Shantanu Khandelwal

CEO

Singapore, Singapore10 yrs 2 mos experience

Key Highlights

  • Over 8 years of experience in Red Team assessments.
  • Expert in vulnerability detection and penetration testing.
  • Proven track record in leading red team operations.
Stackforce AI infers this person is a Cybersecurity expert specializing in Red Team operations and penetration testing.

Contact

Skills

Core Skills

Red TeamPenetration TestingApplication Security

Other Skills

Network SecurityVulnerability AssessmentCybersecurityVulnerability ManagementCloud SecurityProject ManagementInformation SecurityManaged Security ServicesSec opsAmazon Web Services (AWS)Microsoft AzureAnalytical SkillsResiliencyClient RelationsClient Services

About

I convert network layout to an attack path. I protect an organization from attacks by performing "Red Team" assessments. I emulate cyber adversaries to detect vulnerabilities in your People Process and Technology. I have 8+ years of experience in Red Team and Penetration Testing. Let's grab a coffee and discuss about Penetration Testing and Red Team

Experience

10 yrs 2 mos
Total Experience
1 yr 7 mos
Average Tenure
5 mos
Current Experience

Uob

Vice President of Red Team

Dec 2025Present · 5 mos · Singapore · Hybrid

  • Lead red team operations across people, processes, and technology
  • Execute attacks mapped to the MITRE ATT&CK framework
  • Run purple team exercises with the SOC to improve detection and response
  • Perform network, system, and application penetration testing
  • Exploit vulnerabilities and validate real world attack paths
  • Deliver threat and risk insights from red team operations and simulations
  • Partner with infrastructure, application, and security teams to share actionable intelligence
  • Evaluate and operate open source and commercial security tools
  • Manage third party red team and penetration testing engagements
Red TeamPenetration TestingNetwork SecurityVulnerability AssessmentCybersecurity

Kpmg singapore

2 roles

Associate Director

Promoted

Jun 2024Dec 2025 · 1 yr 6 mos · Singapore · On-site

  • Engage with clients to identify business opportunities for red teaming, penetration testing, and working with clients to scope and deliver those services.
  • Fulfill a leadership role within the Cyber Defence team, taking responsibility for driving enhancements of services, processes, knowledge and skills.
  • Led 10+ red team engagements for clients and other technical engagements, as the primary contact taking responsibility for delivery on time and to budget.
  • Acting as a technical leader for the team, providing formal training and mentoring to the team.
  • Lead cloud‑focused adversary simulations (Azure/AWS) to exploit misconfigurations, overprivileged identities, and lateral movement paths.
  • Enhance vulnerability management programs for clients by integrating automated scanning (Nessus, Qualys) with threat intelligence to prioritize risks using CVSS.
  • Conduct purple team exercises, collaborating with SOC teams to map red team TTPs to detection gaps (Splunk, Sentinel).Worked with a bank and reduced MTTR by 25% through ATT&CK‑based detection engineering.
  • Serve as performance manager for junior staff and provide guidance and mentorship as part of their professional development and annual goals.
  • Provide oversight and quality assurance on technical testing including internal, external, application, infrastructure, cloud and API penetration tests conducted using tools such as Burp Suite, Sysinternals, Steampipe etc. .
  • Contribute to internal practice management initiatives such as cyber security training and knowledge sharing across the Singapore firm departments.
  • Work with developers to remediate vulnerabilities post SAST,SCA, DAST reviews.
Red TeamPenetration TestingVulnerability ManagementApplication SecurityCloud Security

Cyber Security Manager

Apr 2021Jun 2023 · 2 yrs 2 mos · Singapore

  • Lead and conduct application (web and mobile) and infrastructure vulnerability assessment and penetration tests on different platforms and technologies.
  • Lead and conduct source code review to identify software program vulnerabilities and detect malware or malicious embedded code.
  • Conduct social engineering and email phishing attacks to simulate the theft of passwords, infiltrate systems, and download malware/ransomware.
  • Simulate real-time cyber-attacks using red team/blue team exercises.
  • Lead server/network/middleware security configuration assessments.
  • Review reports on identified security vulnerabilities and possible recommendations to remediate the vulnerabilities.
  • Continuously enhance the existing penetration testing methodologies.
Red TeamApplication SecurityCybersecurityInformation Security

Aon

Associate Director

Jun 2023Jul 2024 · 1 yr 1 mo · Singapore · On-site

  • Delivered and oversaw technical security testing projects, with particular focus in Adversary Attack Simulation Exercises.
  • Managed stakeholders by developing existing and new client relationships.
  • Managed projects for penetration testing and red team engagements.
  • Performed quality assurance and technical reviews of client deliverables and internal documentation.
  • Planned and executed Adversarial Attack Simulation Exercises for both project‑based and continuous engagements.
  • Researched and weaponized evasion techniques and tooling to bypass cyber‑attack detection technologies.
  • Directed cloud security assessments (AWS/GCP), identifying critical issues like exposed S3 buckets and weak IAM policies, and guiding remediation.
  • Expanded vulnerability management offerings, developing client‑specific workflows for patch governance and zero‑day re‑
  • sponse (e.g., Log4Shell).
  • Led purple team initiatives, blending red team tools (Cobalt Strike) with blue team telemetry to validate detection rules (Sigma, YARA).
Red TeamPenetration TestingVulnerability ManagementApplication SecurityProject Management

Deloitte

Red Team Senior Consultant

Oct 2018Mar 2021 · 2 yrs 5 mos · Hong Kong SAR

  • Experience in managing team of 4 people and conducting penetration testing
  • Experience in providing OWASP training to client employees
  • Application penetration testing for credit score aggregating firm. The firm works similar to TransUnion in terms of providing credit scoring of an individual.
  • Hands on experience in performing iCAST (regulatory Red Team by HKMA for financial institutions) on international banks
  • Web and Wi-Fi Penetration Testing for a Science Park
  • Application penetration testing of Near Field Communication (NFC) based card-less money withdrawal from ATM for one of the largest Chinese bank
  • Network and Application Penetration testing for a utilities company targeting CCTV and Door Access Control systems
  • Internal and External network Penetration Testing for a few large banks in Hong Kong
Red TeamApplication SecurityPenetration Testing

Ey

Associate Consultant

Jul 2016Oct 2018 · 2 yrs 3 mos · Mumbai, Maharashtra, India

  • Drafted Secure Configuration Documents for Network Devices, Operating Systems, Databases etc. for international banks.
  • Configuration review of Network Devices, Operating Systems, Databases etc. for leading international banks.
  • Web Application Security assessment of critical Internal/External Banking and financial products including - Corporate & Personal Banking.
  • Mobile Application Security assessment of critical Banking and Insurance Applications.
  • Web Application/Thick Client Security testing of Critical Internal/External applications in Banking, Insurance and Industry sector
  • Malware analysis of malware involved in a cyber heist
  • Cyber threat Incident response at a leading Indian bank.
  • Vulnerability Assessment & Penetration Testing of International Banks.
  • Hands on experience with penetration testing wide range of Operating Systems including Windows, Unix.
  • ATM penetration testing for leading Indian Bank
Application SecurityCybersecurity

Nagarro

Trainee

Jan 2015Jun 2015 · 5 mos · Gurgaon

  • Java Trainee
  • Ephesoft
  • Python
  • OCR recognition
  • Spring
  • Struts
  • Hibernate
  • Ephesoft Enterprise
  • Automation

C-dac (formerly ncst)

Intern

Jun 2014Aug 2014 · 2 mos · Pune ,India

  • Programming Intern
  • Website Penetration Testing
  • Network Penetration testing
  • Python Automation

Education

Gujarat Forensic Sciences University

Master’s Degree — Cyber/Computer Forensics and Counterterrorism

Jan 2015Jan 2017

Panjab University

Bachelor of Engineering (BE) — Information Technology

Jan 2011Jan 2015

Stackforce found 100+ more professionals with Red Team & Penetration Testing

Explore similar profiles based on matching skills and experience