Security Portfolio AVAILABLE FOR WORK
cr@sh0verr!d3
OT/ICS · APPLICATION SECURITY · PENETRATION TESTING · THREAT MODELING · SECURE-BY-DESIGN
// BACKGROUNDWHO_AM_I

I'm Shail — a self-starter with an early passion for technology. I began exploring systems, dissecting websites, modifying games, and troubleshooting computers as far back as my high school years. What started as pure teenage curiosity has evolved into a rewarding full-time career in cybersecurity.

Today, as a seasoned security professional, I've delivered impact across government and private-sector organizations spanning multiple industry verticals, with a proven track record in web and OT security. With broad experience across various domains of cybersecurity, I specialize in the deep technical work: threat modeling, penetration testing, and designing security pipelines that seamlessly embed security into the development lifecycle.

A passionate advocate for Secure-by-Design principles, I build robust automation guardrails and intelligent security controls that eliminate manual friction, minimize human error, and create self-sustaining systems. This enables teams to move faster and focus on the complex, high-impact challenges that drive real innovation and business value.

// RESUMEEXPERIENCE
2024—NOW Senior Application Security Engineer Domo · Full-time
  • Conduct design and architecture reviews for critical services and features, identifying and mitigating vulnerabilities to ensure robust, scalable, and secure system architectures.
  • Collaborate with cross-functional engineering teams to embed security best practices across all phases of the SDLC, fostering a security-first culture through training sessions and leading Domo's security champions program.
  • Influence senior leadership by presenting actionable security strategies and risk assessments, securing buy-in for organization-wide initiatives and resource allocation.
  • Mentor junior AppSec team members, providing expert guidance when they encounter challenges in their security reviews.
  • Perform in-depth secure code reviews across diverse codebases, leveraging static analysis to identify and remediate vulnerabilities — reducing security defects by 67% in production.
  • Lead threat modeling sessions for high-risk features, proactively identifying attack vectors and implementing countermeasures against sophisticated threats.
  • Develop security automation workflows (including AI-driven) and custom tooling for SAST/DAST/SCA, streamlining detection and remediation to boost operational efficiency by 80%.
  • Orchestrated a vulnerability management program, prioritizing and remediating critical vulnerabilities across enterprise systems — reducing mean time to resolution by 43%.
  • Evaluated 8+ bug bounty vendors, ran PoCs, coordinated onboarding, and designed and now manage a high-impact bug bounty program — triaging external submissions and driving 30+ critical vulnerabilities to resolution while maintaining strong researcher engagement.
  • Execute manual and AI-driven vulnerability assessments on internal and external applications, delivering detailed reports and remediation plans aligned to OWASP, SOC 2, ISO 27001, and HITRUST.
  • Coordinate with third-party pentest vendors, triage their findings, and conduct rigorous penetration testing on mission-critical applications and infrastructure.
  • Coordinate with the Governance, Risk & Compliance (GRC) team to provide evidence, and support recruitment and interviewing for security roles across the organization.
2022—2024 Security Consultant Self-Employed
  • Delivered high-impact security consulting to top-tier clients — hedge funds, venture capital firms, and investor companies — offering strategic guidance on application security, risk management, and compliance.
  • Empowered clients to make informed investment decisions with actionable insights into cybersecurity posture, reducing risk exposure for portfolios valued at over $500M.
  • Conducted web penetration testing and application security assessments for small businesses, identifying and mitigating critical vulnerabilities such as SSRF and SQL injection.
  • Implemented tailored security recommendations that strengthened system resilience while enabling clients to safeguard sensitive data and maintain customer trust.
2021—2022 Application Security Engineer Accolade, Inc.
  • Conducted security design and architecture reviews for critical services and features to ensure robust, scalable, secure architectures.
  • Collaborated with cross-functional engineering teams to embed security into the SDLC, fostering a security-first culture through training sessions.
  • Influenced leadership with actionable security strategies and risk assessments, securing buy-in for organization-wide initiatives.
  • Performed in-depth secure code reviews leveraging static analysis — reducing security defects by 40% in production.
  • Led threat modeling sessions for high-risk features and implemented countermeasures against sophisticated threats.
  • Developed security automation workflows and custom tooling for SAST/DAST/SCA, improving operational efficiency by 55%.
  • Configured and managed AWS security services — WAF, GuardDuty, Security Hub, Inspector, Shield, Secrets Manager, and Cognito.
  • Managed a high-impact bug bounty program, triaging and validating external submissions to drive resolution of critical and high-severity vulnerabilities.
  • Executed vulnerability assessments and delivered remediation plans aligned to OWASP, SOC 2, ISO, and HITRUST.
  • Coordinated with external pentest vendors, triaged findings, and conducted penetration testing on mission-critical applications and infrastructure.
  • Coordinated with the Governance, Risk & Compliance (GRC) team to provide evidence.
2020—2021 Application Security Engineer FormAssembly
  • Conducted security design and architecture reviews for critical services and features.
  • Embedded security best practices into the SDLC through cross-team collaboration and training sessions.
  • Influenced leadership with actionable security strategies and risk assessments, securing buy-in for organization-wide initiatives.
  • Performed in-depth secure code reviews leveraging static analysis — reducing security defects by 79% in production.
  • Led threat modeling sessions for high-risk features and implemented countermeasures.
  • Developed security automation workflows and custom tooling for SAST/DAST/SCA.
  • Configured and managed AWS security services — WAF, GuardDuty, Security Hub, Inspector, Shield, Secrets Manager, and Cognito.
  • Managed a Vulnerability Disclosure Program (VDP), triaging and validating external submissions.
  • Executed vulnerability assessments and delivered remediation plans aligned to OWASP, SOC, and ISO standards.
  • Coordinated with external pentest vendors, triaged findings, and conducted penetration testing on web applications and services.
  • Coordinated with the GRC team and supported recruitment and interviewing for security roles.
  • Tuned EDR, wrote incident response playbooks, and built detection capabilities using open-source tools like Wazuh for SOC activities.
2019—2020 Energy Cyber-Physical Systems Security Researcher National Renewable Energy Laboratory (NREL)
  • Conducted research on smart-grid network architecture, including penetration testing with open-source tools; addressed weaknesses in protocols such as Modbus and DNP3 and implemented mitigations.
  • Performed vendor device security assessments (Schneider Electric, Varentec) and recommended posture improvements.
  • Built the network infrastructure and configured KVMs, servers, firewalls, and switches for the Cyber-Energy Emulation Platform (CEEP).
  • Deployed Zeek and Snort on the platform controller and implemented Elasticsearch, Logstash, and Kibana to monitor cyber and power logs from the IDS.
  • Deployed Ansible and bash scripts for baseline security automation of CEEP and orchestrated GitLab CI/CD pipelines to spin up Nextcloud, Docker, and Kubernetes services.
  • Performed system-level hardening, vulnerability assessments, and threat modeling on CEEP.
  • Wrote IT/ICS/OT exploits, vulnerabilities, and anomalies as part of the technical committee for the DOE CyberForce Competition (2019 & 2020).
  • Evaluated SDN-enabled obfuscation / moving-target defense for wide-area communication (SDN4EDS project).
  • Devised attacking strategies and led 22 Red Team volunteers as Red Team Lead for the DOE CyberForce Competition.
2019 Graduate Teaching Assistant UNC Charlotte — Secure Programming & Penetration Testing
  • Teaching Assistant for the Secure Programming and Penetration Testing class in the Cybersecurity department.
  • Mentored 98 undergraduate and graduate students, holding weekly TA hours to help with their queries.
  • Designed new assignments, projects, and quizzes for the class.
  • Taught labs and graded assignments, projects, midterms, and final exams.
Threat ModelingPenetration Testing Application SecuritySecure Code Review SAST / DAST / SCAOT / ICS Security AWS SecurityVulnerability Management Bug Bounty & VDPPython JavaBash / PowerShell Burp SuiteCodeQL SonarQube · SnykWiz IriusRisk · Threat DragonWazuh Docker · CI/CDELK Stack
DOWNLOAD CV
// CREDENTIALSEDU · CERTS · RECOGNITION · PUBLICATION
Education
M.S. Cyber Security — University of North Carolina at Charlotte · GPA 3.94 / 4.0 DEC 2019
B.E. Electronics & Telecommunication — University of Mumbai · GPA 7.5 / 10 MAY 2017
Certification
AccessData Certified Examiner (ACE) OCT 2018
Recognition & Speaking
Judge — Globee® Awards for Cybersecurity 2025—2026
Author — CVE-2020-27388 2020
Red Team Lead — DOE CyberForce Competition (NREL) 2019 & 2020
Speaker — ROOTCON, GrayHat & BSides Philly 2020
Volunteer — DEF CON 32 AppSec Village · DC303 2019—2024
Publication
Software Defined Networking for Energy Delivery Systems (SDN4EDS) ↗ · Cybersecurity of Energy Delivery Systems (CEDS) Research and Development 2020
// BLOGWRITE-UPS
01 Journey with Telekom's Security / Bug Bounty Program — Pros and Cons AUG 2026 · DRAFT — CONTENT COMING SOON