Sandesh Mysore Anand

Co-Founder

Bengaluru, Karnataka, India17 yrs 10 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Co-founder of innovative AppSec startup.
  • Author of insightful AppSec newsletter.
  • Experienced in leading security initiatives.
Stackforce AI infers this person is a seasoned Application Security expert with a strong focus on enterprise-level security solutions.

Contact

Skills

Other Skills

Application SecurityComputer SecurityDatabasesEclipseEthical HackerInformation SecurityJ2EEJSPJavaJava Enterprise EditionMySQLPenetration TestingProgrammingSecuritySecurity Architecture Design

About

Co-founder, Seezo. Author of Boring Appsec, a newsletter that covers the essential and often overlooked aspects of building and running successful AppSec programs. Co-host of The Boring AppSec Podcast

Experience

Seezo.io

Co-Founder

Jun 2023Present · 2 yrs 9 mos · Bengaluru, Karnataka, India

Razorpay

2 roles

Senior EM, Infosec

Promoted

Oct 2021Nov 2023 · 2 yrs 1 mo

Staff Security Engineer

Oct 2020Sep 2021 · 11 mos

Boring appsec (newsletter)

Author

Aug 2021Present · 4 yrs 7 mos · https://boringappsec.substack.com/

  • AppSec isn't boring. In fact, it’s fascinating! However, the industry tends to focus a lot of energy on the new shiny object. The latest Critical bug or the latest RASP tool or how AI/ML gobbledygook can make the world a better place. The thing is, in addition to keeping up with the latest trends, successful AppSec programs also do the boring things really well (think building an app inventory). This newsletter is about those “boring” things.
  • Subscribe here: https://boringappsec.substack.com/

Synopsys inc

Managing Consultant

Dec 2016Oct 2020 · 3 yrs 10 mos · Bangalore, India

Cigital, inc

6 roles

Managing Consultant

Promoted

Aug 2016Nov 2016 · 3 mos

  • 1. Understand client's application security needs and propose solutions
  • 2. Lead execution of complex projects including architecture risk analysis, red teaming, scalable vulnerability assessments, scalable source code review etc.
  • 3. Explain security concepts, pen test results etc. to various stakeholders in client organization (including developers, architects, compliance teams, CXOs etc.)
  • 4. Assist sales with business development effort across the APAC region

Associate Managing Consultant

Promoted

Nov 2015Jul 2016 · 8 mos

  • I work with Cigital's APAC clients (Financial, Technology, eCommerce etc.) to understand their Application Security needs and propose appropriate solutions.
  • In addition, I ensure the quality of deliverables reaching our clients is top-notch.
  • I specifically assist clients in the following areas:
  • Application Security Testing (web applications, mobile applications, thick clients)
  • Source code review, including static analysis using industry standard tools
  • Security design reviews
  • Building new and improving existing application security programs
  • Finally, I work with other leaders in Cigital Asia to grow our consultant pool. This includes assisting in recruitment, training new employees and mentoring our talented consultants.

Sr. Security Consultant

Feb 2015Nov 2015 · 9 mos

Senior Consultant

Aug 2013Jan 2015 · 1 yr 5 mos

  • Perform various kinds of software security assessments including Ethical Hacking, Source Code Review and Architecture Analysis
  • Assist clients in setting up various software security capabilities
  • Work with Developers to mitigate security vulnerabilities
  • Effectively communicate software security related information with various parts of the client organizations including business teams and upper management

Security Consultant

Promoted

Jan 2012Aug 2013 · 1 yr 7 mos

  • Perform various software security duties which help clients improve their application security posture
  • Performs Ethical Hacking, Static Code Analysis and develop Threat Models for software
  • Help clients develop risk mitigation strategies and implement them.

Associate Security Consultnat

Jun 2011Jan 2012 · 7 mos

  • Manual and Automated Static Code Analysis (J2EE)
  • Manual and Automated Dynamic Analysis (Penetration Testing)
  • Basic Threat Modeling

Null the open security community

Chapter Lead

Mar 2014Sep 2015 · 1 yr 6 mos · Bangalore

Comsys (client: finra)

Application Security Engineer

Jun 2010Jun 2011 · 1 yr

  • Certify various applications for compliance with the AppSec plan
  • Certification involved Web Vulnerability Assessment, Code Scanning, Data Sensitivity Analysis, Network and Firewall Analysis etc
  • Performance evaluation of various commercial Web Application Firewall solutions to suit needs of the organization
  • Developed and Support Risk Acceptance Proposal System (RAP). A Java-GWT based ticketing system
  • Helped different teams with their Application Security Plan. Involves defining various aspects of their security architecture and brainstorm solutions

Free world pulse

Intern - System Architecture

Jul 2009Sep 2009 · 2 mos

  • Setup Development and Production servers (Ubuntu) for the PCE tool.
  • Designed the backup and recovery mechanisms for PCE tool server.

George washington university

Web and Software Developer

Sep 2008Sep 2009 · 1 yr

  • Migrated servers of GWU Wiki and Gelman blogs. These websites run on servers with LAMP (Linux, Apache, MySQL, PHP) architecture
  • Maintained GWOmeka and Gelman Library servers.

Cognizant technology solutions, bangalore, india

Programmer Analyst Trainee

Sep 2007Jul 2008 · 10 mos

  • Developed EET (Error Export Tool), a Java/J2EE tool to retrieve files from a remote database and present it in XML format
  • EET Improved response time to client queries by over 30%
  • Deployed applications on to the UNIX server using the TIBCO Admin tool
  • Coordinated with multiple teams spread across the globe as part of the Production Support - Deployment team

Bharath electronics limited, bangalore, india

Internship, Central Development and Engineering division

Jan 2007Jun 2007 · 5 mos

  • - Developed a mechanism to detect un-authorized modifications to files using custom Hash algorithm based on MD5

Education

The Takshashila Institution

Graduate Course in Public Policy — Public Policy Analysis

Jan 2014Jan 2014

The George Washington University

MS — Computer Science

Jan 2008Jan 2009

Visvesvaraya Technological University

Bachelor of Engineering — Computer Scinece

Jan 2003Jan 2007

Sri Kumaran Children's Home

High School

Jan 1996Jan 2001

Stackforce found 100+ more professionals with Application Security & Computer Security

Explore similar profiles based on matching skills and experience