Raja Nagori

DevOps Engineer

Hyderabad, Telangana, India7 yrs 3 mos experience
Most Likely To Switch

Key Highlights

  • Leader of OWASP-Nightingale initiative.
  • Expert in containerized penetration testing workflows.
  • Active contributor to international security conferences.
Stackforce AI infers this person is a Cybersecurity expert specializing in application security and penetration testing.

Contact

Skills

Core Skills

Product SecurityThreat ModelingApplication SecurityPenetration Testing

Other Skills

Coding StandardsAmazon Web Services (AWS)semgrepdastZAPSASTGitlabfossaArchitectural ReviewPython (Programming Language)Open-Source SoftwaregithlabProblem SolvingJiraFastAPI

About

Raja Nagori Product Security Engineer at Splunk (a Cisco Company) Lead - Nightingale Raja Nagori is a Product Security Engineer at Splunk, a Cisco company, where he works at the intersection of security engineering and innovation. He is an active contributor to the OWASP community and currently leads OWASP-Nightingale, an open-source initiative focused on containerized penetration testing workflows. Under his leadership, Nightingale has been showcased and recognized at several international security conferences, including: • Black Hat Arsenal Asia (2022, 2023, 2024) • Black Hat Arsenal EU (2025) • OWASP Global AppSec EU 2022 • Docker Community Hands-On Event • Black Hat Arsenal MEA (Shortlisted in 2022 & 2023) • IWCON 2023 • c0c0n 2024 Raja’s professional interests span across: • Web and Network Penetration Testing • Android & iOS Application Security • Threat Modeling and Secure Architecture Reviews • Source Code Review (SAST) and Authenticated DAST • DevOps Security: Docker and Container Hardening • DevSecOps: CI/CD Pipeline Security Automation • Scripting and Process Automation (Shell & Python) • Linux and Windows System Hardening Driven by curiosity, Raja is passionate about understanding how and why systems behave the way they do and how they can be made more resilient. He strongly believes that knowledge grows when shared, and has delivered talks and workshops across OWASP chapters and security communities worldwide. Outside of cybersecurity, Raja finds rhythm and balance through music often playing guitar to indie tunes and exploring new roads on his bike.

Experience

7 yrs 3 mos
Total Experience
2 yrs 5 mos
Average Tenure
5 yrs 7 mos
Current Experience

Cisco

Security Engineer

Nov 2024Present · 1 yr 6 mos · Hyderabad, Telangana, India · Hybrid

Coding StandardsAmazon Web Services (AWS)Threat ModelingProduct Securitysemgrepdast+10

Splunk

Product Security Engineer

Oct 2023Present · 2 yrs 7 mos · Hyderabad, Telangana, India · Hybrid

  • Acquired by Cisco
  • Conduct threat modeling and serve as a point of contact to identify insecure design patterns and threats in Splunk's products.
  • Remediate vulnerabilities found through SAST, DAST, and SCA assessments.
  • Develop and own high complexity security automation tools, and CI/CD integration, which handles the trends of the vulnerabilities coming on the products.
  • Detailed analytical information using Splunk Dashboard to classify the vulnerabilities.
  • Working on security design discussions, threat assessments, propose and discuss solutions to security tools, CICD pipeline changes, and pen testing that are directly related to their area of focus.
  • Architected an end-to-end threat-modeling copilot that carries FastAPI retrieval services with a chat surface, enabling security teams to ingest ERDs, query scraped AWS guidance, and receive actionable CIA/AAA recommendations in real time.
JenkinsVulnerability AssessmentThreat Modelingsource codeGitCybersecurity+5

Fis

IT Security Analyst II

Nov 2021Oct 2023 · 1 yr 11 mos · Gurugram, Haryana, India · Remote

  • Conducted authenticated Dynamic Application Security Testing (DAST) using Burpsuite for target systems.
  • Performed Source Code Review with commercial tools like Checkmarx and Veracode.
  • Engaged with CI/CD pipelines to ensure secure software development practices.
  • Conducted Threat Modelling exercises to enhance system security.
Problem Solving

Synack red team

Synack RedTeam Member

Sep 2021Sep 2023 · 2 yrs

  • Accessing & Securing the applications.
Problem Solving

Tac security

Information Security Consultant

May 2021Oct 2021 · 5 mos · Chandigarh, India

  • Perform vulnerability assessment and penetration testing of Web Applications and Networks.
  • Static application security testing on sonarqube, checkmarx.
  • Perform research on new vulnerabilities, attack vectors, exploits, and tools
  • Vulnerability Assessment and Penetration Testing of the Mobile application on platform Android and iOS.
  • Reporting and Documentation of the Vulnerability reported.

Owasp® foundation

Project Lead

Oct 2020Present · 5 yrs 7 mos · India · Remote

Habilelabs private limited

2 roles

Security and Automation Engineer

Jan 2020May 2021 · 1 yr 4 mos · Rajasthan, India

  • Web Application VAPT
  • Securing linux server from internal and external attacks
  • Maintaining SAST integrated tools for In-house Application
  • Maintaining CI/CD Pipelines of the Application
  • Perform OS Hardening on Linux servers
  • Configure Docker Images on multiple ongoing platforms
Problem Solving

Software Engineer

Feb 2019Jan 2020 · 11 mos · Rajasthan, India

  • Maintaining CI/CD Pipelines of the Application
  • Perform OS Hardening on Linux servers
  • Configure Docker Images on multiple ongoing platforms
Problem Solving

Cyberops infosec llp

CyberOps InfoSec Expert | Trainee

May 2018Jun 2018 · 1 mo · Jaipur, Rajasthan, India

  • Learn about the major concept of Cyber Security
  • Perform various methodology for VA and PT

Iant (institute of advance network technology)

Trainee

Jun 2017Jun 2017 · 0 mo · Bikaner, Rajasthan, India

  • Did training in CCNA
  • Learn about many things related to cisco routers and switches.
  • Worked on IP subnetting
  • Configure Routers using Putty
  • Worked on creating LAN Cable of cross and straight type of LAN cable.

Education

Poornima Institute of Engineering & Technology

Bachelor of Technology - BTech — Computer Engineering

Jan 2015Jan 2019

Adrash High School

senior secondary — Computer Science

Jan 2014Jan 2015

Stackforce found 100+ more professionals with Product Security & Threat Modeling

Explore similar profiles based on matching skills and experience