
Results-oriented security architect, consultant, analyst, and leader with a Certified Ethical Hacker certification. Specializes in application vulnerability assessment, penetration testing, security as code, API security testing, DevSecOps, container image assessment, software composition analysis (SCA), secure design reviews, static application security testing, threat modeling, and security architecture. Proven expertise in leading the application security vertical and ensuring the highest level of security for organizations. Extensive experience with OWASP Top 10 web and API vulnerabilities, as well as SANS Top 25 vulnerabilities. Skilled in DAST, SAST, SCA, DevSecOps, API security, container image security, threat modeling, SSDLC, security architecture, and product security. Additionally, adept at application performance tuning and analysis. Known for providing exceptional support to a large customer base and possessing strong proficiency in Java/J2EE languages. Offers 19 years of experience in IT with over 17 years of expertise in the application security assurance area.
• Conducted Threat modeling/secure design reviews for AI agents, LLM-based assistants, and multi-agent systems, identifying risks like prompt injection, tool misuse, data exfiltration, and cross-agent task hijacking.
• Conducted threat modeling and security reviews of AI use cases (e.g., RAG, agentic workflows, model fine-tuning)
• Driving secure coding standards and practices tailored to AI systems (e.g., prompt injection mitigation, output validation, model access controls)
• Partnered with AI/ML, software engineering, and cloud teams to embed security early in the AI development lifecycle (shift left)
• Partnered with product and ML teams to define security and safety requirements for LLM-based chatbots, AI assistants and AI Agents, including context boundary controls, logging, fallback mechanisms, and user intent validation.
• Conducted comprehensive security testing of AI models and applications using established security testing methodologies and frameworks.
• Ensured compliance with regulatory standards and AI safety guidelines, aligning testing outcomes with industry best practices.
• Assessed LLM, AI Agent vulnerabilities, performing safety benchmarking and risk evaluation of machine learning algorithms.
• Collaborated with cross-functional teams to analyze, mitigate, and communicate AI-related security risks across development and deployment phases.
• Defined and operationalized a Secure Development Lifecycle (SDLC) for AI/ML products, integrating AI security controls and automated validation in MLOps pipelines.
• Performed AI/ML-specific threat modeling (STRIDE, MITRE ATLAS) to identify risks like data poisoning, model inversion, and adversarial attacks, and implemented mitigation strategies.
• Architected secure AI infrastructures and governance models, ensuring compliance with privacy, data protection, and responsible AI standards (ISO 27001, NIST AI RMF, GDPR).
• Provided technical leadership and mentorship to cross-functional R&D and product teams on secure AI development practices, model assurance, and ethical AI principles.
• Designed and delivered AI Security Proof-of-Concepts (PoCs) and automated frameworks for model robustness testing, anomaly detection, and secure model deployment.
• Conduct comprehensive threat modeling exercises to identify potential security threats and vulnerabilities in applications and systems.
• Hands-on experience in secure software development, integrating CI/CD pipelines (Jenkins, GitHub Actions, GitLab CI) with automated security testing and deployment workflows.
• Proficient in application security testing methodologies, leveraging SAST, DAST, IAST, and MAST tools (e.g., SonarQube, Burp Suite, Checkmarx, Fortify) to identify and remediate vulnerabilities.
• Experienced in application vulnerability management, from discovery and triage to remediation tracking using tools like Jira, ServiceNow, and Tenable.
• Strong working knowledge of SDLC, OWASP Top 10, CWE 25, and secure coding practices across multiple languages (Python, Java, JavaScript) and frameworks.
• Skilled in threat modeling (STRIDE, DFD-based), API security design, and modern authentication/authorization flows (OAuth 2.0, OIDC, SAML).
Working knowledge of cloud security concepts (AWS, Azure, GCP) and network security principles, ensuring secure data flow and system resilience across distributed environments.
A highly skilled Threat Modeling Expert with extensive experience in identifying, assessing, and mitigating security risks throughout the software development lifecycle. Adept at developing comprehensive threat models and implementing security controls across various domains, including authentication, authorization, data protection, logging , monitoring and vulnerability management. Strong expertise in disaster recovery and business continuity planning, ensuring resilient and secure systems.
Threat Modeling
Application security
Security Architecture
DevSecOps
SAST
DAST
Pen Testing
Cloud Security
Data Security
API Security
Source Code Reviews
Training
OWASP TOP 10
OWASP TOP 10 API
HP Webinspect
Burp Suite Professional
IBM Appscan
Fortify
Shift Left
Postman
Net Sparker
Checkmarx
Veracode
Aqua
OWASP ZAP
Azure Devops
Jenkins