, etc.
  • Providing web application training to peers
  • Execution of Web application security and network penetration testing assignments

Module Lead - Security Practice

Jul 2010Jan 2011 · 6 mos

Miel e-security pvt. ltd.

Technical Consultant - Information Security

Jan 2008Jul 2010 · 2 yrs 6 mos

  • Application Penetration:
  • As the Application Pen-tester was responsible to conduct detailed assessment of the application security posture of client as per Industry standards.
  • External Penetration:
  • As the Pen-tester was responsible to conduct detailed assessment of security posture of the internet facing Systems & Network of client as per Industry standards.
  • Vulnerability Assessment:
  • As a security consultant was responsible to conduct detailed assessment of security posture of the Internal Systems & Network Devices of client as per Industry standards.

Infosys technologies ltd

Analyst

Oct 2007Jan 2008 · 3 mos

Reliance communications

Network Security Engineer

Oct 2006Oct 2007 · 1 yr

  • Management of firewalls, including Netscreen, Cisco PIX & CheckPoint.
  • Configuration & troubleshooting of VPN
  • Engineering and Administration of network and monitoring devices.
  • Security Hardening of Solaris, Linux, and Windows servers.
  • Incident logging/updating and daily system monitoring/maintenance.
  • Backup/Restoration of Firewall config.

Trident infotech services

Sr. Executive - Technical Support

Jan 2005Jan 2006 · 1 yr

Celetronix

Engineer

May 2003Oct 2005 · 2 yrs 5 mos

Education

North Maharashtra University

BE — Electronics & Telecommunication Engg

Jan 1999Jan 2002

Government Polytechnic, Amravati

Diploma — Electronics & Telecommunication Engg

Jan 1996Jan 1999

Stackforce found 100+ more professionals with Enterprise Security & Devsecops

Explore similar profiles based on matching skills and experience