Jovin Lobo

DevOps Engineer

Pune, Maharashtra, India14 yrs experience
AI EnabledAI ML Practitioner

Key Highlights

  • Revitalized Security Champions programs for enhanced security culture.
  • Led SAST implementation optimizing vulnerability detection.
  • Managed bug bounty programs ensuring timely vulnerability resolution.
Stackforce AI infers this person is a Cybersecurity expert specializing in application security and vulnerability management.

Contact

Skills

Core Skills

Security Program ManagementThreat & Vulnerability ManagementSecurity Testing

Other Skills

AWS SecurityAndroid SecurityApplication SecurityBashDevSecOpsInformation SecurityInformation Security ManagementJavaScriptLarge Language Models (LLM)LinuxNetwork SecurityPrompt EngineeringPythonRisk AssessmentSecurity

About

About Me: Passionate and results-driven security professional with extensive experience in driving robust security measures to safeguard organizational assets. Proven track record in spearheading initiatives such as Security Champions programs, Static Application Security Testing (SAST), End of Life (EOL) management, Pentesting and Bug Bounty Program management, LLM (Large Language Models) security, and Threat Modeling. Skilled in collaborating with cross-functional teams to identify and remediate security vulnerabilities effectively. Professional Experience: * Security Program Management: Revitalized Security Champions programs to foster a culture of security awareness and collaboration across engineering pods. Conducted regular training sessions and provided guidance to enhance security posture and awareness. Collaborated closely with Security Champions to identify and address security vulnerabilities promptly. * Threat Modeling and Rapid Risk Assessments: Conducted Rapid Risk Assessments to swiftly evaluate security risks in projects. Reviewed high-level architecture diagrams and documentation for newly designed application features. Provided expert guidance on security considerations during the design phase. * Static Application Security Testing (SAST): Led the implementation and maintenance of Semgrep via Github actions, optimizing results and customizing rules to detect organization-specific vulnerabilities. Ensured seamless operation of Semgrep toolset by managing licensing renewals and resolving technical issues. * End of Life (EOL) Management: Implemented proactive measures to identify and address end-of-life Docker base images, mitigating potential security risks. Conducted educational sessions for developers to understand EOL implications and recommended solutions for timely remediation. * Pentesting and Bug Bounty Program Management: Co-managed bug-bounty program, overseeing issue triage, reward management, and resolution coordination with development pods. Managed vulnerability response process, ensuring adherence to SLAs and expediting bug fixes with recommended security measures. * Compliance and Audit Support: Provided comprehensive support to compliance teams, assisting in documentation related to application security and providing evidence for audits. * LLM (Large Language Models) Security: Evaluated the security posture of LLM-based applications, including both OpenAI and Gemini platforms. Assessed and provided recommendations for enhancing the security of LLM prompts.

Experience

Verto

Devsecops Lead

Aug 2024Present · 1 yr 7 mos · India · On-site

AWS SecuritySecurity Program Management

Razorpay

Application Security Lead

Nov 2022Jul 2024 · 1 yr 8 mos

Threat & Vulnerability ManagementSecurity Program ManagementLarge Language Models (LLM)Security Awareness TrainingPrompt EngineeringRisk Assessment+1

Notsosecure | part of claranet cyber security

2 roles

Senior Security Consultant

Promoted

Apr 2021Nov 2022 · 1 yr 7 mos

Threat & Vulnerability ManagementSecurity Awareness TrainingRisk AssessmentSecurity Testing

Security Consultant

Feb 2020Apr 2021 · 1 yr 2 mos

Threat & Vulnerability ManagementSecurity Awareness TrainingRisk AssessmentSecurity Testing

Amdocs

2 roles

Information Securtiy Specialist

Jun 2017Feb 2020 · 2 yrs 8 mos · Pune Area, India

Threat & Vulnerability ManagementSecurity Awareness TrainingSecurity Testing

Information Security Analyst

Jun 2015May 2017 · 1 yr 11 mos · Pune Area, India

Threat & Vulnerability ManagementSecurity Awareness TrainingSecurity Testing

Aujas networks pvt ltd

Associate Consultant

Jun 2014May 2015 · 11 mos · Mumbai Area, India

Null the open security community

Pune Chapter Lead

Jan 2012Apr 2017 · 5 yrs 3 mos · Pune Area, India

Payatu technologies

Application Security Consultant

Jan 2012Jun 2014 · 2 yrs 5 mos · Pune Area, India

Education

SYMBIOSIS INTERNATIONAL UNIVERSITY

Jan 2010Jan 2012

Symbiosis Institute of Computer Studies and Research

Master of Science - MS — Computer Applications

Jan 2010Jan 2012

Stackforce found 100+ more professionals with Security Program Management & Threat & Vulnerability Management

Explore similar profiles based on matching skills and experience