Piyush K

Product Manager

Bengaluru, Karnataka, India7 yrs 5 mos experience
Highly Stable

Key Highlights

  • 5.5+ years in product security engineering.
  • Expert in vulnerability management and threat modeling.
  • Active bug bounty hunter and security blogger.
Stackforce AI infers this person is a Product Security Engineer specializing in Fintech and SaaS environments.

Contact

Skills

Core Skills

Application SecurityCloud SecurityThreat ModelingDevsecops

Other Skills

OWASPPenetration TestingDASTSASTBurp SuiteSecure SDLCSoftware Development Life Cycle (SDLC)Legal ComplianceIT AuditSecurity TestingWeb Application SecurityCloud ComputingAmazon Web Services (AWS)Microsoft AzureSystem Administration

About

As a Senior Product Security Engineer at Harness with 5.5+ years of experience, I specialize in vulnerability management, threat modeling, bug bounty programs, and penetration testing. My role involves collaborating closely with cross-functional engineering and security teams to proactively secure our products and infrastructure. With a focus on identifying and mitigating security risks, I am committed to building robust security frameworks and enhancing our overall security posture. My work ensures that Harness continues to provide secure, reliable solutions to our customers while staying ahead of emerging threats. In addition, I am a bug bounty hunter and a blogger, sharing my insights and tips on web application security to help others strengthen their security practices.

Experience

7 yrs 5 mos
Total Experience
2 yrs 8 mos
Average Tenure
2 yrs 1 mo
Current Experience

Harness

2 roles

Staff Product Security Engineer

Promoted

Dec 2025Present · 6 mos · Hybrid

Senior Product Security Engineer

May 2024Jan 2026 · 1 yr 8 mos · Hybrid

Application SecurityCloud Security

Ola

Product Security Engineer

Jan 2022May 2024 · 2 yrs 4 mos · Bengaluru, Karnataka, India · On-site

  • I specialize in ensuring web application security at OLA, covering areas such as Mobility, Electric, and Financial Services. Using Threat Modeling, DAST, and SAST, I identify and resolve vulnerabilities, collaborating closely with developers. I meticulously document findings, provide technical summaries, and manage Jira tickets for thorough reporting. I conduct retests to ensure closure of security risks across web, services, and mobile platforms. My role also involves addressing OWASP top 10, MITRE ATT&CK, and Business Logic Vulnerabilities, leveraging tools like Burp Suite. Additionally, I ensure compliance with GDPR, PCI-DSS, ISO 2001, and RBI Audits, safeguarding OLA's digital infrastructure and fostering customer trust.
OWASPPenetration TestingApplication SecurityThreat Modeling

Synopsys inc

3 roles

Security Services Associate Consultant

May 2021Jan 2022 · 8 mos

DevSecOpsPenetration Testing

Security Services Associate

Jun 2019Jan 2022 · 2 yrs 7 mos

DevSecOpsPenetration Testing

Cyber Security Intern

Jan 2019Jun 2019 · 5 mos

DevSecOpsPenetration Testing

Shah technical consusltants private limited

Network and System Administrator

Apr 2017May 2017 · 1 mo · Jaipur, Rajasthan, India

Education

Gujarat Forensic Sciences University

Msc — Digital Forensics and Information Security

Jan 2017Jan 2019

Poornima University

BCA (IT-IMS) — Cloud Computing

Jan 2014Jan 2017

Stackforce found 100+ more professionals with Application Security & Cloud Security

Explore similar profiles based on matching skills and experience