Gaurav Arora

Engineering Manager

Bengaluru, Karnataka, India14 yrs 4 mos experience
Most Likely To Switch

Key Highlights

  • Architected security infrastructure for a leading quick commerce startup.
  • Established high-performing security functions at multiple companies.
  • Active contributor to the cybersecurity community through open-source projects.
Stackforce AI infers this person is a Cybersecurity Expert specializing in Fintech and SaaS security solutions.

Contact

Skills

Core Skills

Product SecurityCloud SecurityDevsecopsSecurity Team DevelopmentSecure SdlcIncident ResponseMobile SecurityNetwork Security

Other Skills

AkamaiAmazon Web Services (AWS)Application SecurityCI/CDCSPMCTFChange ManagementCloud InfrastructureCloudflareCode ReviewCommunicationCyber-securityCybersecurity Incident ResponseDocumentationEthical Hacking

About

Engineering Manager for Cybersecurity at Zepto, architecting the security infrastructure for India's fastest-growing quick commerce startup. With 10+ years of progressive experience across the security landscape, I've established myself as a strategic cybersecurity expert specializing in:- Security Architecture; Zero-Trust Implementation- Cloud-Native; Container Security Solutions- DevSecOps Integration, Security Automation- Platform Engineering, Threat Intelligence- Security Team Development, Leadership. I've successfully established and scaled high-performing security functions from the ground up three times at Zepto, Slice, and SpiceMoney. My approach combines technical excellence with business alignment, delivering measurable security improvements while enabling rapid growth. Active contributor to the security community through open-source projects and sharing insights at conferences including Nullcon and BSides. Always eager to connect with fellow security professionals to discuss emerging threats, defense strategies, and security leadership challenges. Let's collaborate to build resilient security foundations that enable business innovation and growth.

Experience

Zepto

2 roles

Engineering Manager

Promoted

Oct 2024Present · 1 yr 5 mos · Bengaluru, Karnataka, India · On-site

  • Everything Security

Lead Security Engineer

Feb 2024Dec 2024 · 10 mos · Bengaluru, Karnataka, India · On-site

  • Everything Security
Product Security

Slice

Lead Security Engineer

Apr 2022Feb 2024 · 1 yr 10 mos · Bengaluru, Karnataka, India · On-site

  • Improved overall platform security by implementing best practices for mobile application, gateway and cloud infra.
  • Implemented various security automation in application and cloud.
  • API Visbility, Discovery, Monitoring and Security.
  • Built a security team from the ground up.
  • Security awareness sessions for the developers.
  • Organized CTF(capture the flag) events for improving security skills and awareness among developers.
  • Automated revalidation/regression of security issues.
  • Attack surface reduction and continuous monitoring.
  • Cloud security posture management(CSPM)
  • Security hardening and continuous audits/monitoring of cloud accounts
  • IT Infrastructure security
VAPTAmazon Web Services (AWS)Mobile SecurityCybersecurity Incident ResponseSCAProduct Security+22

Boutiqaat

Senior Security Engineer

Jun 2021Apr 2022 · 10 mos · Gurugram, Haryana, India · On-site

  • DevSecOps, AWS Security, WAF, Security Hardening, Patching, Security Automation
  • Security hardening of cloud and SaaS applications.
  • Web and mobile application pentesting.
  • Incident handling and monitoring using WAF(Cloudflare).
  • Security injection in the release process.
  • DevSecOps, Security integration in CI/CD pipeline(Gitlab, Jenkins)
  • SAST and Software composition analysis (SCA) - Sonarqube, OWASP Dependency Check
  • Implemented Forcepoint DLP
  • Application Security in Microservices architecture
Cybersecurity Incident ResponseProduct SecurityCloud SecurityApplication SecurityProblem SolvingIncident Response+16

Spice money

3 roles

Senior Security Engineer

Promoted

Nov 2019Jun 2021 · 1 yr 7 mos

  • Secure SDLC | Solutioning | Penetration Testing | Vulnerability management| Brand abuse prevention
  • Security awareness/Secure coding training to employees
  • Web, Mobile, Network, cloud (AWS), Source code review
  • Tech compliances
  • Security Hardening of entire on-prem and cloud infra
  • Akamai Web Application Protector to set
  • up policies and tweaking/creating WAF/WAP policies to protect against popular cyber attacks
  • Automated the entire change management process using Jira and Ansible
  • Brand Abuse Protection, Incident Response, Threat Monitoring
Mobile SecurityCybersecurity Incident ResponseSecure SDLCProduct SecurityCloud SecurityApplication Security+19

Security Engineer

Promoted

May 2018Nov 2019 · 1 yr 6 mos

  • Pentested various product dimensions like Ecommerce, Travel, Prepaid cards, Wallets, DMT, BBPS, AEPS, Loans, etc.
  • Set up Secure SDLC processes twice
  • Security Training for developers
Cybersecurity Incident ResponseSecure SDLCProduct SecurityApplication SecurityProblem SolvingIncident Response+11

Security Analyst

Mar 2017May 2018 · 1 yr 2 mos

Mobile SecurityCybersecurity Incident ResponseProduct SecurityApplication SecurityProblem SolvingIncident Response+8

Cyberaon technologies

Penetration Tester

Nov 2015Feb 2017 · 1 yr 3 mos · Vishakhapatnam, Andhra Pradesh, India · Remote

  • Penetration testing of CMS based websites, wordpress, joomla, drupal, etc.
  • Network penetration testing
  • Blackbox penetration testing
  • Linux Hardening
  • Scripting
Network SecurityWeb Application Security

We excel

Data Entry

Oct 2014Oct 2015 · 1 yr · Chandigarh, India · On-site

Freelance

Cybersecurity Enthusiast

Nov 2011Nov 2015 · 4 yrs

  • learned hacking and cybersecurity fundamentals
  • did a bunch of freelance projects
  • pwned a bunch of servers for fun

Education

Kurukshetra University

Bachelor of Technology - BTech — Electronics and Communications Engineering

Aug 2010Aug 2014

Stackforce found 100+ more professionals with Product Security & Cloud Security

Explore similar profiles based on matching skills and experience