Software Security Engineer

Vishal Raavi

I work in application and product security, covering threat modeling, secure design review, manual and dynamic testing, and remediation validation. I also build the systems I review, using React, Flask, Python, and Docker, which keeps my findings specific to how the software actually ships.

College Park, MDOSCP certified · M.Eng. Cybersecurity, University of Maryland · 3.88 GPA
Certified 2026
OSCPCertified 2026OffSec Certified Professional, OSID57747451
Apps and APIs assessed
100+Apps and APIs assessedProduction web applications and REST APIs security tested
Fewer software defects
50%Fewer software defectsAchieved through OWASP Top 10 review and remediation
Events monitored
17.4M+Events monitoredSSH and web events indexed for real time investigation

Selected work

Security engineering work where I built the system and then assessed it as a target.

Application and cloud security

Secure AWS E-Commerce Platform

Built a production style AWS environment, then assessed it as a target across identity, network, host, and data controls.

Results

AWS services integrated
14AWS services integrated
IAM model enforced
Least privilegeIAM model enforced
Audit trail with CloudTrail and Flow Logs
FullAudit trail with CloudTrail and Flow Logs
  • AWS EC2
  • ALB
  • Auto Scaling
  • RDS
  • S3
  • CloudFront
  • Route 53
  • VPC
  • +6 more

Threat modeling and detection

Secure Application Infrastructure and Security Monitoring

Segmented a two tier LAMP environment, threat modeled it with STRIDE and DREAD, and instrumented it with centralized log monitoring.

Results

Vulnerabilities classified with STRIDE
16Vulnerabilities classified with STRIDE
Threat scenarios scored with DREAD
12Threat scenarios scored with DREAD
Events indexed and searchable
17.4M+Events indexed and searchable
  • Ubuntu
  • Apache
  • PHP
  • MySQL
  • UFW
  • RBAC and ACLs
  • STRIDE
  • DREAD
  • +3 more

Writing

From the blog

All posts

Notes on certifications, offensive security practice, and findings worth writing down.

Capabilities

Skills

Security specialisms first, followed by the engineering and infrastructure work that supports them.

Application and product security

  • Secure SDLC
  • Threat modeling
  • Attack surface analysis
  • Security architecture and design review
  • Secure code review
  • Web and API security
  • Vulnerability management
  • Remediation validation
  • Security retesting

Application security testing

  • DAST
  • Burp Suite
  • OWASP Top 10
  • SQL injection
  • XSS
  • CSRF
  • IDOR
  • Authentication and authorization testing
  • Session management
  • File upload security
  • CORS
  • Business logic testing

Advanced web security

  • API testing
  • Access control
  • SSRF
  • JWT security
  • HTTP request smuggling
  • Web cache issues
  • Path traversal
  • XXE
  • Command injection

Security tools

  • Burp Suite
  • BloodHound
  • Impacket
  • NetExec
  • Chisel
  • WinPEAS
  • LinPEAS
  • msfvenom
  • Nmap
  • SQLmap
  • Wireshark

Security automation

  • Python
  • Bash
  • Recon
  • Endpoint discovery
  • Fuzzing
  • Payload testing
  • Custom payloads

Programming and web

  • Python
  • Java
  • JavaScript
  • SQL
  • HTML
  • CSS
  • React
  • Node.js
  • Flask
  • REST APIs

DevSecOps and engineering

  • Git
  • GitHub Actions
  • CI/CD
  • Docker
  • Bash
  • Secure deployment
  • Logging

Cloud and infrastructure security

  • AWS EC2
  • S3
  • RDS
  • VPC
  • ALB
  • CloudFront
  • Route 53
  • WAF
  • IAM
  • KMS
  • ACM
  • CloudWatch
  • CloudTrail
  • VPC Flow Logs
  • Security groups
  • NACLs

Frameworks and hardening

  • OWASP Top 10
  • STRIDE
  • DREAD
  • NIST CSF
  • CIS Benchmarks
  • Least privilege
  • RBAC and ACLs
  • Network segmentation
  • SELinux
  • UFW
  • Patch management

Operating systems

  • Linux (Ubuntu, Kali)
  • Windows
  • macOS

Get in touch

Contact

Open to full time roles in application security, product security, and cloud security.