A

Arkadeep Kundu

CEO

Bengaluru, Karnataka, India15 yrs 10 mos experience
Highly Stable

Key Highlights

  • Over 13 years of experience in information security.
  • Expert in Secure Development Lifecycle and Vulnerability Management.
  • Proven track record in leading security teams and initiatives.
Stackforce AI infers this person is a seasoned expert in Network Security and Vulnerability Management within the SaaS industry.

Contact

Skills

Core Skills

Secure SdlcVulnerability ManagementNetwork Security

Other Skills

Cloud SecurityTechnical Risk ReportingVulnerability AssessmentTrainingThreat ModelingCode ReviewResearch and DevelopmentRisk ManagementCloud-Native ArchitectureTeachingWeb Application SecurityPenetration TestingTCP/IP protocolsAlgorithmssqlmap

About

Information Security Practitioner, with 13+ years of hands-on experience in defining and implementing Secure Development Lifecycle (SDL) and Vulnerability Management for software development teams. In spare time, an ethical hacker and a wanderlust. A full time father.

Experience

15 yrs 10 mos
Total Experience
5 yrs 4 mos
Average Tenure
5 yrs 1 mo
Current Experience

Cisco

Product Security Technical Lead

May 2021Present · 5 yrs 1 mo · Bengaluru, Karnataka, India

  • Being a part of the Security Business Group (SBG) of Cisco,
  • Leading Cisco SBG’s India Product Security team
  • Building Offensive Security roadmap for SBG. Building a Bug Bounty program
  • Previously owned the Vulnerability Management for Cisco Secure Email Services
Vulnerability ManagementSecure SDLCCloud Security

Dell

3 roles

Principal Product Security Engineer

Promoted

Oct 2019May 2021 · 1 yr 7 mos

  • Was the lead engineer in Dell’s Product Security Incident Response (PSIRT) team
  • Was involved in defining Dell’s PSIRT and SDL standards and procedures
  • Collaborated with lead engineers to ensure systemic security fixes, pan Dell products
  • Was the technical approver for critical Dell Security Advisories and CVEs
  • Created PSIRT’s annual technical risk reports and presented to BU owners
  • Created PSIRT’s Root Cause Analysis procedure, which learns from PSIRT data to drive improvements in Dell’s SDL practices
  • Automated routine tasks like – vulnerability classification, CVE description creation
  • Created technical trainings for developers. Conducted workshops on infosec topics
Vulnerability ManagementSecure SDLCTechnical Risk Reporting

Senior Product Security Engineer

Oct 2016Oct 2019 · 3 yrs

  • Worked in Dell PSIRT team
  • Reproducing reported vulnerabilities, evaluating vulnerability severities and validating fixes for externally reported security issues across all Dell EMC product portfolio.
  • Learned from PSIRT to drive changes into Dell SDL.
  • Educated product engineering teams, pan-Dell. Conducted numerous trainings and workshops
Vulnerability AssessmentVulnerability ManagementTrainingSecure SDLC

Software Engineer

Apr 2014Sep 2016 · 2 yrs 5 mos

  • Implemented EMC’s SDL and PSIRT process for EMC Documentum product suite from scratch as part of a 4-member team.
  • Collaborated with hundreds of developers/leads, in tandem, across product teams for performing threat modelling, code reviewing, SAST, DAST, software composition analysis, manual testing, Bug Bounty, PSIRT activities.
  • Integrated Fortify, Veracode, BURP, BlackDuck to CI/CD.
  • Created a web penetration testing process and toolkit.
  • Maintained documentation of the security posture and conducted periodic review with product owners and executives. Approved pre-release security requirements.
Secure SDLCThreat ModelingCode ReviewVulnerability Management

Indian institute of technology, kharagpur

Junior Scientific Officer

Jun 2010Mar 2014 · 3 yrs 9 mos

  • Involved in research and development of network security assessment and hardening tools. Worked for the project "Design and Development of an Integrated Security Risk Management System for an Enterprise Network" sponsored by Dept. of Electronics and IT, Gov. of India.
  • Worked as a teaching assistant for Master's Degree students in the Department of IT.
Network SecurityResearch and Development

Education

Indian Institute of Technology, Kharagpur

Master of Science (M.S.) — Network Security

Jan 2010Jan 2012

Jadavpur University

BE — Computer Science and Engineering

Jan 2006Jan 2010

Stackforce found 100+ more professionals with Secure Sdlc & Vulnerability Management

Explore similar profiles based on matching skills and experience