Shantanu Kulkarni

CEO

United Kingdom7 yrs 10 mos experience
Most Likely To Switch

Key Highlights

  • Expert in offensive security and vulnerability management.
  • Led market expansion for a cutting-edge security platform.
  • Developed innovative security testing approaches aligned with industry standards.
Stackforce AI infers this person is a Cyber Security expert with a focus on offensive security and vulnerability management.

Contact

Skills

Core Skills

Offensive SecurityCyber Security SalesPenetration TestingVulnerability ManagementVulnerability AssessmentCyber SecurityAugmented Reality

Other Skills

CMOMarket ResearchSales ManagementStrategic Marketing ManagementSales OperationsBrand DevelopmentCustomer SuccessBusiness DevelopmentCommercial MarketingAnalytical SkillsDigital StrategyCustomer Relationship Management (CRM)SalesRisk AssessmentAttack Surface Management

About

I’m Shantanu Kulkarni, CMO at SecurityBoat. I work with CISOs, CTOs, and security leaders across Europe to help them identify real, exploitable security risks—before they turn into incidents. In many organizations, security testing is still treated as a periodic activity. It supports compliance, but often fails to reflect how modern attack surfaces evolve or how real attackers operate in production environments. At SecurityBoat, we are building a platform-led approach to offensive security. Our core offering is PTaaS (Penetration Testing as a Service)—a continuous, platform-driven model that enables teams to move beyond one-time assessments and adopt ongoing, structured security testing aligned with their development lifecycle. Alongside PTaaS, we provide: - Manual Penetration Testing and Red Teaming for deep, attacker-driven assessments - A Bug Bounty platform to manage vulnerability disclosure programs (both private and public), helping organizations engage with security researchers in a controlled and effective manner - Secure Code Reviews to identify issues early in the development cycle We are also developing our Attack Surface Management (ASM) platform, currently in beta, designed to give organizations better visibility into their external exposure and continuously evolving attack surface. The focus across all of this is consistent: identify what is truly exploitable, help teams prioritize effectively, and reduce real-world risk—not just theoretical vulnerabilities. As we expand across Europe, we understand that expectations around security, resilience, and accountability are significantly higher. Frameworks like NIS2 and DORA are pushing organizations to go beyond compliance and demonstrate actual security maturity. Our role fits alongside this by providing real-world validation of security posture through continuous and attacker-focused testing. In my role, I lead growth, sales, and market expansion at SecurityBoat. I work closely with both technical and business stakeholders to ensure security is understood in terms of risk, impact, and decision-making—not just reports and findings. If you're building or scaling in Europe and want a more continuous, realistic approach to penetration testing and vulnerability management, I’m open to connecting. shantanu.kulkarni@securityboat.net +91 9175154300

Experience

7 yrs 10 mos
Total Experience
1 yr 4 mos
Average Tenure
2 yrs 7 mos
Current Experience

Revgenius

Member

Nov 2025Present · 5 mos · Remote

Securityboat

Chief Marketing Officer

Sep 2023Present · 2 yrs 7 mos · India · On-site

  • At SecurityBoat, I lead growth, sales, and market expansion for a platform-led offensive security company focused on helping organizations identify and reduce real-world security risk.
  • We are building a continuous security testing approach through PTaaS (Penetration Testing as a Service), enabling teams to move beyond one-time assessments and adopt structured, ongoing security validation aligned with modern development cycles.
  • Alongside PTaaS, our work includes deep, attacker-driven penetration testing and red teaming engagements across web, API, cloud, and product environments—focused on identifying vulnerabilities that are truly exploitable in real-world scenarios.
  • We also offer a Bug Bounty platform to help organizations design and manage vulnerability disclosure programs (both private and public), allowing them to engage with security researchers in a controlled and scalable manner.
  • In parallel, we are developing our Attack Surface Management (ASM) platform (currently in beta), focused on providing continuous visibility into externally exposed assets and evolving attack surfaces.
  • Across all engagements, the focus remains consistent:
  • Identify exploitable vulnerabilities in live environments
  • Help teams prioritize and remediate effectively
  • Align security testing with engineering workflows and SDLC practices
  • As part of my role, I work closely with founders, CISOs, and engineering leaders—particularly across Europe—to position offensive security as a continuous, risk-focused function rather than a periodic compliance activity.
  • I also lead GTM strategy, sales enablement, and market expansion, ensuring that our approach to security is communicated in terms of business risk, impact, and decision-making.
Cyber Security SalesCMOMarket ResearchSales ManagementStrategic Marketing ManagementSales Operations+9

Tsys

Senior Product Security Engineer

Jul 2022Sep 2023 · 1 yr 2 mos · Hybrid

  • 🔍 Conduct VAPT and SAT: Perform comprehensive Vulnerability Assessment and Penetration Testing (VAPT) to identify and address security weaknesses in applications, systems, and networks. Conduct Security Assessment and Testing (SAT) to evaluate the effectiveness of security controls.
  • 🛠️ Implement SCA and DAST: Utilize Software Composition Analysis (SCA) tools to identify and manage open-source components and their associated security risks. Conduct Dynamic Application Security Testing (DAST) to assess web applications for vulnerabilities during runtime.
  • 🛡️ Risk Management: Evaluate potential security risks and threats to the organization's assets and infrastructure. Develop and implement risk mitigation strategies and security controls to reduce exposure to cyber threats.
  • 🔒 Vulnerability Management: Lead the Vulnerability Management program, which involves continuous monitoring, scanning, and analysis of systems and applications to identify vulnerabilities. Coordinate with stakeholders to prioritize and remediate vulnerabilities based on their criticality
Penetration TestingDASTVulnerability AssessmentThreat & Vulnerability ManagementSoftware Composition Analysis (SCA)SAST+1

Innowave it infrastructures limited

Tech Lead - Penetration Testing

Jun 2021Jul 2022 · 1 yr 1 mo · Pune, Maharashtra, India

  • 1. Conducts Vulnerability Assessments & Penetration Tests (VAPT) on client's IT infrastructure based on standard testing methodology using automated tools and manual testing.
  • 2. Develop and keep updating organization's Penetration testing checklist for Web, Mobile Apps and IT Infrastructure.
  • 3. Create comprehensive assessment report with details of identified vulnerabilities, analysis of the risks by assessment of potential impact and detailed recommendation for all the identified risks.
  • 4. Develop and execute plan for organization's CERT-In empanelment Process.
  • Tools: BurpSuite Pro, Metasploit, Acunetix, Fortify, Kali Linux, Nessus Professional, NMAP, Wireshark, HPing3 etc.
Penetration TestingNetwork VAPTWeb Application Security AssessmentMobile Application Security TestingCERT-In EmpanelmentVAPT+2

Avante consultants

Security Consultant

Jan 2020May 2021 · 1 yr 4 mos · Pune, Maharashtra, India

  • 1. Perform Vulnerability Assessment & Penetration Testing (VAPT) on Web and Mobile Applications according to OWASP Testing Guide.
  • 2. Perform Internal and External Network Vulnerability Assessment on client IT Infrastructures.
  • 3. Develop and keep updated internal vulnerability checklist for Penetration Testing and Vulnerability Assessment projects.
  • Tools: BurpSuite Pro, Metasploit, Acunetix, Kali Linux, Nessus Professional, NMAP, Wireshark, HPing3 etc.
Penetration TestingOWASP TOP 10VAPTVulnerability AssessmentWeb Application SecurityMobile application Security

Gtt

GNOC Analyst/Technician (Global Network Operation Centre)

Jan 2018Sep 2019 · 1 yr 8 mos · Pune

  • 1. Monitor GTT backbone network using various network FMS tool like IBM Netcool and Nagios.
  • 2. Troubleshoot the issue with various layer 2 devices like DSLAM, BPX, MGX, L2 switches and layer 3 network devices like core routers and switches.
  • 3. Work on configuration issue related to routing protocols like RIP, EIGRP, OSPF, BGP and network concepts like VLAN, VTP, HSRP, VRRP and GLBP.
Cyber SecurityEthical HackingVulnerability Management

Ocular systems

Project Intern

Jul 2016May 2017 · 10 mos · Pune ,Maharashtra

  • "Virtual Dressing Room" based on concept of augmented reality.
  • Using Unity 3D tool for UI design and Microsoft Kinect sensor for human body detection.

Education

Vidya Pratishthans College of Engineering, M.I.D.C.road, Baramati, Dist.Pune

Bachelor of Engineering (B.E.) — Computer Engineering

Jan 2012Jan 2017

CSSRL (acquired in 2020)

Post Graduate Diploma in Cyber Security (PGDCS)

Jun 2018Mar 2019

Stackforce found 100+ more professionals with Offensive Security & Cyber Security Sales

Explore similar profiles based on matching skills and experience