Swaroop Yermalkar

DevOps Engineer

Sydney, New South Wales, Australia10 yrs 4 mos experience
Highly Stable

Key Highlights

  • Over 500 successful penetration tests led globally.
  • Author of 'Learning iOS Penetration Testing'.
  • Top-rated pentester on Cobalt.io and HackerOne.
Stackforce AI infers this person is a Cybersecurity Specialist with extensive experience in mobile and application security.

Contact

Skills

Core Skills

Security ResearchPenetration TestingCyber-security

Other Skills

Team LeadershipCloud SecurityPython (Programming Language)Information TechnologyAmazon Web Services (AWS)Security AuditsProject ManagementOral CommunicationNode.jsWeb Application SecurityPresenting ProposalsProduct SecurityRelationship DevelopmentCloud ComputingIT Security Operations

About

Hey! I'm Swaroop Yermalkar, a cybersecurity professional with more than a decade of experience, currently based in Sydney. I started my cybersecurity journey right after finishing my engineering degree. Since then, I've worked in many different security roles - from Security Analyst and Security Engineer to Product Security Lead and Head of Red Teaming. I really enjoy helping technical teams and business leaders understand each other when it comes to security. I've worked at companies like ThriveDX, Philips Healthcare, Khoros, Traveloka, and Persistent Systems. Now I work as an independent security researcher and consultant, helping companies improve their security with solutions that actually work in the real world. I am the author of “Learning iOS Penetration Testing”, published by Packt (UK). The book teaches how to perform iOS application penetration testing, starting from the basics and moving to more advanced security techniques. It is designed to help security professionals, developers, and beginners understand how to test and secure iOS apps properly. I also lead the OWASP iGoat open-source project, which focuses on mobile security education. iGoat is a CTF-style iOS application that includes multiple hands-on challenges related to iOS penetration testing and security vulnerabilities. It is designed to make learning iOS security practical, interactive, and fun. I love sharing my research globally and have been fortunate to speak at conferences including Defcon (AppSec Village), AppSec USA (2017/2018), HITB, BruCON, SEC-T, and AppSec Israel (2018/2023), as well as HITCON, c0c0n, Bugcrowd LevelUp, KazHackStan, GroundZero, EuropeanSec, 0x90, and GNUnify. I have certifications like OSCP, OSCE, OSWP, and CREST. I'm also a top-rated pentester on platforms like Cobalt.io and HackerOne, having successfully led 500+ pentests for global companies, identified 1,000+ vulnerabilities, and managed global teams of up to 6 pentesters. I believe in always learning new things and helping others in the security community. Whether I'm mentoring people who are new to security, working on open source projects, or helping companies stay safe - I'm always happy to share what I know.

Experience

10 yrs 4 mos
Total Experience
2 yrs
Average Tenure
--
Current Experience

Corellium

Sr Security Researcher

Sep 2024Present · 1 yr 7 mos · Remote

  • Conduct in-depth research on the latest mobile security vulnerabilities, including platform-specific threats (iOS/Android) and emerging attack vectors.
  • Continuously integrate newly discovered vulnerabilities and exploit patterns into automated security scanners to enhance detection capabilities.
  • Perform large-scale assessments of hundreds of mobile applications to identify security flaws, misconfigurations, and privacy issues.
  • Analyze trends in mobile security threats to anticipate future attack surfaces and guide scanner improvements accordingly.
  • Improve the accuracy and coverage of MATRIX, Corellium’s automated vulnerability scanner, through meticulous validation, custom rule creation, and threat modeling.
Security ResearchPenetration Testing

Thrivedx

2 roles

Senior Cyber Security Researcher (AppSec)

Jan 2023Dec 2023 · 11 mos · Remote

  • Researching new cyber security attack vectors in cyber security.
  • Designing educational exercises to enhance developers' security knowledge for Kontra Application Security (https://application.security/).
  • Coding and developing these educational exercises for hands-on learning.
Oral CommunicationNode.jsPython (Programming Language)Security ResearchCyber-securityWeb Application Security+3

Red Team Security Researcher

Jan 2020Dec 2023 · 3 yrs 11 mos · Remote

Oral CommunicationRelationship DevelopmentPython (Programming Language)Cyber-securityCloud ComputingInformation Technology+4

Traveloka

Lead Security Engineer (Product Security Team)

Nov 2018Jan 2020 · 1 yr 2 mos

  • Headed and mentored a team of 7 security engineers.
  • Collaborated with cross-functional teams (development, operations, QA, etc.) to ensure product security.
  • Provided expert guidance in security architecture and design principles to engineering teams.
  • Provided training and mentorship to other engineers on security best practices, tools, and processes, reaching over 1,000 developers in Indonesia, Singapore, and India.
  • Developed secure coding guidelines and ensured products were built from the ground up with security in mind.
  • Led the identification, assessment, prioritization, and remediation of security vulnerabilities in products.
  • Oversaw penetration testing and security assessments, ensuring identified vulnerabilities were addressed in a timely manner.
  • Led the technical response during security incidents related to products, coordinating with other teams to mitigate threats.
Oral CommunicationPython (Programming Language)Security AutomationCyber-securityThreat ModelingInformation Technology+7

Khoros

Senior Security Engineer

Oct 2017Nov 2018 · 1 yr 1 mo · Bengaluru, Karnataka, India

  • Integrated solutions to detect and prevent security flaws in code and infrastructure.
  • Conducted thorough source code reviews to identify and address potential security vulnerabilities and flaws.
  • Assisted the pre-sales team by responding to security questionnaires and providing expert insights to prospective clients.
  • Managed and oversaw the bug bounty program, addressing reported vulnerabilities and coordinating with researchers.
  • Conducted vendor risk analyses to evaluate and ensure third-party services and products met the company's security standards.
  • Worked on cloud security measures, implementing best practices and tools to secure cloud infrastructure and applications.
Oral CommunicationCyber-securityInformation TechnologyRisk AnalysisPayment Card Industry Data Security Standard (PCI DSS)

Owasp foundation

OWASP iGoat Project Lead (Community Project)

Apr 2017Present · 9 yrs

  • Project details: https://igoatapp.com/
  • Adding the latest iOS vulnerabilities to iGoat
  • Coordinating with developers and security professionals from all over the world
  • Adding defense in depth for iGoat
  • Presenting iGoat in worldwide conferences
Python (Programming Language)Cyber-securityInformation TechnologyAmazon Web Services (AWS)Security AuditsProject Management

Cobalt

Pentest Lead

Sep 2016Present · 9 yrs 7 mos · Remote

  • Leading a global team to carry out penetration tests on different systems and technologies.
  • Performing security checks on web, network, mobile, API, and cloud platforms to identify and manage risks.
  • Acting as the primary point of contact for clients, managing expectations, and ensuring clear communication of pentest findings through comprehensive reports
Penetration TestingTeam LeadershipCloud Security

Philips health systems

Senior Software Engineer (Security)

Feb 2016Oct 2017 · 1 yr 8 mos · Bengaluru, Karnataka, India

  • Conducted web application security assessments to identify potential vulnerabilities and recommend mitigation strategies.
  • Performed security assessments on mobile applications across Android and iOS platforms, pinpointing weaknesses related to data leakage, insecure storage, and insecure communication.
  • Executed network security assessments, focusing on potential entry points, weak configurations, and outdated protocols.
Oral CommunicationCyber-securityInformation Technology

Synack red team

Security Researcher (freelancer)

Mar 2015Present · 11 yrs 1 mo

  • One of the top mobile security researcher worldwide
  • Reporting high severity and quality vulnerabilities
Oral CommunicationPython (Programming Language)Cyber-securityInformation TechnologyAmazon Web Services (AWS)Security Audits

Persistent systems

Domain Consultant (Cyber Security)

Jun 2013Dec 2015 · 2 yrs 6 mos · Pune/Pimpri-Chinchwad Area

  • Worked on RFPs to outline the scope of security engagements, detailing methodologies, deliverables, and timelines.
  • Assisted in the preparation of proposals, ensuring they met client requirements and complied with industry best practices.
  • Developed and integrated security automation tools to streamline vulnerability detection and reporting processes.
  • Worked with development teams to embed security checks within CI/CD pipelines, reducing manual effort and enhancing security coverage.
  • Assisted in incident response activities, collaborating with teams to contain and mitigate potential security breaches.
  • Conducted post-incident reviews to identify root causes and recommend preventive measures
Cyber-securityInformation Technology

Education

MIT College of Engineering Pune

Stackforce found 100+ more professionals with Security Research & Penetration Testing

Explore similar profiles based on matching skills and experience