Piyush Kumawat
Securing enterprise software, GenAI/LLM pipelines, and multi-cloud architectures. 7+ years of battle-tested offensive testing, DevSecOps automation, and threat defense.

01 // EXECUTIVE DOSSIER
Know Me More
Staff Product Security Engineer specializing in offensive security, GenAI/LLM threat defense, and DevSecOps pipelines.
I'm Piyush Kumawat, a Product Security Engineer
Product Security Engineer with a background in penetration testing. I have tested over 250+ applications across web, mobile, and API surfaces. Experienced in threat modeling, DevSecOps tooling, and cloud security reviews across Azure, AWS, GCP, and Alibaba Cloud.
I am passionate about ensuring the security of products and dedicated to staying up-to-date with the latest industry trends and techniques.
AI & LLM Security Leadership
Pioneering GenAI threat defense: prompt injection, MCP agent sandboxing, tool permissions, and OWASP Top 10 for LLM Applications at Harness.
Full-Spectrum Penetration Testing
Audited 250+ applications across web, mobile (iOS/Android), REST/GraphQL APIs, and multi-cloud (AWS, Azure, GCP, Alibaba Cloud).
Enterprise DevSecOps Architecture
Zero-friction CI/CD security guardrails: SAST, SCA, container scanning with policy-as-code gates and automated false-positive suppression.
02 // TECHNICAL ARSENAL
My Skills & Specialties
Battle-tested capability across offensive exploitation, automated pipelines, GenAI protection, and multi-cloud security architecture.
Web application penetration testing
Since 2017
API and web service testing
REST, GraphQL, SOAP
Source code review
SAST plus manual review
Android and iOS testing
Static and dynamic
Cloud configuration review
AWS, Azure, GCP
DevSecOps
CI/CD guardrails
Threat modeling
STRIDE on product designs
Bug bounty program operations
Triage and retest
03 // WEAPONRY & TOOLING
Tools I Use
A battle-hardened toolkit across offensive penetration testing, SAST/DAST/SCA scanners, mobile reversing, container orchestration, and cloud infrastructure.
04 // RESPONSIBLE DISCLOSURE
Hall of Fame
Acknowledgements from security programs where responsible disclosures helped protect enterprise platforms and products worldwide.
05 // CAREER TRAJECTORY
Work Experience
7+ years driving product security, building scalable DevSecOps programs, and leading GenAI/LLM threat defense.
May 2024 - Present
★ CURRENT ROLE · STAFF LEVELStaff Product Security Engineer
Harness
Staff Product Security Engineer
- Perform threat modelling, SAST, DAST, and SCA across Harness products to secure the software development lifecycle.
- Own DevSecOps guardrails in CI/CD - SAST, SCA, secrets, and container scanning wired into build pipelines with policy-as-code gates and risk-based exceptions.
- Tune scanner rules and triage automation to cut false positives, so a failed pipeline means a real, exploitable issue.
- Lead AI and LLM security reviews for Harness AI features - prompt injection, insecure output handling, excessive agency, and context or training data leakage, mapped to the OWASP Top 10 for LLM Applications.
- Threat model AI agents, MCP integrations, and model APIs, then set guardrails for tool permissions, sandboxing, and prompt and response logging.
- Run vulnerability management end to end - intake from scanners, bug bounty, and pentests into one deduplicated backlog with severity-based SLAs and named owners.
- Report security posture metrics such as SLA compliance, mean time to remediate, and backlog burn-down to engineering leadership, and drive overdue findings to closure.
- Run and mature the Harness bug bounty programme, validating reports and reducing real-world risk.
- Conduct manual and automated security assessments across web, API, and cloud mapped to OWASP Top 10, MITRE ATT&CK, and business logic risks.
- Define and enforce security requirements, policies, and release gates across the SDLC.
- Work closely with developers to remediate findings and embed secure-by-design practices early in the lifecycle.
- Mentor engineers and security team members to raise the security bar across the organisation.
Jan 2022 - May 2024Product Security Engineer
OLA
Product Security Engineer
- Performed threat modelling, DAST, and SAST on web applications across OLA business groups (Mobility, Electric, Money, Avail Finance, and more).
- Ran web application security assessments for OWASP Top 10, MITRE ATT&CK, and business logic vulnerabilities.
- Managed the OLA bug bounty process and triaged researcher submissions.
- Performed white-box tests and removed false positives from automated scans.
- Worked with developers to remediate findings and mapped risks by business criticality.
- Raised detailed Jira tickets with reproduction steps, remediation guidance, and evidence.
- Conducted retests to verify closure of security risks across web, API, and mobile assessments.
- Supported GDPR and PCI-DSS audit dependencies on application security.
Jun 2019 - Jan 2022Security Services Associate Consultant
Synopsys
Security Services Associate Consultant
- Performed DAST and web application security assessments for OWASP Top 10, MITRE ATT&CK, and business logic issues.
- Ran scans with Burp Suite, Nessus, AppScan, Metasploit, SqlMap, Nmap, OpenVAS, Dirb, Nikto, and related tooling.
- Performed black-box and grey-box security tests and removed false positives.
- Provided executive reports with technical summaries and remediation recommendations.
- Configured DevSecOps tooling such as Checkmarx, WhiteSource, and Burp in CI/CD environments.
- Performed cloud configuration reviews on AWS, Azure, GCP, and Alibaba Cloud.
- Sent daily vulnerability updates and supported parallel revalidation during active tests.
Jan 2019 - May 2019Cyber Security Intern
Synopsys Inc.
Cyber Security Intern
- Learned penetration testing fundamentals, application stacks, and OWASP Top 10 in web environments.
- Automated open-source and commercial SAST, SCA, and DAST tools in Jenkins pipelines for efficient security scanning.
Mar 2017 - Apr 2017System / Network Admin Intern
Shah Technical Consultants Pvt. Ltd.
System / Network Admin Intern
- Managed network and server infrastructure for the organisation.
- Provided proactive solutions for technically challenging operational problems.
06 // SECURITY INTELLIGENCE
Latest From My Blog
AI-Generated Code Security Bugs: A Vibe Coding Case Study
Vibe-coding a pentest findings dashboard, then reading the helpers: f-string SQL, no owner check, a token in source, MD5, a…
Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
Practical cloud misconfig bounty playbook: wordlist probing, open S3/GCS/Azure listings, Firebase dumps, nuclei, and gitleaks on PoC dumps - with…
DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
How software travels from a developer's editor to a live server - and where security checks sit along the way.…
07 // TRANSMISSION CHANNELS
Let's Connect
Open to Staff AppSec leadership, GenAI/LLM security consulting, advisory, and technical collaboration.