Open to work · Mumbai, India

I'mNadeem

Application SecuritySecurity EngineerRed Team OpsGRC & ComplianceApplication Security
What I do

Security from the exploit
to the audit.

01
Application Security

Break it before an attacker does.

Web, mobile, API, Active Directory, and wireless testing against OWASP Top 10 and API Top 10, with secure code review and threat modeling baked into the SDLC.

  • SAST, DAST, SCA and manual pentest
  • Secure code review at commit-time
  • Threat modeling and architecture review
See the work
02
Security engineering

Build the platform that runs it.

In-house security tooling and automation: a Unified Security Command Center, custom SAST and SCA, external attack-surface monitoring, and pipelines that turn manual work into continuous workflows.

  • DevSecOps in Azure DevOps
  • EASM and threat-intel automation
  • Dashboards and executive reporting
See the work
03
Governance, risk & compliance

Compliance as a program, not a checkbox.

Implementation and audit readiness across ISO 27001, SOC 2, PCI-DSS, GDPR, HIPAA, and DPDPA, with third-party risk, risk registers, and AI governance aligned to ISO 42001.

  • ISO 27001:2022 Lead Auditor
  • 3 internal audits, 30+ vendor assessments
  • ISO 42001 AI governance
Credentials
5+ yrs
in security
70%
fewer critical vulns
6
member team led
15
certifications
Selected work

Unique. Intentional. Shipped.

01 / Flagship platform

Unified Security Command Center

An internal security platform used org-wide, up to the CEO. It unifies application security, SOC, GRC, compliance, vendor management, and threat intelligence into one dashboard, with automated evidence collection, SAST and SCA scans, external attack-surface monitoring, and Azure DevOps sync.

React.jsNext.jsNode.jsPythonAI automation
VoltPhish
02 / Open source

VoltPhish

A self-hosted phishing-simulation and awareness platform. FastAPI and React, shipped as a Docker image.

03 / DevSecOps

Secure SDLC, 150 developers

Embedded SonarQube, Checkov, and ScanCode into Azure DevOps and rolled out threat modeling across three product lines, cutting critical vulnerabilities by roughly 70%.

SonarQubeCheckovAzure DevOps
04 / Offensive find

Critical account-takeover

Surfaced an account-takeover flaw allowing unauthorized password changes across accounts within weeks of joining, then drove containment and remediation.

OWASPAppSec
05 / Writing

Account-takeover write-ups

Vulnerability research on Medium: account takeover via the verification-mail flow, and via a 2FA bypass, explained step by step.

Experience

The track record.

Senior Application Security Engineer · ZI Systech

May 2024 - Present
Mumbai, India · ~250-person software org, ~150 developers · Reports to the CISO · Leads a 6-member team
  • Security leadership: Direct a 6-member team across AppSec, SOC, and GRC, and contribute to security budget decisions.
  • Secure SDLC: Rolled out threat modeling and wired SonarQube, Checkov, and ScanCode into Azure DevOps for ~150 developers.
  • AppSec & IR: Web, mobile, API, AD, and wireless testing; led investigation and RCA for live malware and phishing incidents.
  • GRC: Own audit readiness across ISO 27001, SOC 2, PCI-DSS, GDPR, and HIPAA, plus ~30 vendor risk assessments.

Information & Cyber Security Consultant · CipherBeam Technologies

May 2021 - Mar 2024
Mumbai, India · 8 clients across banking, healthcare, and enterprise
  • VAPT: Web, mobile, and API assessments across 35+ web apps, plus Android and iOS apps for regulated clients.
  • SecOps: Managed 2,000+ endpoints with CrowdStrike, Zscaler, Intune, BitLocker, Qualys, and Nessus.
  • Compliance: Supported ISO 27001, RBI, and SEBI engagements.
Credentials

Certified to audit it,
not just test it.

Fifteen active certifications spanning offensive security, red teaming, AI security, cloud, API testing, and audit.

Certified LLM Security Expert (CLLMSE)Red Team Leaders · 2026
Certified Red Team Operations Mgmt (CRTOM)Red Team Leaders · 2026
HITRUST WorkshopNetwork Intelligence · 2026
Digital Personal Data Protection Act, 2023DPDPA.com · 2026
ISO/IEC 27001:2022 Lead AuditorMastermind · 2025
ISO 27001:2022 Lead Auditor (LA)IRCA · 2024
Certified Ethical Hacker (CEH)EC-Council · 2024
Nessus Fundamentals v2Tenable · 2024
Cyber Threat Intelligence AnalystarcX · 2024
API Penetration TesterAPIsec University · 2023
API Security FundamentalsAPIsec University · 2023
Ethical Hacking Essentials (EHE)EC-Council · 2023
Certified AppSec Practitioner (CAP)The SecOps Group · 2022
Ethical Hacking, Pentesting & Bug Bounty V1EC-Council · 2022
Ethical Hacking, Pentesting & Bug Bounty V2Udemy · 2022
Frameworks & standards
OWASP Top 10 · API Top 10AppSec testing
MITRE ATT&CKThreat modeling
ISO 27001 · SOC 2 · PCI-DSSAudit readiness
ISO 42001 · NIST CSF · ISO 27005Risk & AI governance
GDPR · HIPAA · DPDPA · RBI · SEBIData & finance
Education

BSc, Information Technology

Maharashtra College of Science, Arts and Commerce.

CGPA8.88
Contact

Let's talk security.

Open to senior application-security, security-engineering, and GRC roles. I read every message personally.

Email me LinkedIn GitHub