Bikramaditya Guha
Team Lead - Offensive Security @Zalando
Signup · Get unlimited contacts
WORK HISTORY
Team Lead - Offensive Security @Zalando
Berlin, DE
Leading a high-performing team of penetration testers, red teamers, and offensive security engineers delivering full-stack penetration testing, adversary simulations, and threat-driven risk reduction across infrastructure, applications, APIs, and cloud environments.• Built the organization\'s Red Teaming and Vulnerability Management capabilities from the ground up, including hiring, program design, stakeholder engagement, and measurable KPI reporting.• Led and coordinated internal and external adversary simulations across multiple business units, aligning TTPs with MITRE ATT & CK and purple teaming initiatives.• Planned, organized and conducted Purple teaming exercises in coordination with the Cyber Defense Team.• Defined and implemented automation initiatives including a Continuous Automated Red Teaming (CART) framework and custom external attack surface monitoring to detect and eliminate common threats such as subdomain takeovers, source code exposure, credential leaks, and PII data disclosures.• Oversaw the Bug Bounty program, managing triage workflows, validating external reports, and reducing payout costs through targeted automation and internal coverage improvements.• Drove security tooling integration into CI/CD pipelines and cloud infrastructure (AWS), supporting secure-by-design enablement across engineering.• Provided executive-level reporting to CISO and senior leadership, translating technical risk into prioritized remediation actions and investment decisions.• Mentored and developed offensive security talent through structured training paths, external certifications, and internal research initiatives.
EDUCATION
Narbheram Hansraj English School
ISC, Science
Priyadarshini College of Engineering and Architecture, Nagpur, India
Bachelor of Engineering - BE, Electronics
SKILLS
ABOUT BIKRAMADITYA GUHA
I’m an Information Security leader with 18+ years of experience across offensive security, red teaming, penetration testing, vulnerability management, and threat-informed defense. I specialize in building and scaling security programs from the ground up, including designing strategy, defining KPIs, building automation pipelines, and aligning with business risk.My technical foundation comes from hands-on security research and exploit development. I’ve published multiple CVEs, contributed to open exploits, and performed advanced post-exploitation and adversary simulation work across diverse environments. That experience still drives my approach today, whether I’m supporting engineering, influencing SOC strategy, or leading purple teaming initiatives.I’ve built and led Red Teaming and Penetration Testing functions for large enterprises, covering infrastructure, cloud, Active Directory, mobile, APIs, binaries, and CI/CD pipelines. I’ve also architected end-to-end Vulnerability Management programs by selecting tools, defining processes, hiring and mentoring teams, and delivering KPI-driven risk reduction. This includes triaging and remediating thousands of issues across hybrid environments while reducing bug bounty costs through automation.I’m passionate about creating meaningful engagement through security awareness, including global live-hacking demos for employees and their families. I regularly support regulatory audits such as PCI DSS, SOC2, DORA, and BAFIN, build custom tooling like automated red teaming frameworks and attack surface monitoring, and partner cross-functionally across product, engineering, procurement, and legal.What drives me is building secure-by-design culture at scale, grounded in measurable impact, technical depth, and strong people leadership. OSCP Certified | PCI DSS, SOC2, DORA, BAFIN audit support KPI-driven | Risk-based decision-making | Security automation advocate Leader. Builder. Hacker.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.