Arif — DevOps Manager
Accomplished Application Security Engineer and Penetration Tester with 8+ years of experience overall in cybersecurity specializing in building secure SDLC practices from the ground up in fast-paced FinTech environments. A strong believer in OpSec and Privacy. Proven expertise in offensive security, including penetration testing, vulnerability research, and secure code review across web, API (REST/GraphQL), and mobile platforms. Passionate about driving proactive security culture through developer education, process automation, and threat modeling. Recognized for discovering vulnerabilities in products by Google, Microsoft, Paytm, etc. Core Competencies Application Security: Secure SDLC, Threat Modeling (STRIDE), Secure Code Review, SAST/DAST/SCA Implementation, OWASP Top 10, OWASP ASVS, API Security (REST/GraphQL), Mobile Security (iOS/Android). Offensive Security: Penetration Testing (PtaaS), Vulnerability Assessment & Management, Bug Bounty Hunting, Network Security (Nmap, Masscan), CVE Research. DevSecOps & Automation: CI/CD Security Integration, Secrets Scanning (TruffleHog, Gitleaks), Infrastructure as Code (IaC) Security, Scripting (Python, Bash, NodeJS). Security Tools: Burp Suite (Pro/Enterprise), Semgrep, Snyk, SonarCloud, OWASP ZAP, Fiddler, Nessus. Cloud & Endpoint Security: AWS Security (WAF, IAM, GuardDuty, Cloudwatch), EDR Implementation & Testing.
Stackforce AI infers this person is a cybersecurity expert specializing in application security within the FinTech industry.
Location: Bengaluru, Karnataka, India
Experience: 8 yrs 2 mos
Skills
- Application Security
- Penetration Testing
- Offensive Security
- Devsecops
- Technical Writing
- Cybersecurity
- Leadership
Career Highlights
- 8+ years in cybersecurity with a focus on application security.
- Recognized for discovering vulnerabilities for major companies.
- Expert in building secure SDLC practices in FinTech.
Work Experience
Independent Consultant
Security Consultant (2 yrs 5 mos)
Stealth Startup
Security Engineer (2 yrs 1 mo)
Cybrary
Technical Writer (1 yr 1 mo)
Synack Red Team
Red Teamer (2 yrs 3 mos)
Detectify
Ethical Hacker (7 yrs 9 mos)
Secjuice
Leadership Team (3 yrs 8 mos)
Latest Hacking News
Technical Writer (11 mos)
Education
BCA at University