Summary
Overview
Work history
Education
Skills
SECURITY RESEARCH & TOOL DEVELOPMENT
LANGUAGES
Certification
Timeline
Generic
Suraj Bhosale

Suraj Bhosale

Dubai,United Arab Emirates

Summary

Accomplished Cyber Security leader with over 10 years' experience in developing and scaling application security programmes and driving DevSecOps transformation across banking, fintech, and healthcare sectors. Specialises in AI/ML security, AWS cloud-native security, and offensive security automation, with multiple CVEs and Hall of Fame credits. Ensures compliance with OWASP, NIST, PCI-DSS, ISO 27001, GDPR, and NESA.

Overview

1
1
Certification
4
4
years of post-secondary education
11
11
years of professional experience

Work history

LEAD SECURITY ENGINEER

Forward Defense
Dubai
2023.10 - 2026.07

Lead enterprise application security for one of the UAE's largest banking groups — guiding security strategy, managing cross-functional stakeholder relationships, and driving DevSecOps adoption across multiple business units.

  • Lead application security initiatives across multiple business units, setting testing standards, defining risk acceptance criteria, and driving remediation accountability with engineering and product leadership.
  • Conduct Security Architecture Reviews, threat modeling (STRIDE), and secure design assessments across web, mobile, API, microservices, and cloud platforms.
  • Execute SAST (Checkmarx, Semgrep, Fortify), DAST (Burp Suite Pro, OWASP ZAP), SCA (Snyk, BlackDuck), and manual penetration testing for internet and intranet-facing applications.
  • Design and enforce DevSecOps controls integrating SAST, DAST, dependency scanning, container scanning, and secrets detection into CI/CD pipelines.
  • Perform AWS cloud security assessments (IAM, S3, Lambda, API Gateway, EKS) and integrate AWS Inspector, Security Hub, and AWS Config into DevSecOps pipelines for continuous compliance.
  • Assess AI/ML security risks for LLM-powered banking applications (prompt injection, model poisoning, adversarial inputs) aligned with OWASP Top 10 for LLM and MITRE ATLAS.
  • Manage vulnerability risk registers, produce executive security reports, drive remediation roadmaps, and support regulatory compliance and audit initiatives.

Application Security Lead

Paytm (One97 Communications)
Mumbai
2022.04 - 2023.10
  • Led application security for India's largest fintech platform (350M+ users) across payments, wallets, merchant portals, and APIs.
  • Integrated SAST, DAST, and dependency scanning into Jenkins/AWS CodePipeline CI/CD; conducted AWS security reviews (EC2, S3, IAM, RDS, VPC).
  • Led team of security engineers, assigning assessments and reviewing deliverables while mentoring on OWASP methodology and secure code review to enhance overall application security.
  • Defined testing standards, vulnerability severity matrices, and remediation SLAs adopted organization-wide.
  • Oversaw bug bounty triage, managing payouts and escalating critical findings to leadership with root cause analysis to ensure timely resolution of security issues.
  • Established security KPI dashboards and reported risk reduction metrics to senior leadership monthly, providing insights for informed decision-making on security posture.
  • Reviewed AI/ML fraud detection models for adversarial manipulation and data poisoning risks.

APPLICATION SECURITY MENTOR – SECURITY CHAMPION LEAD

eClinicalWorks
Mumbai
2020.01 - 2022.04
  • Established application security programme from scratch for global healthcare SaaS platform, enhancing overall security posture.
  • Designed and implemented secure SDLC framework including coding standards, pre-production security gates, and developer training curriculum.
  • Mentored 40+ developers by creating security champions programme, embedding security ownership across 5 product teams to foster a culture of security.
  • Authored security policies, coding guidelines, and vulnerability management procedures adopted organization-wide.
  • Integrated SAST, dependency scanning, and IaC security scanning (Checkov, tfsec) into GitLab CI/CD and AWS CodeBuild, streamlining secure development processes.
  • Conducted AWS security architecture reviews for HIPAA-eligible services (encryption, IAM, VPC isolation, CloudTrail).
  • Evaluated AI/ML model security for clinical decision support systems (model explainability, training data confidentiality).

ASSOCIATE CONSULTANT – PENETRATION TESTING

ControlCase International
Mumbai
2016.08 - 2020.01
  • Delivered 50+ full-scope penetration testing engagements across web, mobile, API, network, and cloud environments for global banking, fintech, and SaaS clients – building the hands-on exploitation foundation that now drives strategic security leadership.
  • Performed black-box, grey-box, and white-box assessments, manually exploiting SQL injection, XSS, authentication bypass, RCE, privilege escalation, and business logic flaws across complex multi-tier architectures.
  • Executed network and infrastructure penetration testing including firewall rule reviews, VPN security assessments, internal network segmentation testing, and Active Directory security audits.
  • Acted as primary technical point of contact for multiple banking and fintech clients, managing engagement scoping, presenting findings to client leadership, and guiding development teams through remediation processes.
  • Prepared detailed vulnerability reports featuring CVSS/DREAD risk ratings, business impact analysis, and prioritised remediation roadmaps to support PCI-DSS and ISO 27001 compliance.
  • Facilitated full remediation lifecycles for clients, including re-testing, security control validation, and collection of compliance evidence for audit readiness.
  • Mentored junior penetration testers on exploitation methodology, report writing standards, and client communication – laying the foundation for team leadership in later roles.
  • Validated automated scan results (Nessus, Nexpose, OpenVAS), eliminated false positives, and performed manual verification to ensure high-quality deliverables.

TECHNICAL SUPPORT ENGINEER – SECURITY

Know-All-Edge
Mumbai, India
2015.10 - 2016.04
  • Provided technical security support to enterprise customers, translating complex security concepts into actionable guidance for IT teams and business stakeholders, facilitating informed decision-making.
  • Configured, deployed, and maintained WatchGuard firewalls, VPN gateways, and endpoint security solutions across client sites.
  • Implemented secure network segmentation, access control policies, and RBAC configurations to enforce least-privilege principles.
  • Investigated and responded to security incidents, including unauthorized access attempts and malware outbreaks, conducting root cause analysis to prevent future occurrences.
  • Managed enterprise security infrastructure across multiple client environments, enhancing resilience against security threats.

Education

Bachelor of Engineering - Computer Engineering

Nagpur University
India
2008.07 - 2012.03

Skills

  • Web & Mobile App Security API Security AWS Cloud Security AI/ML security Container/Kubernetes Security DevSecOps Threat modelling Risk Management Incident response
  • Checkmarx, Fortify, Semgrep, Veracode (SAST) Burp Suite Pro, OWASP ZAP (DAST) Snyk, Black Duck (SCA) Trivy, Sysdig, Docker Bench (Container) Nessus, Nuclei AWS Inspector, Security Hub, GuardDuty, CloudTrail Jenkins, GitLab CI/CD, GitHub Actions Splunk, ELK Python, Bash, PowerShell, Go
  • Security management Team Leadership & Mentoring Policy development Stakeholder engagement Executive communication Vendor assessment Compliance frameworks

SECURITY RESEARCH & TOOL DEVELOPMENT

  • XSS Scanner – Go + Playwright
  • (github.com/cybertron10/xss-scanner-minimal) – Custom headless browser-based scanner for DOM-based and reflected XSS with WAF bypass, concurrent crawling, and JSON reporting. Used for enterprise testing and bug bounty hunting.

LANGUAGES

English (Advanced) | Hindi (Advanced) | Marathi (Native)

Certification

  • -
  • EWPTXv2
  • - eLearnSecurity Web Application Penetration Tester eXtreme
  • CVE-2021-28294, CVE-2021-28295
  • – Discovered and responsibly disclosed
  • Hall of Fame & Bounty
  • - Google, Dell, Twilio, Alibaba, GSA, U.S. DoD, IBM, AT&T, and more

Timeline

LEAD SECURITY ENGINEER

Forward Defense
2023.10 - 2026.07

Application Security Lead

Paytm (One97 Communications)
2022.04 - 2023.10

APPLICATION SECURITY MENTOR – SECURITY CHAMPION LEAD

eClinicalWorks
2020.01 - 2022.04

ASSOCIATE CONSULTANT – PENETRATION TESTING

ControlCase International
2016.08 - 2020.01

TECHNICAL SUPPORT ENGINEER – SECURITY

Know-All-Edge
2015.10 - 2016.04

Bachelor of Engineering - Computer Engineering

Nagpur University
2008.07 - 2012.03
Suraj Bhosale