Rohan Shetty

Software Engineer

Bengaluru, Karnataka, India4 yrs 6 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Led firm-wide vulnerability management program
  • Designed data scanner with high accuracy
  • Passionate about merging technology and sports
Stackforce AI infers this person is a Software Engineer specializing in security and application development within the SaaS industry.

Contact

Skills

Core Skills

Vulnerability ManagementDevsecopsSecurity Findings AggregationApplication RedesignWeb Application DevelopmentApi DevelopmentNginx Configuration Optimization

Other Skills

CI/CD Pipeline SetupCloud Services EvaluationData Scanner DevelopmentImage Scanning

About

I am a curious learner with an endless fascination for software and the intricate workings beneath the surface. My journey began at RVCE, Bangalore, where I graduated with a Bachelors Degree in Computer Science and Engineering. Today, I am proud to be a Senior Software Engineer at Arcesium, where I have built a reputation for delivering on expectations with precision and efficiency. Innovation drives me, and I aspire to create solutions that leave a lasting impact, making a difference that people recognize and appreciate. My passion for technology is matched only by my love for sports, particularly cricket. Having played the game all my life, I am immensely passionate about it. The idea of merging my two interests—technology and sports—excites me, and I would eagerly embrace any opportunity that allows me to work at this intersection. If you're looking for someone who is dedicated, innovative, and passionate both in and out of the office, feel free to connect with me.

Experience

Arcesium

4 roles

Senior Software Engineer

Aug 2023Present · 2 yrs 7 mos

  • Vulnerability Management
  • Led the firm-wide vulnerability management program in 2024, upgrading 50+ packages across 400+ applications, resolving 100+ CVEs and 5K+ findings, earning recognition from firm leaders for this impactful deliverable.
  • DevSecOps
  • Established the secret scanning process using GitLeaks, enabling application teams to integrate it into pipelines and local development workflows, aligned with the shift-left principle, and authored a runbook for triaging identified secrets.
Vulnerability ManagementDevSecOps

Software Engineer

Aug 2021Jul 2023 · 1 yr 11 mos

  • InfosecHub
  • Aggregated over 1M+ security findings across 650+ applications, integrating tools like dependency scan, DAST, SAST, and more. Features include advanced filtering, dashboards, and reporting, serving as the firm's central hub for vulnerability management and security compliance.
  • Owned the end-to-end redesign of the application, transitioning from a GraphQL-based prototype to a relational schema and RESTful APIs, improving API response times by 4X (from 4s to under 1s) to handle growing data volumes and evolving requirements.
  • DataFence
  • Designed and developed a data scanner to detect confidential information for the firm and its clients in egress data, scanning documents against 500K+ keywords and regex patterns with 80%+ accuracy.
  • Integrated the tool with Slack, Confluence, ZScaler, and Palo Alto, enabling it to process over 1M+ monthly alerts and reduce manual reviews by the security monitoring team to just a few hundred.
  • Played a key role in implementing data confidentiality policies and became the team’s SME for design reviews involving data security and protection.
  • Image Scanning
  • Implemented a periodic image scanning process for production environments using the Trivy scanner to detect and mitigate threats in container images.
Security Findings AggregationApplication RedesignData Scanner DevelopmentImage Scanning

Intern

Feb 2021Jul 2021 · 5 mos

  • InfosecHub
  • Designed, developed and owned a feature-rich web application for Arcesium, built from the ground up, consolidating application security findings into a centralized hub.
  • Built the APIs using Spring Boot with GraphQL, using Postgres as the data store with MyBatis as the persistence framework.
  • The records of security findings were ingested into the system using an event driven architecture enabled through SNS, SQS, and S3.
  • The application user interface was built using React with Zustand as the state management tool.
  • Setup the CI/CD pipelines by contributing to the configurations of GitLab and Kubernetes. Also setup application monitoring by configuring logs, metrics and alerts on Datadog and ELK.
Web Application DevelopmentAPI DevelopmentCI/CD Pipeline Setup

Summer Intern

May 2020Jul 2020 · 2 mos · Hyderabad, Telangana, India · Remote

  • Optimized the NGINX configuration change process by migrating the configuration templates from code to a data store. Evaluated Amazon DynamoDB and S3 for the use case. Saw a reduction in the need for deployments by 60% on historical release data.
NGINX Configuration OptimizationCloud Services Evaluation

Education

RV College Of Engineering

Bachelor's degree — Computer Science

Jan 2017Jan 2021

Stackforce found 100+ more professionals with Vulnerability Management & Devsecops

Explore similar profiles based on matching skills and experience