Shantanu Ghumade
>
Contact Information
Summary
Security Tech Lead with 6+ years of hands-on work across AppSec, cloud security, and DevSecOps. I focus on making security practical for engineering teams: reviewing code and architecture, building CI/CD guardrails, hardening cloud environments, and turning repeatable security work into useful automation. Lately, that has included AI-driven tooling for threat intelligence, triage, and policy workflows.
Certifications
Work Experience
Deriv, Malaysia
Security Tech Lead - Security Assurance
- Lead security assurance work across application security, cloud security, DevSecOps, and AI-assisted security automation.
- Work with product and engineering teams on security reviews, automation strategy, and practical risk reduction.
- > AI & Security Automation
- Threat Feed Automation: Built an AI-driven threat intelligence feed mapped to the internal tech stack, helping surface relevant risks earlier.
- Security Assistant: Developed an internal RAG-based assistant that answers employee security questions from Information Security policies and internal process docs.
- HackerOne Triage Bot: Designed an automated HackerOne prescreening agent to cut down manual triage effort and improve initial response time.
- Vendor Prescreening: Automated third-party vendor prescreening with LLM-assisted research and risk flagging.
- Compliance Gap Analysis Framework: Created an AI-powered framework for comparing internal policies against regulatory requirements.
Deriv, Malaysia
Senior Security Engineer
- Led end-to-end security assessments for web, mobile, API, network, and cloud products, including secure code and architecture reviews.
- Improved cloud security posture with CIS-aligned hardening across 20+ AWS accounts and 20+ GCP projects.
- Reviewed Perl, Node.js, Python, Go, React.js, and Flutter code to catch vulnerabilities earlier in the delivery cycle.
- Owned and scaled DevSecOps adoption, including pre-commit hooks and organization-wide secret prevention controls.
- Built and maintained CI/CD security pipelines with SAST, SCA, IaC scanning, and secret detection.
- Managed Deriv’s HackerOne bug bounty program end to end, improving triage workflows and researcher engagement.
- Used CrowdStrike EDR and Datadog SIEM for threat detection, incident response, and proactive threat hunting.
- Owned incident response investigations, correlating logs across platforms, finding root causes, and putting safeguards in place to reduce repeat issues.
- > Detection & Incident Response
- Performed threat detection and hunting with CrowdStrike EDR and Datadog SIEM.
- Led incident response investigations, root-cause analysis, and follow-up control improvements.
- Reversed malware from a campaign where a fake AI recruiter on LinkedIn lured developers into a private GitHub repository.
Read Article
SecureLayer7, Pune, India
Lead Security Consultant
- Led end-to-end security testing engagements for global clients in finance, technology, and payment solutions.
- Chosen for critical on-site international engagements, including infrastructure penetration tests for high-value clients.
- Translated complex vulnerability findings into clear remediation plans for executive stakeholders.
- Earned two promotions within three years by consistently delivering strong assessments and client outcomes.
- Presented a webinar on mobile application security
Watch Webinar
Security Consultant
Feb 2021 – Feb 2022- Performed in-depth source code analysis and mobile application penetration testing for Android and iOS.
- Ran internal sessions on topics including "Fuzzing HTTP Requests" and "HTTP request smuggling."
Associate Security Consultant
Feb 2020 – Feb 2021- Conducted 50+ web application, API, and network vulnerability assessments.
- Reported vulnerabilities found through manual and automated VAPT testing with clear reproduction steps and remediation guidance.
Technical Skills
Application Security & Pentesting
- Security assessments across web, mobile (Android/iOS), API, network, and cloud environments.
- Tools: Burp Suite, Postman, MobSF, Frida, Nmap, Metasploit.
- Secure code review and architecture review.
Cloud Security
- AWS, GCP, and Alibaba Cloud hardening and configuration review.
- SCP policy implementation and public exposure reduction.
- Automated cloud security posture management (CSPM).
DevSecOps & Automation
- CI/CD security integrations for SAST, DAST, IaC, and secret scanning.
- Custom tooling, including Nuclei templates and subdomain monitoring.
- LangChain-based automation for threat intelligence and triage.
Enterprise Security Platforms
- Vulnerability management with Qualys and Upguard.
- Endpoint Security: CrowdStrike, Jamf, Kandji.
- SIEM & Observability: Datadog.
- WAF and network controls with Cloudflare.
Open Source Contributions
JSScanner
Scans JavaScript files for exposed endpoints and secrets to make reconnaissance faster and more thorough.
ffufplus
Adds extra features and automation on top of FFUF for more flexible web fuzzing.
CVENotifier
Tracks CVE feeds for selected technologies and products.