Kumar Ashwin

Director of Engineering

Bengaluru, Karnataka, India4 yrs 11 mos experience
Most Likely To Switch

Key Highlights

  • Expert in both offensive and defensive security.
  • Developed innovative security solutions and gamification platforms.
  • Strong background in cloud and application security.
Stackforce AI infers this person is a Cybersecurity expert with a focus on DevSecOps and application security.

Contact

Skills

Core Skills

Security EngineeringSupply Chain SecurityDevsecopsProject ManagementApplication SecurityPenetration Testing

Other Skills

Adobe IllustratorAutomationBashBootstrapC (Programming Language)Cascading Style Sheets (CSS)Cloud SecurityCommunicationEntrepreneurshipGitGo (Programming Language)Graphic DesignJavaScriptLeadershipMySQL

About

Hey there šŸ‘‹ Thanks for stopping by! TL;DR about me - Security Engineer, Hacker, Speaker, Trainer, Snooker Enthusiast, etc. etc. šŸ˜‰ I’m Ashwin, and I’m passionate about security—that’s my field of work. love tackling challenging problems that need solving. I’m naturally curious and either ask tons of questions or secretly research things I don’t know about. I started out as a hacker and offensive security guy, and now I've transitioned to defensive security, bringing a unique perspective to the table. I still hack different targets for fun or to learn new attacks, and I create labs or CTFs for others to hack on. Speaking of that, I love creating and automating things, especially if I have to do them more than 2-3 times (yes, I’m lazy like that). Most of my work involves creating solutions, implementing security controls in software supply chains, cloud security, web security, and researching these areas. I’ve spoken at multiple conferences and trained at Blackhat, nullcon, x33fcon, etc. There’s a lot more on my website (kumarashwin.com), so check it out if you want to know more. Feel free to hit me up on LinkedIn—I’m happy to connect!

Experience

Redhunt labs

Technical Manager, Research & Consulting

Nov 2024 – Present Ā· 1 yr 4 mos Ā· London Area, United Kingdom Ā· Remote

Tide

Senior Security Engineer

Nov 2023 – Nov 2024 Ā· 1 yr Ā· Remote

  • Working alongside engineering teams to promote shift-left culture and improve company’s security posture.
  • Conducted architecture reviews and threat modeling to proactively implement security best practices.
  • Developed and launched ā€Hourglass,ā€ a security gamification platform at Tide to reward positive security behavior, encouraging proactive issue reporting and reducing potential security risks.
  • Worked with the cloud engineering team to incorporate security in the AWS infrastructure.
  • Developed detections using logs from SaaS products like Okta and Google Workspaces with SIEM & SOAR, focusing on PCI, PII, and DLP compliance.
  • Performed automated code reviews by creating custom DAST rules in Semgrep to enforce security practices, complemented by manual code reviews for thorough coverage.
  • Implemented data security by analyzing lineage, reviewing tool config., and managing controls and classification.
  • Detected and resolved misconfigurations in CI/CD pipelines, collaborating with teams to enhance security and mitigate supply chain risks.
  • Automated the metrics collection from various sources to generate actionable security insights and informed decision-making.
Security EngineeringSupply Chain SecurityAutomation

Deepsource

Security Engineer

Feb 2023 – Sep 2023 Ā· 7 mos Ā· Bengaluru, Karnataka, India Ā· On-site

  • Implement and enforce security practices throughout the entire organization.
  • Implemented security tooling such as Trivy, Trufflehog, and others, and ensured the integration of GitHub security features into the DevOps pipeline. Collaborated cross-functionally to drive widespread adoption of these security measures.
  • Research on different exploits reported by tool to determine it’s impact and exploitability using frameworks like EPSS.
  • Conducted penetration tests on feature releases and managed annual third-party security assessments to ensure software security and compliance.
  • Implemented a centralized vulnerability management solution to efficiently manage and triage security issues reported by tools like Trivy and ScoutSuite-powered makeshift CSPM.
  • Conducted routine access audits, enforced the least privilege principle, restricted access to sensitive components and data to only when necessary, and maintained comprehensive access logs for these instances.
  • Played a pivotal role in working towards attaining SOC2 and ISO27001 compliance certifications, demonstrating a commitment to industry- leading security standards.
  • Used Terraform for automated resource provisioning via pull requests, enhancing security and consistency while reducing operational risks.
  • Actively led the codebase and GitHub organization migration process, including restructuring and access control, to ensure a secure and organized transition.
  • Collaborated on enhancing deployment security with ArgoCD, optimizing the management of GitOps-driven infrastructure and ensuring secure, automated deployments.
  • Efficiently triaged reports from our open bug bounty program, prioritizing and addressing security vulnerabilities to enhance overall system resilience.
  • Conducted phishing drills to educate and raise awareness among team members about security threats and phishing attack vigilance.
Security EngineeringDevSecOpsProduct SecurityCloud SecurityPlatform Security

Payatu

3 roles

Security Consultant - Program Manager

Apr 2022 – Feb 2023 Ā· 10 mos

  • Managed entire delivery process of all the projects in the company ensuring the quality of work is being delivered to the customer.
  • Coordinating with different departments like HR, Marketing, Finance to get the best for the consultants and customers.
Project ManagementCommunicationService DeliveryPeople Management

Security Consultant

Promoted

Jul 2021 – Apr 2022 Ā· 9 mos

  • Performed penetration testing on a wide range of web technologies to identify critical vulnerabilities affecting the business.
  • Experienced in working with automated and manual penetration testing methodology to deliver quality results.
  • Performed cloud configuration review and penetration testing to find critical misconfiguration in the client’s infrastructure.
  • Automated workflows, created DevSecOps pipelines and performed penetration testing on CI/CD pipelines to find vulnerabilities.
  • Worked on in-house open-source projects like https://securecode.wiki and https://cybersecwiki.com to contribute to the infosec community.
  • Hosted and managed Payatu Hiring CTF, contributed to creating challenges, hosting and maintaining infrastructure, moderating Discord, etc. post that taking interviews of the top candidates to hire them.
Application SecuritySecurity ConsultingPenetration TestingCloud Security

Security Consultant

Jan 2021 – Jun 2021 Ā· 5 mos

Revmeup

Back End Developer

May 2020 – Aug 2020 Ā· 3 mos Ā· Bengaluru, Karnataka, India

  • Worked with NodeJS, Firebase and MongoDB and basic front end web development to
  • develop an admin panel to monitor and manage data and requests from the mobile
  • application.

Symbiosis international university

Developer

Dec 2019 – May 2020 Ā· 5 mos Ā· Pune

  • Working in NAAC accredition project for Symbiosis in which I developed automation tools using Python and Shell Scripting that helped in data cleaning, data migration and data integration.

Education

Symbiosis Institute of Computer Studies and Research

Bachelors — Computer Science

Jan 2018 – Jan 2021

Stackforce found 100+ more professionals with Security Engineering & Supply Chain Security

Explore similar profiles based on matching skills and experience