Vaibhav Singhal

Product Engineer

United States14 yrs 1 mo experience
Most Likely To SwitchAI ML Practitioner

Key Highlights

  • Over 14 years of experience in cybersecurity.
  • Expert in vulnerability research and threat detection.
  • Proven leadership in managing cross-functional teams.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in vulnerability research and application security.

Contact

Skills

Core Skills

Cloud ComputingCyber-securityResearch Skills

Other Skills

Team ManagementSoftware DevelopmentProduct ServiceAnalyticsProduct DevelopmentLeadershipTransport Layer Security (TLS)Engineering ManagementSoftware Development Life Cycle (SDLC)Problem SolvingSkill DevelopmentArtificial Intelligence (AI)BOTNext-Gen Web Application FirewallPenetration Testing

About

Results-driven security professional with over 14+ years of experience in vulnerability research, secure systems development, and technical leadership. Proven expertise in managing cross-functional teams and overseeing multiple high-impact projects simultaneously. Cloudflare's Official Blog - https://blog.cloudflare.com/author/vaibhav/

Experience

14 yrs 1 mo
Total Experience
2 yrs 4 mos
Average Tenure
4 yrs
Current Experience

Cloudflare

Lead Security Researcher

May 2022Present · 4 yrs · United States · Hybrid

  • Lead research on AI training bots, develop advanced detection methodologies, and author technical blogs to share insights with the broader security community.
  • Conduct offensive security assessments and penetration testing of Cloudflare’s Application Security stack—including WAF and Bot Management—while managing and fine-tuning detection rulesets such as Managed Rules, OWASP Core Rules, custom signatures, and Bot Management heuristics.
  • Reverse-engineer n-day exploits and emerging vulnerabilities; analyze large-scale bot and fraud attack patterns to detect and mitigate billions of malicious requests daily.
  • Perform secure code reviews, architecture assessments, and threat modeling to proactively identify and remediate risks across WAF product surfaces.
Team ManagementSoftware DevelopmentProduct ServiceAnalyticsCloud ComputingResearch Skills+11

Palo alto networks

Principal Security Researcher

May 2016Apr 2022 · 5 yrs 11 mos · San Francisco Bay Area

  • Managed a wide range of security projects encompassing SCADA/ICS, IT/OT, IoT research, threat hunting, malware analysis, reverse engineering, and penetration testing using tools such as Metasploit, Cobalt Strike, Core Impact, and BreakingPoint.
  • Served as a key liaison between project management, engineering, and QA teams to ensure seamless coordination and successful delivery of security initiatives.
  • Conducted research and developed detection signatures for Palo Alto Networks products, focusing on vulnerabilities in IoT devices, SCADA systems, medical equipment, Microsoft/Adobe Patch Tuesday updates, and third-party software.
  • Collaborated closely with third-party testing vendors specializing in NGFW, NGIPS, and DCNS to improve threat detection coverage and vulnerability mitigation.
  • Designed and implemented automation frameworks for honeypot data correlation, signature development, and regression testing to streamline security operations and enhance detection accuracy.
MetasploitCyber-securitySoftware DevelopmentProduct ServiceCloud ComputingResearch Skills+5

Qualys

Senior Vulnerability Signature Engineer

Mar 2015Apr 2016 · 1 yr 1 mo · Redwood City

  • Conducted in-depth vulnerability research focused on Microsoft MAPP Patch Tuesday, Adobe Patch Tuesday, Oracle Patch Tuesday, zero-day exploits, databases, operating systems, and third-party applications.
  • Developed a web-based tool to monitor daily signature coverage, enabling effective tracking of false positives and false negatives.
  • Created automation tools to streamline deployment of builds, packages, and binaries across large-scale infrastructure environments.
  • Managed the publication of daily security content releases and builds to ensure timely and reliable delivery to customers.
MetasploitSQLCyber-securitySoftware DevelopmentNeXposeTenable Nessus+5

Corero

Security Research Engineer

Aug 2012Feb 2015 · 2 yrs 6 mos

  • Researched and developed IPS signatures targeting vulnerabilities from Microsoft MAPP Patch Tuesday, Adobe Patch Tuesday, Core Impact, Metasploit, Canvas, and OSINT sources as a key contributor to the Corero Active Response Team.
  • Managed the full security content lifecycle, including research, development, automation, testing, and comprehensive documentation.
  • Analyzed and implemented effective countermeasures against security threats such as buffer overflows, integer overflows, SQL injection, XSS, CSRF, and other OWASP Top 10 vulnerabilities.
  • Conducted research on DDoS mitigation algorithms and developed a performance monitoring tool leveraging Splunk and big data analytics.
  • Addressed high-priority customer security escalations with rapid resolution and minimal turnaround time.
MetasploitSQLSoftware DevelopmentSoftware Development Life Cycle (SDLC)Problem SolvingCyber-security

Harvard university

Information Security Intern

Jan 2012Apr 2012 · 3 mos · Greater Boston Area

  • Conducted penetration testing leveraging tools such as Core Impact and Metasploit, and recommended remediation strategies for identified security vulnerabilities.
  • Developed and updated security policies and procedures for Harvard’s Server Operations Center during the Capstone project.
Software DevelopmentProblem Solving

Corero

Security Enginner Intern

Jun 2011Dec 2011 · 6 mos

  • Designed and implemented security GUI automation through Perl test scripts and comprehensive test suites.
  • Executed various security testing methodologies including blackbox, whitebox, smoke, regression, system-level, and performance testing of product signatures.
  • Identified defects and collaborated closely with the development team to resolve issues, enhancing overall product quality.
  • Assisted in the setup of lab infrastructure, including hardware, network, software, and building virtualization servers.
Software DevelopmentProblem Solving

Hcl career development center

Security Intern

Dec 2009Apr 2010 · 4 mos

  • Completed RedHat Linux Administration course, securely installing and configuring services including FTP, NFS, CIFS, DNS, and DHCP.
Software DevelopmentProblem Solving

Xoftoasis pvt ltd

Assistant Programmer Intern

May 2009Aug 2009 · 3 mos

  • Contributed to coding the Chat, Quiz, and Blog add-ons on www.vrindavandham.com.
  • Developed and debugged the full Chat box functionality, integrating video and audio features into the website.
Software DevelopmentProblem Solving

Education

Northeastern University

Masters — Information Assurance

Amity University

Bachelor of Technology — Computer Science & Engineering

Stackforce found 100+ more professionals with Cloud Computing & Cyber-security

Explore similar profiles based on matching skills and experience