th3m0nk

Senior Security Engineer

I am a Senior Security Engineer with 6 years of experience across product security, application security, secure code review, threat modeling, adversarial testing, DevSecOps, and third-party security reviews. My work has focused on reducing real-world exploitability by going beyond scanner output: reviewing design and code, validating reachability, building security automation, running cyber drills with engineering and SRE teams, and helping leadership understand where risk actually exists.

At PhonePe, I am part of the Product Security function, where I work on secure code reviews for internal applications, DevSecOps visibility for engineering leadership, pre-commit controls to prevent secret leakage, third-party security reviews, and security readiness exercises. I have also built automated red-team agents for Linux and Windows environments to surface credentials, tokens, misconfigurations, and risky artifacts across infrastructure.

Before PhonePe, I worked as a Senior Security Consultant and Red Team Specialist, including consulting work for VMware. I have led secure code review programs, built threat models for enterprise products, executed penetration tests across web, cloud, network, and Windows AD environments, and mentored security engineers.

# What I Am Looking For

I am looking for product security roles in Web3 where I can build, scale, or lead the product security function. My goal is to join an engineering-focused organization where security is treated as a product and architecture problem, not just a compliance or audit checklist.

I am especially interested in roles where I can:

- Build a strong product security program from the ground up or mature an existing one.
- Own secure design reviews, threat modeling, and code review for high-impact product areas.
- Work closely with engineering leaders, architects, protocol teams, backend engineers, DevOps, and SRE teams.
- Improve vulnerability visibility through reachability analysis, risk-based prioritization, and practical DevSecOps automation.
- Design guardrails that reduce classes of bugs before code reaches production, including secrets prevention, CI/CD security checks, and dependency governance.
- Review Web3 integrations, wallets, smart contract adjacent systems, signing flows, custody flows, bridges, APIs, and third-party vendors.
- Run security drills and incident-readiness exercises so engineering teams know how to respond under pressure.
- Help the organization make better security decisions during product design, vendor onboarding, and launch readiness.

The role I am aiming for is one where I can be hands-on technically while also creating the structure, processes, and security culture needed for a strong product security function. I want to partner with engineering teams, not slow them down, and help build products that are secure by design, resilient in production, and trusted by users.



Experience: 6 years

Yearly salary: $104,000

Hourly rate: $50

Nationality: 🇮🇳 India

Residency: 🇮🇳 India


Experience

Senior Security Engineer
Phonepe
2024 - 2026
Part of the Product Security function, handling secure code reviews and deep-dive assessments for internal applications. • Drive DevSecOps initiatives that give Heads of Engineering visibility into vulnerable engineering functions, in- cluding first-level reachability analysis to prioritize exploitable risk. • Set up pre-commit hooks to prevent secrets from being pushed into version control and reduce credential leakage at source. • Lead automated red-team program discovering security artifacts (credentials, misconfigurations, tokens) across production and staging environments; developed maintainable Linux and Windows agents for continuous Auto- mated Red Teaming. • Integrated SAML into Caldera for continuous red-teaming, rewriting the SAML plugin so authentication can be managed by the IdP. • Conduct security drills with Engineering and SRE teams to assess readiness and produce actionable incident- response runbooks. • Conduct third-party security reviews for companies integrating with PhonePe; prevented multiple potential data- breach scenarios and identified breached vendors before onboarding. • Work with senior architects and HoEs to solve emerging security pain points across their charters.
Senior Security Consultant
Traboda Cyberlabs
2020 - 2024
• Executed penetration tests and security assessments across web applications, cloud infrastructure, networks, Win- dows AD, delivered reproducible PoCs with developer-focused remediation guidance • Lead secure code review program for 15+ enterprise products, identified and mitigated critical flaws achieving 30% reduction in CVSS 9+ vulnerabilities • Architected threat models for secure application design conducted threat modeling assessments for VMware en- terprise software products • Developed and delivered comprehensive VAPT training curriculum to 100+ participants; trained 20+ government personnel on advanced exploitation and evasion techniques • Created CVE exploit proofs-of-concept maintained vulnerability tracking and emerging threat intelligence via CVE databases and dark-web research • Recruited, trained, and mentored red-team specialists established engagement methodologies and quality standards across parallel assessments

Skills

architecture
assembly
python
security
english