Skip to content

Shantanu Ghumade

>

Cyberjaya, Malaysia
OSCP & OSWE Certified

Contact Information

Summary

Security Tech Lead with 6+ years of hands-on work across AppSec, cloud security, and DevSecOps. I focus on making security practical for engineering teams: reviewing code and architecture, building CI/CD guardrails, hardening cloud environments, and turning repeatable security work into useful automation. Lately, that has included AI-driven tooling for threat intelligence, triage, and policy workflows.

Certifications

Work Experience

Deriv, Malaysia

Security Tech Lead - Security Assurance

Apr 2026 – Present
  • Lead security assurance work across application security, cloud security, DevSecOps, and AI-assisted security automation.
  • Work with product and engineering teams on security reviews, automation strategy, and practical risk reduction.
  • > AI & Security Automation
    • Threat Feed Automation: Built an AI-driven threat intelligence feed mapped to the internal tech stack, helping surface relevant risks earlier.
    • Security Assistant: Developed an internal RAG-based assistant that answers employee security questions from Information Security policies and internal process docs.
    • HackerOne Triage Bot: Designed an automated HackerOne prescreening agent to cut down manual triage effort and improve initial response time.
    • Vendor Prescreening: Automated third-party vendor prescreening with LLM-assisted research and risk flagging.
    • Compliance Gap Analysis Framework: Created an AI-powered framework for comparing internal policies against regulatory requirements.

Deriv, Malaysia

Senior Security Engineer

Jan 2023 – Apr 2026
  • Led end-to-end security assessments for web, mobile, API, network, and cloud products, including secure code and architecture reviews.
  • Improved cloud security posture with CIS-aligned hardening across 20+ AWS accounts and 20+ GCP projects.
  • Reviewed Perl, Node.js, Python, Go, React.js, and Flutter code to catch vulnerabilities earlier in the delivery cycle.
  • Owned and scaled DevSecOps adoption, including pre-commit hooks and organization-wide secret prevention controls.
  • Built and maintained CI/CD security pipelines with SAST, SCA, IaC scanning, and secret detection.
  • Managed Deriv’s HackerOne bug bounty program end to end, improving triage workflows and researcher engagement.
  • Used CrowdStrike EDR and Datadog SIEM for threat detection, incident response, and proactive threat hunting.
  • Owned incident response investigations, correlating logs across platforms, finding root causes, and putting safeguards in place to reduce repeat issues.
  • > Detection & Incident Response
    • Performed threat detection and hunting with CrowdStrike EDR and Datadog SIEM.
    • Led incident response investigations, root-cause analysis, and follow-up control improvements.
    • Reversed malware from a campaign where a fake AI recruiter on LinkedIn lured developers into a private GitHub repository.
      Read Article

SecureLayer7, Pune, India

Lead Security Consultant

Feb 2022 – Jan 2023
  • Led end-to-end security testing engagements for global clients in finance, technology, and payment solutions.
  • Chosen for critical on-site international engagements, including infrastructure penetration tests for high-value clients.
  • Translated complex vulnerability findings into clear remediation plans for executive stakeholders.
  • Earned two promotions within three years by consistently delivering strong assessments and client outcomes.
  • Presented a webinar on mobile application security
    Watch Webinar

Security Consultant

Feb 2021 – Feb 2022
  • Performed in-depth source code analysis and mobile application penetration testing for Android and iOS.
  • Ran internal sessions on topics including "Fuzzing HTTP Requests" and "HTTP request smuggling."

Associate Security Consultant

Feb 2020 – Feb 2021
  • Conducted 50+ web application, API, and network vulnerability assessments.
  • Reported vulnerabilities found through manual and automated VAPT testing with clear reproduction steps and remediation guidance.

Technical Skills

Application Security & Pentesting

  • Security assessments across web, mobile (Android/iOS), API, network, and cloud environments.
  • Tools: Burp Suite, Postman, MobSF, Frida, Nmap, Metasploit.
  • Secure code review and architecture review.

Cloud Security

  • AWS, GCP, and Alibaba Cloud hardening and configuration review.
  • SCP policy implementation and public exposure reduction.
  • Automated cloud security posture management (CSPM).

DevSecOps & Automation

  • CI/CD security integrations for SAST, DAST, IaC, and secret scanning.
  • Custom tooling, including Nuclei templates and subdomain monitoring.
  • LangChain-based automation for threat intelligence and triage.

Enterprise Security Platforms

  • Vulnerability management with Qualys and Upguard.
  • Endpoint Security: CrowdStrike, Jamf, Kandji.
  • SIEM & Observability: Datadog.
  • WAF and network controls with Cloudflare.

Open Source Contributions

Bug Bounty

Synack

Red Teamer

Level 2

HackerOne

BugCrowd

CTF Profile

Publications

Education

Designed with Next.js, Framer Motion & TailwindCSS

© 2026 Shantanu Ghumade. All rights reserved.