AeroLeads people directory · profile

Kiran Shirali Email & Phone Number

Security Director, Threat Management and Response at eBay
Location: Milpitas, California, United States 8 work roles 2 schools
1 work email found @ebay.com 2 phones found area 408 and 866 LinkedIn matched
✓ Verified August 2026 4 data sources Profile completeness 100%

Contact Signals · 1 work email · 2 phones

Work email k****@ebay.com
Direct phone (408) ***-****
LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
Security Director, Threat Management and Response
Location
Milpitas, California, United States

Who is Kiran Shirali? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Kiran Shirali is listed as Security Director, Threat Management and Response at eBay, based in Milpitas, California, United States. AeroLeads shows a work email signal at ebay.com, phone signal with area code 408, 866, and a matched LinkedIn profile for Kiran Shirali.

Kiran Shirali previously worked as Senior Manager, Security Engineering at Ebay and Security Engineering Manager, Detection & Automation at Ebay. Kiran Shirali holds Master Of Science (Ms), Computer And Information Systems Security/Information Assurance (Information Security) from Northeastern University.

Company email context

Email format at eBay

This section adds company-level context without repeating Kiran Shirali's masked contact details.

{first_initial}{last}@ebay.com
86% confidence

AeroLeads found 1 current-domain work email signal for Kiran Shirali. Compare company email patterns before reaching out.

Profile bio

About Kiran Shirali

My Motto:"Only those who will risk going too far can possibly find out how far one can go" - Thomas Stearns Eliot#whoamiAn agile leader who has immersed himself in the verticals of Application Security, Offensive Security, Security Engineering (Security Detection and Automation) and Security Incident response. I have experience in managing different facets of security. I have been accountable for the success of security programs from establishing the vision to meeting quantifiable goals and measures to reduce risk for the organization. My greatest accomplishment is helping grow the careers of both security engineers and a security manager, while they have a fulfilling work life.

Listed skills include Red Team, Information Security, Penetration Testing, Wireshark, and 44 others.

Current workplace

Kiran Shirali's current company

Company context helps verify the profile and gives searchers a useful next step.

eBay
Ebay
Security Director, Threat Management and Response
Website
AeroLeads page
8 roles

Kiran Shirali work experience

A career timeline built from the work history available for this profile.

Security Director, Threat Management And Response

Current

San Jose, Ca, Us

Organization: Security Incident Response, Security Hunting, Security Engineering (Security Detection, Security Automation, Security Analytics and Data Engineering) and Security Problem ManagementCurrently Manage: 2 Security Managers and 2 Security Problem Management Engineers and a total organization of 32 peopleResponsible to ensure that we contain and eradicate any security threat for eBay.

Apr 2024 - Present

Senior Manager, Security Engineering

San Jose, Ca, Us

Responsible for: Security Engineering (Security Detection, Security Automation, Security Analytics and Data Engineering)Influence and Adhoc Management: Security Incident ResponseCurrently Manage: 5 Security Analytics and Data Engineers, 4 Security Automation Engineers, 8 Security Detection Engineers.Setup and spearheaded eBay InfoSec's automation program to increase InfoSec's efficiency (Security Incident Response, Vulnerability Response, AppSec Bug Bounty, GRC and Threat Intel). For example, we had a 85% reduction in Mean Time to Resolve Incidents YoY after year one implementation of the automation program. Our workflow automation efforts have achieved a 50% end to end automated security response on all security alerts generated (no human intervention). We have enabled automation for automated evidence collection for myriad of GRC related standard compliance (10+%). We have ensured automated processing of 1k+ indicators influencing our detective and preventative controls. Manage InfoSec's security analytics and data engineering efforts. We are building a custom data engineering logging pipeline and alerting platform leveraging Kafka, Flink and Hadoop to scale to eBay's security needs (currently ingesting daily 25TB+ and counting)Accountable for the detection engineering program for our Security Incident Response team. Manage a team of eight security detection engineers who are responsible for ensuring that our security Incident response team has valuable alarms (and associated investigative data) for bad behavior in our network.Not only is CSIRT my customers, I am also the backup for the CSIRT Manager. I am well versed with handling incidents, dealing with threat intelligence and hunters, engaging with forensic partners, interfacing with legal, communications, brand and treasury teams to build relationships and responding to different audits (internal and external auditors/regulators; ex: PCI, NYDFS)

Sep 2019 - Apr 2024

Security Engineering Manager, Detection & Automation

San Jose, Ca, Us

I currently lead efforts in two logical functions:Detection - Splunk Use Case/Security Content Development• We build intelligent correlation rules on Splunk (our SIEM) to help our Security Operation Center (SOC) get high fidelity alerts so that they can go after malicious entities on systems and networks.• We fine tune the plethora of tools that we have in service to help our detection efforts. Our focus is to improve the true positive percentage for detection tools like Imperva, Netwitness, Tripwire, Data loss Prevention and so on. Fine tuning efforts led to a 11% reduction in manpower costs for the organization for the financial year 2018.Automation - CSIRT Security Orchestration and Automation • We build automated workflows, response and orchestration actions so as to let our analysts be more efficient in their day to day Security Incident Response activities. Implementation of a SOAR setup led to an 87.5% reduction in Mean time to Resolve an Incident.• We also build automated prevention and detection of indicators of compromise by using external threat feeds, there by operationalizing threat intelligence. Also for fun and in the few times that is required, I have jumped into the middle of an investigation to support it both as a technical expert and as a sounding board for analysts to bounce their leads and efforts off.Automation - Vulnerability Management Automation• We build automated workflows for our vulnerability management team, meshing vulnerability findings to asset owners. This allows for a scaled approach of making owners accountable to fixing vulnerabilities in their assets.Purple Team Collaboration: Be a bridge between our Red and Blue team to ensure that there is collaboration and a feedback channel on all activities.

Sep 2017 - Aug 2019

Senior Information Security Engineer (Red Team - Offensive Security Lead)

San Jose, Ca, Us

My responsibilities were:• Red team Activities (Simply put, I break into stuff). My targets ranged from the application layer to systems and networks. On a daily basis I was working on a myriad of activities ranging from port scanning subnets using masscan and nmap to extracting passwords from SAM in memory using powershell and mimikatz.• Penetration Test existing applications to catch any security flaws and to get them remediated. I also have performed due diligence penetration tests for potential mergers and acquisitions and have then worked with the business stakeholders (the target's CEO, CTO, Senior Technical and Managerial Staff and so on) to up the security posture.• Coordinated PCI external pentests for eBay for 2016 and 2017. In this role, I had to work with external pentesters and different internal teams in ensuring that all the pentests are performed and issues are remediated to ensure sufficient evidence for the PCI QSA.• Influence building better defensive postures and detection capabilities -- Tested our end point security and perimeter defenses using custom malware built with the help of MSFvenom (Metasploit Tool). -- Engaged the Security command center in bettering their detection use cases based on Red Team exploit kill chains. -- Communicated weaknesses in our defensive posture on a monthly basis to the CTO so as to gain upper management support. -- Coordinated with infrastructure and build teams to harden base images to be deployed for eBay’s external facing applications based on NIST (SP 800-123) standards. -- Conducted companywide awareness sessions on the state of security, successful Red Team exploits and security best practices.

Nov 2015 - Sep 2017

Senior Information Security Engineer (Application Security - Secure Sdlc)

San Jose, Ca, Us

Some part of this role was when I was on PayPal's security team before eBay and PayPal split up to become two different companies. My responsibilities in both PayPal and eBay's security team were:• Build security frameworks so as to enable automated security scans on applications -- Leveraged IBM AppScan Enterprise which is a dynamic application security testing (DAST) tool. -- Enabled automated security scans based on data from existing selenium tests scripts in the Continuous Integration/DEVOPS Model. -- Designed, built and managed the entire AppScan Enterprise set up for eBay and PayPal. Spearheaded all activities from license and server procurement to setup and evangalization of the solution.• Help in efforts to advance security awareness and guidelines among product development teams. -- Incorporated a form of lightweight threat modelling using a tool from Security Compass called SD Elements. -- Ensured that it is baked into the DEVOPS model by automating and integrating the security guidelines system into our internal tools. -- Influenced application architecture designs to incorporate security best practices and standards at PayPal. -- Delivered tailored training sessions to product development teams on security vulnerabilities and their mitigation techniques.• Penetration Test existing applications to catch any security flaws and to get them re-mediated. I also have performed due diligence penetration tests for potential mergers and acquisitions and have then worked with the business stakeholders (the target's CEO, CTO, Senior Technical and Managerial Staff and so on) to up the target's security posture.

Jun 2014 - Nov 2015

Graduate Teaching Assistant (Masters Assistant)

Boston, Ma, Us

Was a TA for Foundations of Information Assurance course for the Fall Semester and TA Grader for Cyberspace Programming course for the Spring Semester.

Sep 2013 - Apr 2014

Security Intern Graduate Student

San Jose, Ca, Us

Worked for the Infrastructure QA - AppSec Team. Developed an automation project involving PayPal's Proprietary framework BlueFin (based on Selenium Web driver) and an application security tool IBM AppScan Enterprise.Tested some of the PayPal applications for application security issues before releases went out to production.

May 2013 - Aug 2013

Offshore Consultant - Team Lead

San Diego, Ca, Us

For our client Qualcomm,• Led teams to build various desktop and mobile based web applications, using jQuery (and jQuery Mobile) framework, Spring framework (java based web application development framework), HTML5 and JBOSS RESTEasy framework (RESTful web services), for QUALCOMM’s groups. • Performed security assessments to find and eliminate some of the OWASP Top 10 security issues by leveraging proxy tools like Paros and Burp Suite.• Ensured that input sanitization was in place by leveraging OWASP AntiSamy Project and also put in place whitelisting measures.In addition to my technical responsibilities for our client Qualcomm, I was responsible for many additional tasks for Tata Consultancy Services. They are:• Was responsible for security awareness and recent college grad training during their induction to the offshore development center -- Conducted awareness training on OWASP Top 10 attacks, Spring and Hibernate frameworks for RCGs and other laterals when they joined the team.• Was responsible for Tata Consultancy Services' Security Audit Requirements for the Offshore Development Center. -- Coordinated with the Physical Access Team to ensure that physical access to the Offshore Development Center was regulated. Ensured that access reconciliation was carried out on a timely basis. -- Coordinated with the IT Infrastructure team to ensure that logical access to the Offshore Development Computers and Networks was regulated. Ensured that access reconciliation was carried out on a timely basis. Also ensured that associates in the Offshore Development Team are aware and compliant with the Security Policy. Conducted awareness sessions like iSecure and presentations sessions on a quarterly basis to ensure standards of "due care" are met. • Conducted initial screening interviews for freshers and laterals for the Offshore Development Team on topics like Application Security Vulnerabilities, Java, Spring, JavaScript, jQuery and Hibernate.

Sep 2008 - Aug 2012
Team & coworkers

Colleagues at eBay

Other employees you can reach at ebayinc.com. View company contacts →

2 education records

Kiran Shirali education

Master Of Science (Ms), Computer And Information Systems Security/Information Assurance (Information Security)

Northeastern University

Bachelor Of Engineering (B.E.), Computer Science

National Institute Of Engineering, Mysore
FAQ

Frequently asked questions about Kiran Shirali

Quick answers generated from the profile data available on this page.

What company does Kiran Shirali work for?

Kiran Shirali works for eBay.

What is Kiran Shirali's role at eBay?

Kiran Shirali is listed as Security Director, Threat Management and Response at eBay.

What is Kiran Shirali's email address?

AeroLeads has found 1 work email signal at @ebay.com for Kiran Shirali at eBay.

What is Kiran Shirali's phone number?

AeroLeads has found 2 phone signal(s) with area code 408, 866 for Kiran Shirali at eBay.

Where is Kiran Shirali based?

Kiran Shirali is based in Milpitas, California, United States while working with eBay.

What companies has Kiran Shirali worked for?

Kiran Shirali has worked for Ebay, Northeastern University, Paypal, and Qualcomm (Via Tata Consultancy Services).

Who are Kiran Shirali's colleagues at eBay?

Kiran Shirali's colleagues at eBay include Mandeep Singh, Hamidullah Formuli, Rick Fleet, Nirit Shua Geva, and Violetta Prince.

How can I contact Kiran Shirali?

You can use AeroLeads to view verified contact signals for Kiran Shirali at eBay, including work email, phone, and LinkedIn data when available.

What schools did Kiran Shirali attend?

Kiran Shirali holds Master Of Science (Ms), Computer And Information Systems Security/Information Assurance (Information Security) from Northeastern University.

What skills is Kiran Shirali known for?

Kiran Shirali is listed with skills including Red Team, Information Security, Penetration Testing, Wireshark, Nmap, Nessus, Web Application Security, and Security Engineering.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.