20+ years of expertise in collaborating with key stakeholders to identify gaps, develop security processes and capabilities to enhance security posture by introducing vulnerability management and automated security tools. Built Application Security Program from scratch.Successfully built and managed a team of 8 for 5 years in performing application security penetration testing, in addition to code reviews, to ensure compliance to security standards and proactively identify vulnerabilities. Ensured timely delivery of quality deliverables.Proficient at guiding teams and sharing knowledge, while spearheading training and workshops. Possesses robust abilities in motivating and developing teams across all project phases. Recognized for exceptional communication skills, collaborative mindset, and fostering a culture of accountability and ownership.Significant expertise in Application Development, Threat Modeling, Secure Design Analysis, Secure Code Review, Static Code Analysis (SAST), Dynamic Security Analysis (DAST), Penetration testing(PenTest) and Security Automation(DevSecOps).A J2EE Developer turned Application Security Professional with unique ability to understand both the worlds better (Development and Security).Accomplished Enterprise-wide Integration of Dynamic Security Analysis (DAST) on CICD pipeline providing immediate feedback to Developers using Jenkins and Webinspect.Working experience in top companies like Fidelity Investments, TD Ameritrade, DTCC, MindTree, Honeywell and AOL.Chapter Leader, Core Member of Null Security Group and OWASP Security Communities responsible for organizing, conducting and presenting the "meet" on a weekly/monthly basis.Specialties: Threat Modeling, Secure Code Review, Web Penetration Testing, Server Audits, Security Training, Security Automation I'm excited to connect with professionals, innovators, and organizations looking to enhance their security posture. Let’s discuss how I can bring value to your team or project. If you’re interested in collaborating, have an opportunity, or just want to chat about the latest in cybersecurity, reach out to me at hkgsatish@gmail.com
Listed skills include Java, Application Security, Sdlc, Information Security Management, and 35 others.