About

Security engineer who ships the code as well as the findings

I am a Software Security Engineer at the University of Maryland, where I own application security across the development lifecycle for software that is exposed to external users. My work covers attack surface review, threat modeling, manual and dynamic testing with Burp Suite, and working directly with developers through triage, remediation, and retest.

Before this I spent a year at Sathayush Technologies assessing client web applications and REST APIs. I tested more than 100 production applications for SQL injection, XSS, CSRF, IDOR, authentication and authorization flaws, insecure file handling, and misconfigurations, then worked with their engineering teams until each finding was closed and verified.

I hold the OSCP and a Master of Engineering in Cybersecurity from the University of Maryland, completed with a 3.88 GPA. I am currently working toward the Burp Suite Certified Practitioner certification.

I still write production code. Most of my engineering work is in React, Flask, Python, REST APIs, and Docker, with releases running through GitHub Actions. Knowing how a system is built is what makes a security review specific and actionable rather than generic.

Career

Experience

Apr 2024 to Present

Current

Software Security Engineer, Product Security

University of Maryland · College Park, MD

Own application security across the development lifecycle for research software that is exposed to external users, and build production features on the same codebase.

  • Cut software defects by 50% through OWASP Top 10 code review and remediation of XSS, insecure design, input validation, and cross origin weaknesses, using server and client side validation, CORS hardening, and DOM safe content handling.
  • Run manual and dynamic testing with Burp Suite across API endpoints, authentication and authorization flows, session handling, input validation, CORS behavior, and business logic, then reproduce findings and confirm real impact before remediation.
  • Embed security into the SDLC by reviewing attack surface, trust boundaries, REST APIs, user controlled inputs, file processing paths, and externally exposed functionality at design, development, and release.
  • Lead threat modeling and security design reviews across frontend and backend data flows, service integrations, and privilege boundaries, turning high risk attack paths into concrete engineering controls.
  • Design token authenticated Flask REST APIs and access controlled workflows that strengthen authentication, authorization, and session boundaries for externally accessible functionality.
  • Partner with developers on triage, root cause analysis, code level fixes, and retesting before release to confirm remediation and prevent regression.
  • Reduced application response time by 50% while building production services with React, Flask, Python, REST APIs, and Docker.
  • Standardized releases with GitHub Actions, CI/CD, Docker, and shell automation, improving deployment reliability, logging visibility, and secure configuration management.
  • Burp Suite
  • OWASP Top 10
  • Threat Modeling
  • Flask
  • React
  • Python
  • Docker
  • GitHub Actions

Nov 2022 to Dec 2023

Application Security Engineer

Sathayush Technologies · Hyderabad, India

Delivered security assessments for client web applications and APIs, then worked with their engineering teams through remediation and retest.

  • Assessed more than 100 production web applications and REST APIs, identifying SQL injection, XSS, CSRF, IDOR, authentication and authorization bypasses, insecure file handling, and security misconfigurations using Burp Suite, Nmap, and custom payloads.
  • Reviewed authentication, authorization, user controlled inputs, API endpoints, session management, business logic, and sensitive data exposure, and gave developers specific remediation guidance for every confirmed finding.
  • Worked with software engineers through reproduction, root cause analysis, secure implementation changes, and retesting before closure.
  • Ran threat modeling, attack surface analysis, and security design reviews for web and cloud hosted applications, prioritizing controls by likelihood and potential impact.
  • Built Python and Bash tooling for reconnaissance, endpoint discovery, fuzzing, and payload testing, which widened coverage and reserved manual effort for higher risk functionality.
  • Performed internal and external infrastructure assessments, validating SMB, LDAP, and identity misconfigurations with Metasploit, NetExec, and BloodHound.
  • Burp Suite
  • Nmap
  • Metasploit
  • BloodHound
  • NetExec
  • Python
  • Bash

Credentials

Certifications

Earned 2026

OffSec Certified Professional (OSCP)

OffSec · OSID57747451

In progress

Burp Suite Certified Practitioner (BSCP)

PortSwigger · Web and API security testing

Completed

Software Design Threats and Mitigations

University of Colorado System · Secure software design

Completed

Software Design as an Element of the Software Development Lifecycle

University of Colorado System · Secure SDLC

Academic

Education

Jan 2024 to Dec 2025

Master of Engineering, Cybersecurity

University of Maryland, College Park · College Park, MD

GPA 3.88 / 4.0

Relevant coursework

  • Cloud Security
  • Penetration Testing
  • Security Tools
  • Secure Software Design