Vishal Jindal

Vishal Jindal Email and Phone Number

Application Security Leader at Apple | Investor | Author | Researcher @ Apple
Vishal Jindal's Location
Greater Seattle Area, United States, United States
Vishal Jindal's Contact Details
About Vishal Jindal

Information Security leader with established track record of 8+ years in delivering impactful and high quality risk reducing work. Brings a lot of breadth and deep technical knowledge in Security & Privacy with a strong background in Security automation applied to large scale environments.Open to chat about roles larger than my current role, advising, angel investing and security product feedback for startups.Specialities: Information Security, Data Security, Infrastructure Security, Security Automation, Spam Detection, Abuse Detection, Intrusion Detection and Response, Mobile and Applications Security, SIEM, SOC2 and Compliance, Logging infrastructure, Hiring, Mentoring/Coaching, Interviewing

Vishal Jindal's Current Company Details
Apple

Apple

View
Application Security Leader at Apple | Investor | Author | Researcher
Vishal Jindal Work Experience Details
  • Apple
    Application Security Leader
    Apple Sep 2022 - Present
    Cupertino, California, Us
  • Better Appsec
    Author
    Better Appsec Jul 2022 - Present
    New York, Ny, Us
  • Amazon
    Manager, Application Security Automation
    Amazon Aug 2021 - Sep 2022
    Seattle, Wa, Us
    Built and led a highly technical Security Engineering team of 6 focused on providing Amazon's Worldwide Consumer business (60k+ engineers) automated application security assessment tooling (SAST & DAST) at scale. Focused on delivering high degrees of customer trust in the tooling and reduce the cost of performing ongoing security reviews with rigorous detection quality standards (>90% accuracy), comprehensive coverage (CWE & OWASP mapping), and efficient processes to iterate quickly.• Worked to achieve 95% of all critical/high severity security vulnerabilities identified with automation which drove continuous improvement in security detections, developer empowerment, and the eradication of vulnerability classes.• Expanded build/release time, ad-hoc, and continuous automated security scanning by driving the deployment of new custom, open source, and commercial Static & Dynamic Application Security Testing (SAST & DAST) scanning technologies and detections.• Established scanning coverage standards for code and web based assets across a massive and diverse environment while also providing depth of coverage on higher risk issues such as reflected cross site scripting (XSS) (targeted 99.9% prevention).• Integrated automated security scanning tools into engineers' workflows that resulted in Application Security reducing the time to perform a security review and reducing bug bounty pay out costs by catching common security issues.• Improved security detection rate by 20% by introducing a federated detection authorship process and integrating it into automated processes.
  • Amazon
    Security Engineer Ii, Application Security
    Amazon Oct 2019 - Aug 2021
    Seattle, Wa, Us
    • Developed automated pipeline to scan entire Amazon endpoints for CSRF, XSS and Open-Redirect vulnerabilities and surface identified risks to developers without changing their risk remediation experience• Performed security testing for critical applications and identified code and design vulnerabilities• Automated and incorporated risks identified through pentests and bug bounty programs to ensure those vulnerabilities are identified across the org• Wrote automated static detections to looks for security vulnerabilities, like Reverse Tabnabbing, and integrated it within the pipeline to ensure we are proactively looking for security vulnerabilities.
  • Amazon
    Security Engineer Ii, Selling Partner Services
    Amazon Apr 2018 - Oct 2019
    Seattle, Wa, Us
    • Built mini-OST team performing/organizing penetration testing, red team engagements and bug bounty programs.• Developed dynamic scanners to identify OWASP top 10 vulnerabilities in an automated manner• Identified/remediated high impact security gaps that impact customer's privacy• Implemented open-source web application scanner to scan entire Marketplace platform on a weekly basis• Reported key security metrics to senior leadership and ensured that organization is improving security posture over time• Due to shortcomings of Source Code Analysis Tool (SCAT) used within organization, evaluated and implemented better SCAT tool to help developers identify code-related vulnerabilities early in the development process• Published security guidance for configuring AWS technologies, like RDS, DynamoDB, Lambda, EC2, etc., when storing critical/restricted data
  • Amazon
    Security Engineer, Selling Partner Services
    Amazon Sep 2017 - Mar 2018
    Seattle, Wa, Us
    • Identified shortcomings of web application scanner, used with Marketplace organization, and recommended an open-source solution to reduce cost and get better results.• Performed threat modelling for critical applications to help developers identify security vulnerabilities early in the development process• Provided consultation on an on-going basis to help developers build secure applications• Hosted external penetration tests, for entire Amazon Marketplace organization, to identify security vulnerabilities from an attacker’s perspective• Performed certifications, which included Manual Code Review and Security Testing, of critical web applications
  • Fidelity Investments
    Senior It Auditor
    Fidelity Investments Dec 2016 - Aug 2017
    Boston, Ma, Us
    • Evaluated risks (technology, financial, reputational, and regulatory)• Tested controls designed to mitigate risk, communicated issues and findings to management, devised solutions for business improvements, and followed-up on corrective actions.• Planned and executed multiple concurrent IT audits, including reviews of cyber security, existing production applications, systems currently being developed, technology infrastructure and specialized or emerging technologies.• Identified and assessed complex risks (both business and technological) and provided advice to management regarding mitigation of these risks.
  • Fidelity Investments
    It Audit Analyst
    Fidelity Investments Sep 2015 - Dec 2016
    Boston, Ma, Us
    • Worked on audits related to various business units like Enterprise Infrastructure (EI), Cybersecurity, Business and Operations, etc.• Worked with teams on performing code reviews and auditing different aspects of IT audit like change management, disaster recovery, information security and data processing.
  • Northeastern University
    It Services
    Northeastern University May 2015 - Jul 2015
    Boston, Ma, Us
  • Northeastern University
    Master'S Assistant
    Northeastern University Jan 2015 - May 2015
    Boston, Ma, Us
    Master's assistant for Software Security course. The responsibilities include:- Configured lab environment for students- Graded assignments, tasks and labs- Answered student queries related to course and labs
  • Fidelity Investments
    It Co-Op
    Fidelity Investments Jun 2014 - Dec 2014
    Boston, Ma, Us
    Responsibilities included:1. Identifying the weaknesses in IT systems and creating an action plan to prevent security breeches in the technology. 2. Planning and execution of internal audit procedures and the creation of internal audit reports.3. Worked with teams to create a solid information technology infrastructure, and collaborate with clients to devise and put in place policies and procedures regarding IT security issues.
  • Northeastern University
    It Services
    Northeastern University Jan 2014 - May 2014
    Boston, Ma, Us
  • Mahashakti Energy Pvt Ltd
    Web Developer
    Mahashakti Energy Pvt Ltd Oct 2012 - Jun 2013
    • Re- Designed organization's website and made it secure against various attacks like SQL injection, XSS attacks
  • Mahashakti Energy Pvt Ltd.
    Software Engineer
    Mahashakti Energy Pvt Ltd. Jul 2012 - Oct 2012
    • Worked on the applications of Programmable Logic Controllers (PLC) using Computer Numeric Control (CNC) machines.• Researched the composition and build PLC hardware, programmed PLCs and interfaced them with CNC machines and operated a stand-alone as well as a network of PLCs and CNC machines in the factory area.
  • Tata Research Development & Design Center
    Intern
    Tata Research Development & Design Center Jun 2011 - Mar 2012
    • Researched and implemented an algorithm for speeding the pointer analysis phase of a compiler for millions of lines of C-code.• Results - Achieved 50% more speed than existing algorithms while maintaining the efficiency and accuracy of results

Vishal Jindal Skills

Oracle Oracle Rac Databases Performance Tuning Data Migration Database Administration Database Applications Pl/sql Data Warehousing Replication Unix Goldengate Oracle Rman Ibm Aix Asm Oems Data Center Oem 12c C C++ Java Linux Sql Eclipse Html Microsoft Office Javascript Shell Scripting Windows Core Java Programming Microsoft Excel Network Security Computer Security Powerpoint Website Development Wireshark Nessus Metasploit Cisco Ios Cisco Routers Nmap Owasp Tcp/ip Hsrp Vrrp Vlan Eigrp Osi Model Cisco Technologies Mac Os Ospf Mpls Auditing Vmware Vmware Workstation Vmware Infrastructure Application Testing Secure Code Review Penetration Testing Identity And Access Management

Vishal Jindal Education Details

  • Northeastern University
    Northeastern University
    Computer And Information Systems Security/Information Assurance
  • Maharashtra Institute Of Technology
    Maharashtra Institute Of Technology
    Computer Science
  • Cbse St. Kabir School
    Cbse St. Kabir School
    Xiith
  • St. Joseph'S Convent School
    St. Joseph'S Convent School
    Xth

Frequently Asked Questions about Vishal Jindal

What company does Vishal Jindal work for?

Vishal Jindal works for Apple

What is Vishal Jindal's role at the current company?

Vishal Jindal's current role is Application Security Leader at Apple | Investor | Author | Researcher.

What is Vishal Jindal's email address?

Vishal Jindal's email address is vi****@****ook.com

What is Vishal Jindal's direct phone number?

Vishal Jindal's direct phone number is +161726*****

What schools did Vishal Jindal attend?

Vishal Jindal attended Northeastern University, Maharashtra Institute Of Technology, Cbse St. Kabir School, St. Joseph's Convent School.

What are some of Vishal Jindal's interests?

Vishal Jindal has interest in Social Services, Children, Table Tennis, Badminton, Civil Rights And Social Action, Politics, Trekking, Environment, Education, Painting.

What skills is Vishal Jindal known for?

Vishal Jindal has skills like Oracle, Oracle Rac, Databases, Performance Tuning, Data Migration, Database Administration, Database Applications, Pl/sql, Data Warehousing, Replication, Unix, Goldengate.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.