10+ years in Application Security — VAPT, SAST/DAST, DevSecOps, Threat Modeling and Cloud Security, with 3 credited CVEs. I blend hands-on pentesting with secure-by-design architecture to drive measurable risk reduction across the SDLC.
I'm a Security Architect with 10+ years across the full application-security spectrum: VAPT (web, API, mobile), SAST/DAST/SCA, threat modeling (STRIDE, OWASP ASVS), and DevSecOps pipeline security — backed by cloud security on AWS and Azure and Kubernetes hardening.
What sets me apart is the blend: I don't just review architecture on paper — I attack it. That hands-on pentesting instinct feeds directly into the reference architectures, policy gates and secure-SDLC controls I design, so the defenses I recommend actually hold up against a real adversary.
I lead cross-functional engagements, embed automated security gates into CI/CD, mentor junior engineers, and drive remediation with measurable risk reduction — translating findings into design patterns and actionable user stories that teams ship.
Tools built from real engagement work — the parts that turned out to be reusable, packaged so other people can run them.
74 offensive-security playbooks for AI coding agents — vulnerability classes plus a discipline layer that makes an agent prove a finding instead of asserting one. Ships for Claude Code, Cursor, Copilot, Codex, Gemini, Zed and the AGENTS.md standard. Load-tested on four of them; the rest are format-verified and labelled as such. Open source, MIT.
An offline DAST scanner for air-gapped corporate networks — zero outbound connections, with a multi-identity engine for the access-control bugs generic scanners are structurally blind to.
Fuzzing and confinement for LLM-agent tool loops — treat the model as untrusted, find where the tool-use boundary breaks, then enforce it fail-closed at runtime.
Writeups and methodology at hackz.blog — most recently five ways my own secret scanner lied to me.
B.Tech, Electronics & Communication Engineering — Lakireddy Bali Reddy College of Engineering (2012–2016).
Original vulnerability research responsibly disclosed to vendors and assigned public CVE identifiers via GitHub Security Advisories & MITRE.
Missing per-user authorization on the WireGuard-portal statistics WebSocket — any authenticated user could read every peer's live traffic stats.
Exec injection via unescaped newlines in package-controlled .desktop shortcut fields in conda/menuinst — code execution on install.
Authentication bypass in Supabase database.dev — a forged session JWT escalated an anonymous caller to an authenticated role.
Open to Security Architect & AppSec leadership roles.
Threat modeling, secure-SDLC, DevSecOps enablement, cloud & Kubernetes security, and hands-on VAPT. Reach out and I'll get back within a day.
Email me →