Mohit Panwar

DevOps Engineer

Bengaluru, Karnataka, India10 yrs 11 mos experience

Key Highlights

  • Over 10 years of experience in Product Security.
  • Expertise in Application Security and Vulnerability Assessments.
  • Certified Ethical Hacker and Offensive Security Certified Professional.
Stackforce AI infers this person is a Product Security expert with a focus on Application Security in the Healthcare sector.

Contact

Skills

Core Skills

Product SecurityApplication Security

Other Skills

Static Source Code AnalysisDoD DISA RMF compliance assessmentsMcAfee Application ControlEncryption for Sensitive DataThreat and Gap AssessmentVulnerability AssessmentsPenetration TestingSecure Application Development LifecycleThreat ModellingC#JavaVBScriptOSCPSecure SDLCSecure Code Review

About

10+ Years’ Experience in Product Security Hello and thank you for taking time to go through my profile. I am a self-learner and passionate about Security Research and Application Security. Have training/hands-on on: Product Security | OSCP | CEH | Application Security | Web Security | Source Code Review | Threat Modelling | Secure SDLC implementation | HIPPA | NIST 800-53 | System Hardening | https://medium.com/@Shorty420 #Certified Ethical Hacker(C|EHv8) #Offensive Security Certified Professional (OSCP) #Certified Information Systems Security Professional (CISSP) and hope to acquire some more down the line... ________ # Research paper on Heartbleed Mitigation ________ As we all say, you learn it when you do it, I have been doing (and facilitating) Product Risk Assessment, Business Impact Analysis, Product Security Reports(PSIS/On-Premise Security Questionnaires etc.), driving security decisions/improvements, Threat Modelling, DoD-RMF and NIST 800-53 compliance assessments/documentation, maintaining Product Catalog security databases, developing Critical Security Controls, Security Defect fixes, Secure Static Code Review. I have been working very closely with Product Security Officer, Principal Security Architect, Product Managers, Philips Global Security Team for security deliverables. Individually worked on Extensive Penetration Testing, Developing various Dep-op/Infrastructural tools (Offline remote Microsoft Updates Identifier/downloader/installer and Secure Vault for Windows based on LSA Security), developing Web Sites. Hobbies: Exercising | Music | Movies | Creating Proof of Concept for Vulnerabilities | PentestLab | VulnHub | HackTheBox | Trying doing things that I don't know or I can't do. _________ I wish to see myself grow with knowledge each day and attain great heights in all my endeavours... Thanks :) Mail: "mohitpanwaraws@gmail.com"

Experience

Groww

Lead Application Security Engineer

Apr 2025Present · 11 mos · Bengaluru, Karnataka, India · On-site

Beckman coulter diagnostics

Lead Application Security Engineer II

May 2023Apr 2025 · 1 yr 11 mos · Bengaluru, Karnataka, India · Hybrid

Ge healthcare

Product Security Lead

Apr 2019May 2023 · 4 yrs 1 mo · bangalore

Philips

2 roles

Product Security Engineer

Jun 2015Dec 2018 · 3 yrs 6 mos · Bengaluru Area, India

  • ˗ Manual and HP Fortify tool based Static Source Code Analysis
  • ˗ DoD DISA RMF compliance assessments and documentation
  • ˗ McAfee Application Control implementation
  • ˗ McAfee Anti-Virus build and configuration
  • ˗ Implementing Encryption for Sensitive Data and Key management
  • ˗ Developing proof of concepts to introduce new security controls for CT/AMI products and exploits for Pen Testing.
  • ˗ Threat and Gap Assessment and Threat Modeling based on NIST, HIPPA and Global Philips Security Policies
  • ˗ Vulnerability Assessments, Penetration Testing for various Philips products and network
  • ˗ Security Risk Assessment Report for CT/AMI products
  • ˗ Implementing Secure Application Development Lifecycle for SAFE Agile products
  • ˗ Collaboration with project managers, program managers and stakeholders to develop effective implementation plans as per the project milestones for all security solutions
  • ˗ Security Test Design for Verification and Validation teams
  • ˗ Investigation of field security incidents
  • ˗ 3rd Party Patch Impact Assessment Template
  • ˗ Security Bug investigation and fixes
Static Source Code AnalysisDoD DISA RMF compliance assessmentsMcAfee Application ControlEncryption for Sensitive DataThreat and Gap AssessmentVulnerability Assessments+4

Software Intern

Jan 2015Jun 2015 · 5 mos · Bengaluru Area, India

  • ˗ DIACAP STIG Assessment of CT/AMI products based on DISA STIGs.
  • ˗ Developed System Component to improve DoD compliance ratio
  • ˗ Worked with GPOs, Registries and Administrative Tokens.
  • ˗ Implemented SSH server.
  • ˗ Software Signing with Digital Certificates.
  • ˗ Assessed 3rd party tools for open vulnerabilities.

Education

Vellore Institute of Technology

Bachelor of Technology (BTech) — Information Technology

Jan 2011Jan 2015

ASTER PUBLIC SCHOOL

Senior high — Mathematics and Computer Science

Jan 2008Jan 2010

Stackforce found 100+ more professionals with Product Security & Application Security

Explore similar profiles based on matching skills and experience