Neelu Tripathy

Co-Founder

Bengaluru, Karnataka, India12 yrs 9 mos experience
Highly Stable

Key Highlights

  • Expert in both offensive and defensive security strategies.
  • Keynote speaker at major cybersecurity conferences.
  • OSCP certified with extensive hands-on experience.
Stackforce AI infers this person is a Cybersecurity Architect with expertise in both offensive and defensive security strategies.

Contact

Skills

Core Skills

Technical ReviewsSecurity Architecture DesignPodcastingTraining & DevelopmentDevsecopsRisk ManagementPenetration Testing

Other Skills

Application SecurityArchitectural DesignBusiness DevelopmentCEHChange ManagementCloud-Native ArchitectureCode ReviewCommunicationComputer SecurityConsultingDesign ReviewF5 BigIPIPSIPSecInformation Security

About

As a seasoned Senior Security Architect at Adobe Systems and Product Security Thought Leader, I bring a unique dual perspective to the complex challenges of safeguarding digital innovation. My expertise spans both offensive and defensive security, allowing me to build robust, resilient application ecosystems by anticipating adversary tactics and proactively designing out vulnerabilities. My rich background includes leading large-scale security implementation programs, as exemplified during my tenure as Head of Security for Thoughtworks India. My focus has consistently been on "building security into" application lifecycles through timely threat identification, comprehensive vulnerability management, deep assessments, and fostering security capability with strategic automation. This is underpinned by extensive hands-on offensive security experience, honed across Vulnerability Assessments & Penetration Testing, Advanced Red Teaming, Social Engineering, Reconnaissance, Threat Modelling & Design Reviews of web applications & APIs, and Source Code Reviews. Beyond my direct contributions, I am deeply committed to advancing the cybersecurity community and sharing knowledge. I'm an OSCP-certified professional and a recognized voice on global stages, having served as a Primary Trainer at BlackHat (Basic Infrastructure Hacking - 2017), and as a Keynote Speaker at DevSecCon24 AMER. My insights have also been featured at prominent conferences including OWASP APAC 2022, Agile India 2022, ADDO 2022, c0c0n, rootconf, and BSidesDelhi. I've actively shaped community initiatives, organizing villages at DefCon (Recon 2017) and Nullcon (Social Engg. 2016-18), and conceptualizing the corporate security conference, SecConf for Thoughtworks (2021-22). My dedication extends to serving on the review boards for BlackHat Asia, BSides Singapore,Goa and NullCon India, Berlin. As a former chapter leader for Null Mumbai and Bengaluru, I remain actively involved with the Indian security community. Driven by a passion for continuous learning , I leverage my analytical skills to explore new frontiers in security innovation. I thrive on engaging with fellow security practitioners to exchange ideas and foster collaborative solutions. You can also catch my insights as the host of Breakpoint Security Podcast, the first technical security podcast from India. Do tune in!

Experience

4 yrs 10 mos

Network Intelligence (I) Pvt. Ltd.

Present

Black hat

Review Board Member, BlackHat Asia

Nov 2024Present · 1 yr 4 mos · Asia · Remote

  • Review Board Member, BlackHat Asia
Technical Reviews

Adobe

Senior Security Architect

Jan 2024Present · 2 yrs 2 mos · Bangalore Urban, Karnataka, India · On-site

  • In this role, I help design and architect custom, cutting-edge security solutions to safeguard the Adobe's products and infrastructure. Some of current responsibilities include:
  • Developing security architecture frameworks and standards.
  • Collaborating with cross-functional teams to integrate security into the product home grown development platforms.
  • Designing and implementing security controls for cloud-based environments.
  • Evaluating and recommending security technologies and design integrations for Adobe environments.
  • Leading security architecture reviews and providing guidance on security best practices.
  • Providing security expertise and guidance to stakeholders, including executives and engineering teams.
Security Architecture Design

Security bsides goa

BSidesGoa Review Board

Dec 2023Present · 2 yrs 3 mos · Remote

  • BSides Goa is a community-driven cybersecurity conference held annually in Goa, India, focusing on providing a platform for networking, knowledge sharing, and skill development in the field of information security. As a reviewer I evaluate submitted papers, ensuring the quality and relevance of content to the security community.
Technical Reviews

Self-employed

Product Security Consultant & Architect

May 2023Dec 2023 · 7 mos · Bengaluru, Karnataka, India · On-site

DevSecOpsProgram DevelopmentSecurity Architecture Design

Breakpoint-security-podcast

Podcast Host

Jan 2023Present · 3 yrs 2 mos · India

  • br3akp0int-'Exploring the depths of Defensive Security'. The defensive side of Security is a world in itself with teams achieving amazing feats that involve excellent engineering practices and smart optimisation for scale. This is not talked about enough in the industry. Join me in the br3akp0int podcast as we reflect on the methods and approaches these smart teams use to solve practical challenges in information security and innovate their way into the future.
  • Who is this meant for? : This podcast is for anyone in InfoSec willing to know more about advances in security techniques. This includes security researchers or professionals, product owners, compliance or cloud, AI/ML, threat intel, SecOps automation, Security Leaders, development teams, pentesters and security practitioners. https://breakpoint.buzzsprout.com/
PodcastingDevSecOpsInformation SecurityInterviewing

Thoughtworks

3 roles

Head of Security

Promoted

Jul 2022Dec 2022 · 5 mos

  • Security Programs
  • Security Champions Program:
  • Started the largest and foundational program to integrate the security mindset across product teams
  • Trained and created a networks of hundreds of sec champs
  • Implemented Effective security practices using the sec champ network
  • Secrets Management Program:
  • Started and ran the security automation program to manage secrets effectively across DevOps lifecycles for hundreds of projects India wide
  • Enabled & Implemented Secret Scanning/Secrets manager across pipelines
  • Tracked Secrets check-in and managed check-in prevention in most cases
  • Information Security:
  • Oversaw various other security functions such as Incident Response, risk management
  • Created procedures for security review of other internal support functions
  • Created processes for review and assessment for Thoughtworks' non-client products
  • Oversaw the development of internal security tools for vulnerability management
  • Security Demand Generation & Fulfillment
  • Kick-started business unit for security within TWI to meet external and internal demand for Security
  • Created and executed multiple security offerings around security assessments, Vulnerability Assessments and Penetration testing, mobile security, Threat Modelling, Source Code Reviews, cloud security, DevSecOps & trainings.
  • Created and grown the security team and catered to multiple short/long term engagements/year
Risk ManagementDevSecOpsProject ManagementProgram DevelopmentSecurity AutomationTraining & Development+9

Security Practice Lead

Promoted

Apr 2020Sep 2022 · 2 yrs 5 mos

  • Security Practices
  • Matured the existing security practices for secure delivery of products
  • Created multiple trainings and workshops for secure code handling, development practices and security automation(DevSecOps).
  • Grew and curated a large security community(of developers & security champions) within India
  • Started TW’s own security conference SecConf in 2021 and Youtube channel SEConnect
  • Threat Identification & Management
  • Established & regularized Threat identification through Iterative Agile Threat Modelling.
  • Established effective threat tracking & management for 73% of accounts India wide
  • Enhanced Threat Modelling frequency from adhoc to at least once a quarter or more for 39% of the accounts
  • Identified hundreds of threats across applications and helped resolved High/Critical threats for projects
Code ReviewWeb Application Architecture ReviewDevSecOpsSecurity AutomationTraining & DevelopmentSecure Coding+6

Principal Consultant

Feb 2019Mar 2020 · 1 yr 1 mo

  • Started working as AppSec Specialist for Thoughtworks India. Work involved assessing security for various projects and helping resolve security challenges across tech stacks, designs and business scenarios using manual and automated techniques.
DevSecOpsSecurity AutomationTraining & DevelopmentWeb Application SecuritySecurity Architecture Design

Bsides singapore

BSides Singapore Review Board

Apr 2022Present · 3 yrs 11 mos

  • BSides Singapore is an annual information security conference. It is a conference by the community for the community. As part of the Review board at BSidesSG, I like to identify and promote practical and advanced cyber security research through talks and workshops.

Cyseck

CySEK Marketplace: Panel of Experts

Nov 2020Feb 2024 · 3 yrs 3 mos · https://cs-coe.iisc.ac.in/marketplace-expert-panel/

  • Volunteering to share my experience to ensure students and professionals get exposed to the best in quality trainings available in the market. This initiative is driven in collaboration with IISc & Govt. of Karnataka.
Training & Development

Nullcon

Nullcon Review Board Member

Mar 2020Present · 6 yrs · https://nullcon.net/review-panel/neelu-tripathy

  • As part of the Review board at Nullcon(Asia's largest Security Conference), I am contributing to finding and promoting cutting edge research in information security. I like to bring forth the best and most impactful research from the awesome submissions we get at Nullcon.

Notsosecure

2 roles

Principal Consultant

Jul 2018Jan 2019 · 6 mos

  • For this period I was leading and structuring red teaming & external penetration testing engagements for these larger organizations. This involved not only conducting the testing involving hundreds(thousands) of applications/IPs but also structuring the engagement, ensuring coverage, motivating teams to find relevant entry points into the network, reporting and communicating with the team and client all through the engagements.
Penetration TestingRed TeamingNetwork SecurityApplication SecurityCommunication

Senior Security Consultant

May 2016Jun 2018 · 2 yrs 1 mo

  • Through this time I was actively involved in carrying out mass reconnaissance, red teaming, external penetration tensing for some of the larger organizations. This involved conducting engagements involving 100s of applications and thousands of IPs (very large network ranges) for the clients.
Penetration TestingRed TeamingReport WritingWeb Application Security

Institute of information security (iis)

Trainer

Jun 2011Jul 2011 · 1 mo · Mumbai Area, India

  • Conducted and supported trainings for Web Application Security courses at IIS.
Network SecurityTraining & DevelopmentInformation SecurityWeb Application Security

Tata consultancy services

Security Analyst

Jan 2008Sep 2011 · 3 yrs 8 mos

  • Conducted Vulnerability assessments and penetration tests for Network and web applications
  • Interacted with clients to process the engagement, find estimates and worked on proposals
  • Worked as a developer and tester for VC++, MATLAB platforms
Penetration TestingCode ReviewInformation SecurityVulnerability Assessment

Education

Kalinga University

B-Tech — Computer Sciences

Jan 2004Jan 2008

Stackforce found 100+ more professionals with Technical Reviews & Security Architecture Design

Explore similar profiles based on matching skills and experience