Senior Product Security Engineer · Founding security engineer at Licious
I build product security programs across application security, cloud infrastructure, and software delivery. My work connects finding a problem with the engineering decisions, ownership, and verification needed to fix it.
Portfolio · Résumé · LinkedIn · Email
| Project | What you can use or inspect |
|---|---|
| SecOps Dashboard | A self-hosted workspace for importing, deduplicating, and triaging scanner findings. FastAPI, Next.js, and PostgreSQL, with team access controls and a documented threat model. Latest published release · Interactive walkthrough with synthetic data. |
| DevSecOps Reference | An executable learning reference connecting API tests, CI gates, supply-chain evidence, Kubernetes policy, and incident response, with practical guides and assessment templates. Published release · CI runs and validation artifacts. |
| Security portfolio | Engineering case studies, public vulnerability research, and interactive project walkthroughs. Explore the work. |
- Product Security at Licious: established the security function across AppSec, AWS controls, vulnerability management, bug bounty operations, and governance.
- CyberShield360 at Invia: designed product architecture and the security workflow for an attack surface management product, and helped take it to launch.
- Security in the delivery pipeline: integrated Semgrep and Trivy, tuned findings, and introduced enforcement based on confidence and risk.
My selected CVEs link to public advisories and publisher acknowledgments.
- When an image upload becomes executable content — Traccar research and the SVG upload trust boundary.
- The trust boundary in a CSV export — how exported data can become active spreadsheet content.
- LLM security and the OWASP Top 10 — writing published on the Halodoc engineering blog.
Based in Bengaluru, India, and open to global opportunities in Product Security, AppSec, Cloud Security, and security engineering leadership. I also welcome collaboration on open-source security tooling and practical research.





