Open to Staff Security Roles & Advisory

Piyush Kumawat

Staff Product Security Engineer · Harness

Securing enterprise software, GenAI/LLM pipelines, and multi-cloud architectures. 7+ years of battle-tested offensive testing, DevSecOps automation, and threat defense.

Staff AppSec Engineer
Portrait of Piyush Kumawat
⚡ Harness · AI & DevSecOps
LOCATION India / Remote
EXPERIENCE 7+ Years
VULNS FOUND 1,000+
01 // EXPERIENCE
7+
Years of Experience
Years of Security Leadership
02 // AUDITS
250+
Security Projects Completed
Security Projects Audited
03 // DISCOVERIES
1000+
Security Issues Reported
Security Issues Remediated
04 // CREDENTIALS
4
Certifications
Industry Certifications

01 // EXECUTIVE DOSSIER

Know Me More

Staff Product Security Engineer specializing in offensive security, GenAI/LLM threat defense, and DevSecOps pipelines.

I'm Piyush Kumawat, a Product Security Engineer

Product Security Engineer with a background in penetration testing. I have tested over 250+ applications across web, mobile, and API surfaces. Experienced in threat modeling, DevSecOps tooling, and cloud security reviews across Azure, AWS, GCP, and Alibaba Cloud.

I am passionate about ensuring the security of products and dedicated to staying up-to-date with the latest industry trends and techniques.

🤖

AI & LLM Security Leadership

Pioneering GenAI threat defense: prompt injection, MCP agent sandboxing, tool permissions, and OWASP Top 10 for LLM Applications at Harness.

🛡️

Full-Spectrum Penetration Testing

Audited 250+ applications across web, mobile (iOS/Android), REST/GraphQL APIs, and multi-cloud (AWS, Azure, GCP, Alibaba Cloud).

⚙️

Enterprise DevSecOps Architecture

Zero-friction CI/CD security guardrails: SAST, SCA, container scanning with policy-as-code gates and automated false-positive suppression.

02 // TECHNICAL ARSENAL

My Skills & Specialties

Battle-tested capability across offensive exploitation, automated pipelines, GenAI protection, and multi-cloud security architecture.

🌐 STAFF LEVEL

Web application penetration testing

Since 2017

98%
⚡ STAFF LEVEL

API and web service testing

REST, GraphQL, SOAP

95%
🔍 STAFF LEVEL

Source code review

SAST plus manual review

92%
📱 STAFF LEVEL

Android and iOS testing

Static and dynamic

88%
☁️ STAFF LEVEL

Cloud configuration review

AWS, Azure, GCP

90%
⚙️ STAFF LEVEL

DevSecOps

CI/CD guardrails

94%
🎯 STAFF LEVEL

Threat modeling

STRIDE on product designs

96%
🏆 STAFF LEVEL

Bug bounty program operations

Triage and retest

93%

03 // WEAPONRY & TOOLING

Tools I Use

A battle-hardened toolkit across offensive penetration testing, SAST/DAST/SCA scanners, mobile reversing, container orchestration, and cloud infrastructure.

Burp Suite
Nmap
Metasploit
Nessus
HCL AppScan
OWASP ZAP
Nuclei
Semgrep
Checkmarx
Snyk
GitHub Advanced Security
MobSF
Frida
Postman
Wireshark
Trivy
Kali Linux
Terraform
Kubernetes
Docker
Jenkins
GitHub Actions
AWS
Microsoft Azure
Google Cloud

04 // RESPONSIBLE DISCLOSURE

Hall of Fame

Acknowledgements from security programs where responsible disclosures helped protect enterprise platforms and products worldwide.

✓ CERT RECOGNIZED
✓ RESPONSIBLE DISCLOSURE
✓ RESPONSIBLE DISCLOSURE
✓ RESPONSIBLE DISCLOSURE
✓ RESPONSIBLE DISCLOSURE
✓ RESPONSIBLE DISCLOSURE
✓ RESPONSIBLE DISCLOSURE

05 // CAREER TRAJECTORY

Work Experience

7+ years driving product security, building scalable DevSecOps programs, and leading GenAI/LLM threat defense.

May 2024 - Present ★ CURRENT ROLE · STAFF LEVEL

Staff Product Security Engineer

🏢 Harness
AI / LLM Security DevSecOps Gates Policy as Code Bug Bounty Lead Threat Modeling
  • Perform threat modelling, SAST, DAST, and SCA across Harness products to secure the software development lifecycle.
  • Own DevSecOps guardrails in CI/CD - SAST, SCA, secrets, and container scanning wired into build pipelines with policy-as-code gates and risk-based exceptions.
  • Tune scanner rules and triage automation to cut false positives, so a failed pipeline means a real, exploitable issue.
  • Lead AI and LLM security reviews for Harness AI features - prompt injection, insecure output handling, excessive agency, and context or training data leakage, mapped to the OWASP Top 10 for LLM Applications.
  • Threat model AI agents, MCP integrations, and model APIs, then set guardrails for tool permissions, sandboxing, and prompt and response logging.
  • Run vulnerability management end to end - intake from scanners, bug bounty, and pentests into one deduplicated backlog with severity-based SLAs and named owners.
  • Report security posture metrics such as SLA compliance, mean time to remediate, and backlog burn-down to engineering leadership, and drive overdue findings to closure.
  • Run and mature the Harness bug bounty programme, validating reports and reducing real-world risk.
  • Conduct manual and automated security assessments across web, API, and cloud mapped to OWASP Top 10, MITRE ATT&CK, and business logic risks.
  • Define and enforce security requirements, policies, and release gates across the SDLC.
  • Work closely with developers to remediate findings and embed secure-by-design practices early in the lifecycle.
  • Mentor engineers and security team members to raise the security bar across the organisation.
Jan 2022 - May 2024

Product Security Engineer

🏢 OLA
Mobility & Electric Fintech DAST / SAST Bug Bounty
  • Performed threat modelling, DAST, and SAST on web applications across OLA business groups (Mobility, Electric, Money, Avail Finance, and more).
  • Ran web application security assessments for OWASP Top 10, MITRE ATT&CK, and business logic vulnerabilities.
  • Managed the OLA bug bounty process and triaged researcher submissions.
  • Performed white-box tests and removed false positives from automated scans.
  • Worked with developers to remediate findings and mapped risks by business criticality.
  • Raised detailed Jira tickets with reproduction steps, remediation guidance, and evidence.
  • Conducted retests to verify closure of security risks across web, API, and mobile assessments.
  • Supported GDPR and PCI-DSS audit dependencies on application security.
Jun 2019 - Jan 2022

Security Services Associate Consultant

🏢 Synopsys
  • Performed DAST and web application security assessments for OWASP Top 10, MITRE ATT&CK, and business logic issues.
  • Ran scans with Burp Suite, Nessus, AppScan, Metasploit, SqlMap, Nmap, OpenVAS, Dirb, Nikto, and related tooling.
  • Performed black-box and grey-box security tests and removed false positives.
  • Provided executive reports with technical summaries and remediation recommendations.
  • Configured DevSecOps tooling such as Checkmarx, WhiteSource, and Burp in CI/CD environments.
  • Performed cloud configuration reviews on AWS, Azure, GCP, and Alibaba Cloud.
  • Sent daily vulnerability updates and supported parallel revalidation during active tests.
Jan 2019 - May 2019

Cyber Security Intern

🏢 Synopsys Inc.
  • Learned penetration testing fundamentals, application stacks, and OWASP Top 10 in web environments.
  • Automated open-source and commercial SAST, SCA, and DAST tools in Jenkins pipelines for efficient security scanning.
Mar 2017 - Apr 2017

System / Network Admin Intern

🏢 Shah Technical Consultants Pvt. Ltd.
  • Managed network and server infrastructure for the organisation.
  • Provided proactive solutions for technically challenging operational problems.

07 // TRANSMISSION CHANNELS

Let's Connect

Open to Staff AppSec leadership, GenAI/LLM security consulting, advisory, and technical collaboration.