Pratham Mittal

DevOps Engineer

Sangrur, Punjab, India3 yrs 7 mos experience
Most Likely To Switch

Key Highlights

  • 3+ years of experience in Product Security.
  • Managed bug bounty programs for leading fintech companies.
  • Expert in Cloud Security and Application Security.
Stackforce AI infers this person is a Cybersecurity professional specializing in Application Security and Cloud Security within the Fintech sector.

Contact

Skills

Core Skills

Cloud SecurityApplication SecurityThreat ModellingPenetration Testing

Other Skills

AkamaiAnalytical SkillsApplication Security ArchitectureAutomationBurp SuiteBusiness LogicCloud Security (AWS)Computer NetworkingCybersecurityDASTDecision-MakingDesign ReviewEnglishGolangGoogle Dorking

About

A Software Security Engineer with 3+ years of full time experience in Product Security and additional 6 months+ internship experience as Security Consultant who loves to play CTFs, do bug hunting apart from my full time Security Engineer role to brush up my skills. Skills: 1) Pentesting & Vulnerability Assessment: Web / Network / API / Payment Gateway / Mobile pentesting. 2) Computer Fundamentals: Linux / Operating systems / DBMS / Computer Networking. 3) Computer Languages: HTML / JavaScript / PHP / Python / Bash / C (Good) / C++ / Java (beginner to moderate) 4) Secure Code Reviews: Source Code Review / Payment Gateway integration secure code reviews. (C++/Java/Python/Golang/C#) 5) Threat Modelling: Security Design Reviews / Tech Docs Reviews. 6) LLM Security: OpenAI LLM security (Threat modelling & pentesting) 7) Cloud Security (AWS): Reviewing all policies and security checks to make sure cloud infrastructure and services are secure and compliant with industry standards. 8) Training & Knowledge Sharing: Trained Interns and open to guide students who want to shift in cybersecurity. I love listening to songs, watching movies, exploring new places, Mathematics, solving Puzzles & Aptitudes as well. let's connect if you want to know more about what I do or my profile seems interesting or suitable to you.

Experience

Amazon

2 roles

Application Security Engineer - 2 (Asia/Pacific)

Promoted

Jul 2025Present · 8 mos

  • Cloud Security (AWS)
  • Secure Design & Architecture Reviews
  • Threat Modelling
  • Secure Code reviews
  • Automation stuffs
  • Worked on Multiple COEs
  • [Part of APAC Core Security Team - AppSTAR]
Cloud Security (AWS)Secure Design & Architecture ReviewsThreat ModellingSecure Code reviewsAutomationCloud Security+1

Application Security Engineer - 1 (Asia/Pacific)

May 2024Jun 2025 · 1 yr 1 mo

  • Cloud Security (AWS)
  • Secure Design & Architecture Reviews
  • Threat Modelling
  • Secure Code reviews
  • Automation stuffs
  • [Part of APAC Core Security Team - AppSTAR]
Cloud Security (AWS)Secure Design & Architecture ReviewsThreat ModellingSecure Code reviewsAutomationGolang+12

Razorpay

Product Security Engineer

Jul 2023Apr 2024 · 9 mos · Bengaluru, Karnataka, India · Hybrid

  • Responsible for handling the bug bounty program of Razorpay where I revalidate the reported vulnerabilities, get them fixed from developers and Responsible on deciding bounty structure as well to pay bug hunters accordingly.
  • Performing Threat modelling (also tech-spec reviews if applicable) and adhoc security testing on QA/dev stack environments before making APIs/functionalities live for end users.
  • Performing security assessments (SAST/DAST/manual) on all razorpay products & acquisitions (BillMe, Poshvine, ezetap etc.) to ensure security at each level (yes we automate things here to save time and not just depends upon tools)
  • Handling gateway security assessments (gateway pentests and code reviews) and making sure no gateway gets integrated without security assessment and each and every gateway is end-to-end secure.
  • [Razorpay is one of the largest payment gateways and top fintech company in India]
GolangApplication Security ArchitectureSecurity PolicyStatic AnalysisDesign ReviewSecurity Automation+8

Makemytrip

Security Engineer

Jun 2022Jul 2023 · 1 yr 1 mo · Gurugram, Haryana, India · On-site

  • Working in AppSec (Performing Pentests on all platforms i.e. Web/Android/Ios/PWA) and managing MMT/GI's bug bounty Program
  • Learning and working on Perimeter security of MMT & GI
  • Writing scripts to automate the things and strengthen the security at MMT.
  • Working with XVigil (AI based digital risk monitoring tool by Cloud_SEK) to monitor digital footprints for GI & MMT.
  • [MakeMyTrip is India's largest OTA!!]
Network SecurityWeb Application FirewallTenable NessusVAPTSecurity PolicyKali Linux+12

Synopsys inc

Security Consultant Intern

Jan 2022Jun 2022 · 5 mos · India (Remote)

  • Initially trained on DAST offering & Pentesting where I learnt about vulnerabilities not only limited to OWASP Top 10 through sessions conducted by mentors, senior members and online degreed platform and got hands on experience on the same by practicing on different pentesting platforms like Portswigger labs, Pentester academy, DVWA/Web Goat and other vulnerabilities specific websites.
  • Made my own locally hosted vulnerable web app using tech-stack (PHP, HTML, JavaScript & XAMPP web server) having almost all the vulnerabilities learnt during the internship and after successfully demonstrating my web app, I secured it thus making a complete secure web app which enhanced my Secure Coding knowledge.
  • Trained on beginner SAST offering where I leant about detecting vulnerabilities not only limited to OWASP Top 10 at an early stage of SDLC i.e. on source code level mainly in these languages (Java/C++, JavaScript, PHP, HTML and Python).
  • After all these learnings, I made a professional POC (Proof of Concept) report of OWASP Juice Shop web app (It is probably the most modern and sophisticated insecure web application by OWASP!) according to PT-E(Pentesting-Essential) checklist of company and submitted it as my demo project. At last I made a professional POC (Proof of Concept) report of Mobile IMS web app(It is specially designed by company employees as an internal testing web application) according to PT-S(Pentesting-Standard) checklist of company and submitted it as my final project.
  • [Synopsys is termed #1 in Electronic Design Automation Solutions & Services and is also leader in Application security]
Vulnerability ManagementSource code reviewPenetration TestingApplication SecurityKali LinuxBurp Suite+4

Haryana police

Gurugram Police Cyber Security Summer Intern 2021

Jun 2021Jul 2021 · 1 mo · India (Remote)

  • Learned about different types of attacks, Scams and IT Rules in Cyber world and took a pledge of Digitally Safe India.
  • Participated in CTFs and improved my Web and Networking Skills under the guidance of Rakshit Tandon sir.

Vieh group

2 roles

Cyber Security Team Lead Intern

Dec 2020Feb 2021 · 2 mos · India (Remote)

  • In the span of 2 months, I managed a team of 4 Interns named "VIEH Cyber Warriors" where we learnt many new approaches and techniques of web & network pentesting
  • Gave my interns some innovative tasks based on Web and Network pentesting, solved some public and self created CTFs and finally we made 2 Projects:
  • 1) Smart Key logger
  • 2) Chrome Password Extractor.
  • Overall My team (VIEH Cyber Warriors) enjoyed this Internship and learned some innovative and new things.

Cyber Security Analyst Intern

Oct 2020Dec 2020 · 2 mos · India (Remote)

  • In the span of these 2 months I got the opportunity to apply Pentesting skills (Web and Networking) by working on weekly tasks/assignments, conducting various Vulnerabilities specific sessions.
  • Got hands on experience experience of VAPT/WAPT by conducting VAPT/WAPT assessment on one of the internal subdomain of VIEH Group based on real world scenario and submitted professional POC report of the same at the end.
  • Learned about some new tools and expanded my knowledge on how to get started with creating/developing your own tools using scripting languages.
  • Overall it was a great and learning internship experience.

Cloudsek

cloudSEK XVigil Training

Aug 2020Aug 2020 · 0 mo · India

  • - Successfully completed the online task based on Threat Intelligence where a real world Dark Web scenario was created by Cloud_SEK team and participants were challenged to find flags (in form of different hashes) on the website by combining all the information available in that scenario.

Bugcrowd

Bug Hunter

Jul 2020May 2022 · 1 yr 10 mos · Remote · Remote

  • Found various bugs as freelance bug hunting during college days.
Penetration TestingApplication SecuritySecurity ManagementCybersecurity

Education

Thapar Institute of Engineering & Technology

Bachelor of Engineering - BE — Computer Engineering

Jan 2018Jan 2022

Himland Public School Dirba, Sangrur Punjab

XI & XII — Non Medical

Mar 2016May 2018

General Gurnam Singh Public school, Sangrur Punjab

I - X

Mar 2007Mar 2016

Stackforce found 100+ more professionals with Cloud Security & Application Security

Explore similar profiles based on matching skills and experience