Skip to content
View djvirus9's full-sized avatar
🎮
BB101
🎮
BB101

Block or report djvirus9

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
djvirus9/README.md

Danish Siddiqui

Senior Product Security Engineer · Founding security engineer at Licious

I build product security programs across application security, cloud infrastructure, and software delivery. My work connects finding a problem with the engineering decisions, ownership, and verification needed to fix it.

Portfolio · Résumé · LinkedIn · Email

Open-source work

Project What you can use or inspect
SecOps Dashboard A self-hosted workspace for importing, deduplicating, and triaging scanner findings. FastAPI, Next.js, and PostgreSQL, with team access controls and a documented threat model. Latest published release · Interactive walkthrough with synthetic data.
DevSecOps Reference An executable learning reference connecting API tests, CI gates, supply-chain evidence, Kubernetes policy, and incident response, with practical guides and assessment templates. Published release · CI runs and validation artifacts.
Security portfolio Engineering case studies, public vulnerability research, and interactive project walkthroughs. Explore the work.

Selected engineering work

  • Product Security at Licious: established the security function across AppSec, AWS controls, vulnerability management, bug bounty operations, and governance.
  • CyberShield360 at Invia: designed product architecture and the security workflow for an attack surface management product, and helped take it to launch.
  • Security in the delivery pipeline: integrated Semgrep and Trivy, tuned findings, and introduced enforcement based on confidence and risk.

Research and writing

My selected CVEs link to public advisories and publisher acknowledgments.

Work with me

Based in Bengaluru, India, and open to global opportunities in Product Security, AppSec, Cloud Security, and security engineering leadership. I also welcome collaboration on open-source security tooling and practical research.

Get in touch · Community and recognition

Pinned Loading

  1. awesome-devsecops-mastery-2026 awesome-devsecops-mastery-2026 Public

    Executable DevSecOps reference: API tests, CI gates, supply-chain evidence, Kubernetes policy, and incident response.

    Python 54 4