Saurabh Kumar

AI Researcher

Bengaluru, Karnataka, India4 yrs 11 mos experience

Key Highlights

  • Identified security vulnerabilities in major products.
  • Avid CTF competitor with a passion for security innovation.
  • Expertise in secure code review and client-side security.
Stackforce AI infers this person is a Cybersecurity expert with a focus on application security and vulnerability research.

Contact

Skills

Core Skills

Application SecurityCybersecurityWeb SecurityFuzz Testing

Other Skills

Security TestingCollaborationBug ValidationImpact AnalysisFuzzingPythonGitAcrobat JavaScript APIIDAWindbgTool DevelopmentUnit TestingSecurity Bug FixingDockerDjango

About

Saurabh is a Security Researcher II at Microsoft (Edge Browser) on the Vulnerability Research Team. A graduate of IIT Roorkee, he specializes in web-security, client-side security, secure code review, and development. Passionate about discovering security vulnerabilities, he has independently identified bugs in products such as Razor, LastPass, Dgraph, and Adobe. An avid CTF competitor and a quick learner, Saurabh consistently takes on challenging tasks to drive security innovation.

Experience

4 yrs 11 mos
Total Experience
2 yrs 9 mos
Average Tenure
2 yrs 2 mos
Current Experience

Microsoft

Security Researcher 2

Mar 2024Present · 2 yrs 2 mos · Hyderabad, Telangana, India · Hybrid

Nutanix

2 roles

Application Security Engineer, MTS-2

Promoted

Aug 2022Mar 2024 · 1 yr 7 mos

Application Security Engineer, MTS-1

Jun 2021Aug 2022 · 1 yr 2 mos

  • As part of Nutanix Product Security, SDL-team, i perform internal security testing for Nutanix Core and SaaS products.
  • Collaborating with the engineering team in fixing the security bugs.
  • Validating and analyzing the impact of reported security bugs from Hackerone and Customers.
Security TestingCollaborationBug ValidationImpact AnalysisApplication SecurityCybersecurity

Payatu

Security Researcher

May 2020Oct 2020 · 5 mos

  • As part of cloudfuzz team, worked on fuzzing software Adobe/Foxit.
  • Implemented python script which automate the generation of Dharma grammar for Acrobat JavaScript API and successfully integrated it on Cloudfuzz Virtual machines for fuzzing.
  • Analyzed some crashes to confirm if it's exploitable.
  • TechStack:Python, Dharma, Git, Acrobat JavaScript API’s, IDA, Windbg
FuzzingPythonGitAcrobat JavaScript APIIDAWindbg+2

Owasp foundation

Google Summer of Code 2019

May 2019Aug 2019 · 3 mos · India

  • Implemented custom tools for Defectdojo project like Cobalt, Openscap, Mozilla observatory, etc.
  • Written Unit-tests for scans like Nmap, Nikto, Checkmarx, etc.
  • found some security bugs in DefectDojo and fixed it.
  • Tech Stack: Git, Python, Docker, Django, MySQL
Tool DevelopmentUnit TestingSecurity Bug FixingGitPythonDocker+4

Education

Indian Institute of Technology, Roorkee

Bachelor of Technology - BTech

Jan 2017Jan 2021

Jawahar Navodaya Vidyalaya - JNV

Jan 2009Jan 2016

Stackforce found 100+ more professionals with Application Security & Cybersecurity

Explore similar profiles based on matching skills and experience