Application Security
Threat modeling, secure design, code review.
$ whoami
I'm Amit — Senior Product Security Engineer. I write about finding flaws in design, code, and pipelines before adversaries do. AppSec, DevSecOps, mobile testing, and secure architecture.
// expertise
Threat modeling, secure design, code review.
SAST, SCA, SBOM in CI/CD pipelines.
Android & iOS AppSec, BugBazaar labs.
Dependency risk, third-party trust.
IAM, CSPM, environment hardening.
Architecture review, attack surface.
// filter by topic

CFG, CDG, and DDG/PDG — what makes static analysis actually work beyond pattern matching.
> Read article
How GitHub Actions fits into CI/CD and why workflow security matters.
> Read article
Dependency risk, SCA tooling, and open-source visibility in pipelines.
> Read article
Trust, third-party deps, and the real impact of software supply chains.
> Read article// series
Grouped by topic for structured reading.
$ ./connect.sh
Android BugBazaar, ApkRecon, security labs — built in public on GitHub.