Rajat Moury

Founder

Bengaluru, Karnataka, India10 yrs experience
Most Likely To Switch

Key Highlights

  • Reduced security incident likelihood by 99% for Livspace teams.
  • Identified 100+ critical vulnerabilities across multiple environments.
  • Helped 20+ companies prepare for audits and IPO readiness.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in application and infrastructure security.

Contact

Skills

Core Skills

Security AssessmentRisk ManagementSecurity AuditsSecurity StrategyIncident ManagementApplication SecurityVulnerability ManagementDevopsInfrastructure ManagementWeb Application SecurityNetwork SecurityPenetration Testing

Other Skills

Cloud SecurityAccess ControlSecurity ReviewsLeadership AdvisoryBug Bounty ProgramsCompliance ReadinessInfrastructure SecurityIncident ResponseApplication Security TestingVulnerability IdentificationSecurity Process EstablishmentContainerizationKubernetesDockerTerraform

About

I didn’t enter cybersecurity through the traditional route. It started in school with GTA cheat codes. While most kids were just playing the game, I wanted to understand why the system behaved differently when you modified a file. That curiosity for “breaking things to understand them” slowly turned into a lifelong obsession. At IIT Guwahati, I explored security deeper. Not through lectures, but through labs, late nights and bug bounty hunting. Finding vulnerabilities in real systems taught me more about how software fails than any textbook could. Then I moved to the other side. At Zomato and Meesho, I worked on defending large-scale systems, securing infrastructure, and training teams to prevent social engineering attacks. Offence gave me instincts. Defence gave me structure. That mix is what eventually shaped Apni Sec. Today, we help companies strengthen their security maturity through: • Deep-dive security audits • Application & infra hardening • Compliance readiness • Hosting and managing bug bounty programs • Building organisation-wide security behaviour Our approach is simple: Internal teams secure what they can see. External researchers find what no one is looking at. Security isn’t a product. It’s a mindset companies build over time. I’m here to help CTOs, engineering leaders, and founders build that mindset and stay ahead of the threats they don’t see coming. Let's talk if you find a match -rajat.moury@apnisec.com

Experience

10 yrs
Total Experience
2 yrs
Average Tenure
2 yrs 6 mos
Current Experience

Apni sec

CEO & Founder

Oct 2023Present · 2 yrs 6 mos · Bengaluru, Karnataka, India

  • I help high-growth startups and scale-ups identify and fix real security risk before it turns into incidents, audits, or reputational damage.
  • 1) Key responsibilities
  • Work directly with founders, CTOs, and engineering leaders to assess security posture across cloud, application, and access layers
  • Design practical security programs that balance speed, developer experience, and risk reduction
  • Lead security assessments, threat modeling, and remediation planning for production systems
  • Act as an extension of in-house security teams for companies without dedicated security leadership
  • 2) Impact
  • Helped 20+ companies across Fintech, Ecommerce & Recruitech reduce critical security gaps before audits / launches / IPO readiness
  • Identified 100+ critical-severity vulnerabilities across CLOUD / APP / INFRA environments.
  • Reduced security incident likelihood by 99% for Livspace teams
  • Supported teams scaling from 10 → 100 engineers without slowing delivery
  • Focus areas: Application Security · Cloud Security · Access Control · Security Reviews · Leadership Advisory
Application SecurityCloud SecurityAccess ControlSecurity ReviewsLeadership AdvisorySecurity Assessment+1

Zomato

2 roles

Security Lead

Promoted

Nov 2022Oct 2023 · 11 mos

  • Led security initiatives for production systems supporting a large, high-traffic consumer platform operating under IPO-level scrutiny.
  • 1) What I worked on
  • Owned security strategy across application and infrastructure layers
  • Partnered with engineering teams to embed security into development workflows
  • Reviewed architecture changes, vendor integrations, and access patterns at scale
  • Acted as a point of escalation during security incidents and risk assessments
  • 2) Key contributions
  • Secured systems supporting 80Million MAU users
  • Led remediation of 50+ critical / high-risk vulnerabilities across Application/Infra
  • Introduced Processes/Systems/Automations that reduced recurring security issues
  • 3) What this taught me: How security expectations change when public scrutiny, audits, and scale collide.
Security StrategyApplication SecurityInfrastructure SecurityIncident Management

Security Engineer II

Dec 2020Nov 2022 · 1 yr 11 mos

  • Hands-on security engineering across application, infrastructure, and internal tooling.
  • 10 What I worked on
  • Conducted application security testing and code reviews
  • Identified vulnerabilities in APIs, backend services, and internal tools
  • Collaborated with engineers to fix issues without blocking releases
  • Supported incident response and post-mortem analysis
  • 2) Impact
  • Discovered and helped fix 100+ vulnerabilities, including Account Takeovers, PII Data leak.
  • Improved security coverage for SERVICE COUNT / AREA
  • Reduced repeat vulnerabilities by 70%
Application Security TestingVulnerability IdentificationIncident ResponseApplication SecurityVulnerability Management

Meesho

Security Engineer - II

Dec 2019Dec 2020 · 1 yr · Bengaluru, Karnataka, India

  • Early-stage security work during rapid product and team growth.
  • 1) What I worked on
  • Application security testing for fast-moving product teams
  • Identified gaps caused by rapid feature releases and architectural changes
  • Worked closely with developers to prioritize fixes under tight timelines
  • 2) Key contributions
  • Found 100+ security issues across [WEB / API / MOBILE] surfaces
  • Helped establish early security processes for a growing engineering org
  • Reduced risk in critical flows like PAYMENTS / AUTH / PII DATA
  • What this taught me: Why security breaks first when growth outpaces process.
Application Security TestingVulnerability IdentificationSecurity Process EstablishmentApplication SecurityRisk Management

Societe generale global solution centre

2 roles

Specialist SE - DevOps

Promoted

Oct 2018Nov 2019 · 1 yr 1 mo · Bengaluru, Karnataka, India

  • Part of ARChitecture team (SG|PaaS) with expertise on Enterprise Docker Engine, Kubernetes & Serverless solutions.
  • Architecture review and redesigning to migrate monolithic applications into microservices on PaaS platform keeping in mind the functionalities of application & infra cost saving.
  • Language stack includes Java springboot, Node Angular & React JS based applications.
  • Supporting & managing docker platform including UCP, Swarm cluster, docker engine, volumes, networks, HRM & registry.
  • Creating stack compose files & writing Dockerfiles to create images for application for resusability in order to deploy an application to Docker platform.
  • Securing the container deployment environment(s), container pipeline & infrastructure.
  • Writing pipeline script for application provisioning on different platform with CI-CD process, single-click deployment (Jenkins-git-sonarqube-maven-nexus-checkmark-docker).
  • Development, writing Unit & integration tests of Docker-Vault-Secret Plugin based on Go-Lang for secrets stored in the Vault server being invoked by our microservice.
  • Comprehensive deep dive study of Kubernetes Production-grade Container Orchestrator over Docker analyzing key parameters HA, Scalability, rolling updates & auto-rollbacks.
  • Development of serverless framework solution (node-JS) for SG|Lambda on-premise implementing FaaS (Function as a Service) & BaaS (Backend as a Service).
  • Designing and integration of Kubeless, Fn & OpenWhisk distributed serverless platform within private cloud that executes functions f(x) in response to events at any scale.
  • Public Cloud Building Trust & Control with Azure Kubernetes Services (aks cluster).
  • Automating public cloud transformation for onboarding application teams with ad-hoc pre-configured & ready-to-use aks cluster with help of Terraform Infrastructure as Code Technology.
  • Secured position in Top 5 in Cyber Security Brainwaves Hackathon organized by SocGen Globally.
DevOpsContainerizationKubernetesInfrastructure Management

Sr. Software Engineer

Jun 2017Sep 2018 · 1 yr 3 mos · Bengaluru, Karnataka, India

Owasp foundation

OWASP Hackademic Project

Jan 2016May 2017 · 1 yr 4 mos · Open Source

  • Development of Sandboxed CTF type challenges, Implementing Security of Web applications, Real world Vulnerabilities in safe and controllable environment, represented by the Mentor in the AppSec Conference 2016, Rome.
  • Making the Application platform-independent for better Deployment used Vagrant Boxes, Vagrantfiles and Docker containers for challenges and the CMS.
  • Technologies Used : PHP CMS, Vagrant & Docker, WebApp Security.
Web Application SecurityVulnerability Management

University of mumbai

Summer Research Intern at VJTI, Mumbai

May 2015Jul 2015 · 2 mos · Mumbai Metropolitan Region

  • Security of Wireless Networks, security of AODV routing protocol of Wireless Sensor Networks (WSN) by mitigating Black Hole Attack by Implemting SRD-AODV and GAODV algorithms on Network Simulator EXata by running Live scenarios.
  • LAN Monitoring, Web filtering modification in Squid proxy server ACL and Pentesting to test Vulnerabilities on LAN, WLAN and Routers.
  • Technologies Used : C++, OOPs concepts, EXata, Wireshark, aircrack-ng, Nmap.
Wireless Network SecurityPenetration TestingNetwork Security

Education

Indian Institute of Technology, Guwahati

Bachelor of Technology (B.Tech.) — Electrical and Electronics Engineering

Jan 2013Jan 2017

Stackforce found 100+ more professionals with Security Assessment & Risk Management

Explore similar profiles based on matching skills and experience