Anvesh Y.

CTO

Bengaluru, Karnataka, India16 yrs 4 mos experience

Key Highlights

  • 16+ years of core security experience in diverse environments.
  • Expert in Cloud Security and Application Security frameworks.
  • Proven track record in managing secure development lifecycles.
Stackforce AI infers this person is a Cloud Security and Application Security expert in the Fintech industry.

Contact

Skills

Core Skills

Application SecuritySecurity AutomationVulnerability Management

Other Skills

AJAXAmazon Web Services (AWS)CC++CSRFCloud ComputingCloud SecurityCode ReviewCore JavaCybersecurityData StructuresEclipseEnd to End Product Security OwnershipGap AnalysisGoogle Apps Script

About

Around 16+ years of Core Security Experience securing Enterprise Digital Payments, Enterprise Mobile Device management, Enterprise Cloud Architecture. 1)Working on Cloud Security, AWS, GCP 2) Web/API & Infrastructure Security Assessments 3) Security Architecture Review- Threat Modelling 4) Scan Tool Automation into CI Pipeline-Jenkins 5) Secure Code Review, Developer Security Education 6) Crypto-Advisor, TLS/SSL, Digital Certificates 7) Experience building Key Management Infrastructure, worked on Thales HSM 8) Authentication/Authorization advisor 9) Securing Federated Architectures, SAML2.0 10) Remediation of OWASP Top 10 classes, CWE-25, XSS, XSRF,Command Injection, etc 11) Managing Secure Development Lifecycle across all products in the company 12) Pentesting as well as working with Pentesters. (Knowledge of Burp Suite) 13) Qualys/Nexpose API Automation 14) OWASP DependencyChecker Automation 15) Java/Javascript/Python/C/C++/Google Apps Script 16) Sensitive Data Review - Securing data at rest and in transit 17) Docker Container Security 18) Security Incident Response and Management- Customer Engagement 19) Linux OS hardening, OSCAP tools, Redhat STIG/DISA STIG 20) Worked on securing FIDO Integrated Solutions 21) CSPM Automation and Remediation 22) WAF Automation and False Positive analysis at Scale

Experience

16 yrs 4 mos
Total Experience
3 yrs 1 mo
Average Tenure
8 mos
Current Experience

Exotel

VP- Information Security(CISO)

Oct 2025Present · 8 mos · Bengaluru South, Karnataka, India · Hybrid

  • Overseeing both Information Security and IT, leading efforts to secure our systems, modernize our infrastructure in the age of AI, enhance reliability, and ensure technology and security work hand-in-hand to enable business growth.

Junglee games

Security Leader

May 2023Sep 2025 · 2 yrs 4 mos · Bengaluru, Karnataka, India · On-site

  • Currently heading the Security charter under the CTO.
  • Building capabilities and augumenting the Security posture under all the functional security pillars- Application Security, Cloud Security, Enterprise Security,GRC, Security Assurance and Security Operations.

Goto group

Cloud Security Leader

Jan 2022May 2023 · 1 yr 4 mos · Bengaluru, Karnataka, India · Hybrid

Paypal

Application Security Specialist

Sep 2020Jan 2022 · 1 yr 4 mos · Bangalore Urban, Karnataka, India

Mobileiron

2 roles

Staff Security Engineer

Promoted

Jul 2018Sep 2020 · 2 yrs 2 mos · Bengaluru Area, India

  • End to End Product Security Ownership for multiple products both on-prem and cloud(AWS)
  • Application Security across SDLC
  • PKI (Public Key Infrastructure)
  • SAST tools like Checkmarx, Sonarqube including Automation
  • Security Automation into CI/CD pipeline including Jira Integration
  • Automating Vulnerability Management cycle across products like Qualys/Nexpose
  • Secure by Design
  • Automated Threat Modelling
  • Secure Code Reviews
  • Platform Security
  • Securing Next-Gen Authentication -FIDO
  • SSL/TLS advisor
  • Secure Authentication/Authroization
End to End Product Security OwnershipApplication SecurityPKISAST toolsSecurity AutomationVulnerability Management+2

Senior Security Engineer

Jun 2016Jun 2018 · 2 yrs · Bengaluru Area, India

  • Securing On-Prem MDM Software via
  • 1- Manual Threat Modelling at the time of design for all High Value features
  • 2- Code Review for Security Sensitive Features and Crypto Usage including Reviewing Legacy codebase for Security issues for critical pieces such as authentication
  • 3- Gap Analysis of existing On Prem Infrastructure
  • 4- Manage PSIRT(Product Security Incident Management) program for an Onprem product including interfacing with Customers via Blogs and tickets raised by Customers.
  • 5- Vulnerability Management
  • 6- Worked on Security Health Check tool for Customers to check if their deployments have followed recommended Security best practices and necessary guidance for failed checks.
Manual Threat ModellingCode ReviewGap AnalysisVulnerability ManagementSecurity Health Check toolApplication Security

Paypal

Software Engineer 2

Nov 2009May 2016 · 6 yrs 6 mos · Chennai Area, India

  • Converted to full time at PayPal with the Security Engineering Team.
  • Worked on various IRM projects, SafeBrowser, Password Strength Checker, Password Scrambler to name a few.
  • Also part of the Ratelimiting team currently involved in countering day to day velocity attacks against Paypal, limited failed login attempts on Paypal, mitigated api login traffic velocity attack using Ratelimiter.
  • Various key achievements during these years :-
  • 1) Received PAT Award COSMIC KUDOS in H2, 2010.
  • 2) Worked on creation of specification for the new custom pin verification command on payshield HSMs (Hardware Security Module) with external vendor Thales.
  • 3) Worked on critical delivery project Touchstone HSM Pin Verification incorporating HSM PIN verification capabilities into poscryptoserv.
  • 4) Received Spot award for successful completion of Point of Sale projects.
  • 5) Successfully delivered multiple projects in Consumer Security Initiative for IRM namely Password Strength Checker and SafeBrowser Initiative.
  • 6) Involved in the development and support of SecurityAPI, a basic security framework for basic encryption capabilities.
  • 7) Worked in resolving bugs for Certicom based tools to be used for key management teams.
  • 8) Worked on custom security tools from time to time for other vertical PayPal teams based on their requirements.
  • a. Tools for QA to use to create various types of 1024/2048 encrypted versioned pinblocks in Java.
  • b. Tools for encrypting/decrypting certain critical data for use in production
  • 9) Also finished as finalist in Hackathon 2011 (24 hour coding challenge) for Restaurant Management App ( IOS App based + Central Web based Restaurant Management Framework)
  • 10) Represented PayPal in NullCon conference in a 2 day event in Pune.
  • 11) Worked on educating developers on basics of Password Security through Pin-up Cartoon strips.

Education

Indian Institute of Information Technology,Allahabad

Bachelor of Technology (BTech) — Information Technology

Jan 2005Jan 2009

Sri Chaitanya College

College — MPC

Jan 2003Jan 2005

Atomic Energy Central School

Higher Secondary School

Jan 1993Jan 2003

Stackforce found 100+ more professionals with Application Security & Security Automation

Explore similar profiles based on matching skills and experience