Skip to main content
Portfolio

Amit Kumar

Senior Product Security Engineer with 6+ years of experience in AppSec, DevSecOps, threat modeling, secure code review, and practical security automation.

View GitHub Projects

Product security, AppSec, and DevSecOps

Threat modeling, architecture review, and code review

Web, mobile, API, and cloud security testing

AI-driven security automation and open-source research

Highlights

Security profile

Focused on product security, secure architecture, mobile AppSec, and scaling security across engineering teams.

6+Years of experience
5+Open-source tool contributions
100+Bug bounty recognitions
Skills

Core strengths

Animated expertise bars that visually show depth across key security domains.

Application Security95%
DevSecOps92%
Android Pentesting94%
iOS Pentesting84%
Cloud Security82%
Source Code Review91%
Threat Modeling90%
GitHub Actions88%
CI/CD Security89%
Reverse Engineering86%
Secure SDLC93%
Security Automation90%
Experience

Professional experience

Experience highlights from the resume, with company names intentionally omitted.

1
Oct 2025 – Present

Senior Product Security Engineer

  • Owned end-to-end security architecture reviews and data handling assessments for critical business systems.
  • Led advanced threat modeling across applications and cloud infrastructure to identify design flaws early in the SDLC.
  • Designed and maintained DevSecOps pipelines with SAST, DAST, SCA, secrets detection, and policy enforcement.
  • Built AI-driven security agents for automated code review, vulnerability triage, and security signal correlation.
2
Jan 2025 – Present

Security Engineer

  • Performed security architecture and data handling reviews with actionable recommendations for product teams.
  • Executed manual and automated penetration testing for web, mobile, and API applications.
  • Embedded security checks into developer workflows to automate compliance validation and reduce release bottlenecks.
  • Partnered with engineering and DevOps teams to drive secure-by-design adoption and secure coding practices.
3
Mar 2020 – Dec 2025

Lead Security Consultant

  • Delivered product security consulting and defined security requirements and risk acceptance criteria across sectors.
  • Performed VAPT for web, API, mobile, and infrastructure applications with OWASP-focused remediation guidance.
  • Conducted automated and manual secure code reviews in Python, Java, NodeJS, and PHP.
  • Integrated SAST, DAST, and IaC scanning into CI/CD pipelines and guided teams on secure development practices.
4
Aug 2018 – Aug 2020

Security Consultant

  • Performed end-to-end security assessments of web, mobile, and infrastructure applications including penetration testing and risk reporting.
Contributions

How I contribute

Practical contribution areas that show impact beyond a project list.

Open-source security projects

Building and sharing practical repositories, experiments, and learning resources through GitHub.

Technical security writing

Publishing hands-on blog content around DevSecOps, supply chain security, and mobile testing.

Community knowledge sharing

Contributing through walkthroughs, research notes, and practical explanations that help other engineers learn faster.

Conferences

Talks and sessions

Selected speaking and showcase highlights from the resume.

Black Hat Arsenal Europe

Showcased Android BugBazaar

Presented open-source mobile AppSec playground work built around insecure design patterns and exploitation scenarios.

Seasides Conference

Android AppSec speaker

Presented on Android security bypasses, protected components, and automation with Semgrep.