Skip to main content

$ portfolio

Senior Product Security Engineer

Amit Kumar

Product Security

AppSec · DevSecOps · Threat modeling · Secure code review · Mobile & cloud security · Open-source research.

> GitHub Projects
Black Hat ArsenalSeasides ConfRedTeam SummitBugBazaarSemgrep
amit@sec — portfolio
AK

Amit Kumar

Product Security Engineer

Open for consulting & talks
0+Years exp.
0+OSS tools
0+Bug bounties
amit@sec:~$ whoami
role → Senior Product Security Engineer
focus → AppSec · DevSecOps · Mobile
amit@sec:~$ cat mission.txt
Find it before they do.
amit@sec:~$

$ ls portfolio/

// skills

Core strengths

Grouped by domain — SDLC, supply chain, AI agents, web, mobile, cloud, and leadership.

// sdlc-security

SDLC Security

Shift-left security across design, code, and release.

Application Security95%
Secure SDLC93%
Source Code Review91%
Threat Modeling90%

// supply-chain

Supply Chain & DevSecOps

Pipeline security, dependency trust, and CI/CD hardening.

DevSecOps98%
Security Automation98%
CI/CD Security98%
GitHub Actions98%
SCA / SBOM98%

// ai-agent-security

AI & Agent Security

Securing AI systems, agents, and automated security workflows.

AI Security Agents98%
Automated Code Review Agents98%
LLM App Security98%
Prompt & Tool Abuse98%

// mobile-security

Mobile Security

Android, iOS, and reverse engineering depth.

Android Pentesting98%
Reverse Engineering98%
iOS Pentesting98%

// web-security

Web Security

Web apps, APIs, and modern browser attack surfaces.

Web Application Security98%
API Security98%
OWASP / VAPT98%
AuthN / AuthZ Review98%

// cloud-security

Cloud Security

Cloud posture, identity, and environment hardening.

Cloud Security82%
IAM & Access Control80%
CSPM / Misconfig Review78%

// leadership

Leadership & Delivery

Driving secure outcomes with teams and stakeholders.

Security Consulting92%
Secure-by-Design Adoption90%
Cross-team Enablement88%
Mentoring Engineers86%
// experience

Professional journey

Product security, consulting, and hands-on offensive + defensive work.

1
Oct 2025 – Present

Senior Product Security Engineer

  • Owned end-to-end security architecture reviews and data handling assessments for critical business systems.
  • Led advanced threat modeling across applications and cloud infrastructure to identify design flaws early in the SDLC.
  • Designed and maintained DevSecOps pipelines with SAST, DAST, SCA, secrets detection, and policy enforcement.
  • Built AI-driven security agents for automated code review, vulnerability triage, and security signal correlation.
2
Jan 2025 – Present

Security Engineer

  • Performed security architecture and data handling reviews with actionable recommendations for product teams.
  • Executed manual and automated penetration testing for web, mobile, and API applications.
  • Embedded security checks into developer workflows to automate compliance validation and reduce release bottlenecks.
  • Partnered with engineering and DevOps teams to drive secure-by-design adoption and secure coding practices.
3
Mar 2020 – Dec 2025

Lead Security Consultant

  • Delivered product security consulting and defined security requirements and risk acceptance criteria across sectors.
  • Performed VAPT for web, API, mobile, and infrastructure applications with OWASP-focused remediation guidance.
  • Conducted automated and manual secure code reviews in Python, Java, NodeJS, and PHP.
  • Integrated SAST, DAST, and IaC scanning into CI/CD pipelines and guided teams on secure development practices.
4
Aug 2018 – Aug 2020

Security Consultant

  • Performed end-to-end security assessments of web, mobile, and infrastructure applications including penetration testing and risk reporting.
// talks

Conferences & sessions

Talk recordings, Black Hat Arsenal, Seasides, and community speaking.

BLACK HATARSENAL
EUROPE2024
Android BugBazaarLondon, UK
Black Hat ArsenalDec 2024London, UK

Black Hat Europe 2024

Android BugBazaar

Your Mobile AppSec Playground to Explore, Exploit & Excel

with Amit Kumar & Vedant Wayal

Showcased open-source Android AppSec playground with 30+ vulnerabilities and real-world mobile pentesting scenarios at the Arsenal track.

AndroidOpen SourceArsenal
Unveiling Mobile App Exploitation — Seasides
SeasidesSep 2023Goa, India

India's Most Loved Conference

Unveiling Mobile App Exploitation

Defend Android Apps — Reveal Weaknesses, Implement Robust Strategies

with Amit Kumar & Gaurav Bhosale

Hands-on session on Android security weaknesses, defensive strategies, and shielding apps against real-world exploitation.

AndroidMobile AppSecDefense
Creating Code for Bypassing Android Security Checks — RedTeam Security Summit
RedTeam Security SummitDec 2021Online

Season 4 · 3-Day Online Workshop

Creating Code for Bypassing Android Security Checks

Day 1 · 4-hour hands-on workshop

with Amit Kumar

Workshop on writing bypass code for Android security checks — root detection, emulator checks, Frida hooks, and runtime protection evasion. Delivered as Security Consultant at Payatu.

AndroidBypassWorkshopFrida

$ ./connect.sh

Let's work together

Open to security consulting, talks, and collaboration on open-source AppSec tools.

> GitHub