Application Security Engineer
Current• Designed and championed an Application Security Pipeline that was used by 300+ devs and adopted across over 100 business-critical repositories. This initiative successfully eliminated critical vulnerabilities and reduced the number of high-risk vulnerabilities by 50% within the first year of implementation.• Played a key role in administering the bug bounty program: processed tens of vulnerabilities, incorporated a few new company assets, liaised with external hackers, and supported the development team's remediation process.• Crucial contributor to both external and internal penetration tests: adhered to compliance requirements, managed vulnerabilities, prepared environments, and maintained clear communication with all stakeholders.• Actively tailored Web Application Firewall (WAF) rules to align with evolving web application security threats(like log4shell), ensuring robust defense mechanisms.