Varun Bhat
Information Security Engineer
- Role
- Engineer Information Security at Jio Platforms Limited Jpl
- Location
- Mumbai, MH, IN
- LinkedIn followers
- 500 followers
About Varun Bhat
Ever since I was a teenager, I loved building front end web applications, tinkering around default configurations of routers and fiddling with WiFi networks. I enjoyed setting up network environments and websites for my friends and debugging their assignment code, hardening their computers, solving day to day PC problems (network, virus, malware). Hacking was part of my game and as a script kiddie, I sure had a lot of fun.As i grew up, I ended up liking backend programming, PHP, Python, Networks and Internet of Things, to name a few. With this newly gained knowledge, I would keep fiddling around the Internet trying to find new ways to break applications and bypass restrictions while at the same time understanding the bigger picture of how applications were built and how backend code could create a wide array of client and server side vulnerabilities.Up until my graduation in 2019, I was focused on building a career in software development till I decided I wanted to jump into the professional cybersecurity world. I realized the world is certificate-driven and therefore I earned some certifications: CEH(Masters), ECSA(Masters), AWS Certified Security-Specialty (SCS-C01). I set my foot in bug bounty too. A few of my most valuable findings are listed below.I have been acknowledged by Samsung, a leading e-commerce solution provider(Private) and a leading financial services provider (Private) in India for uncovering and helping fix critical bugs in each of these 3 organizations that individually exposed more than a billion plus personally identifiable information of clients and customers. In 2021, I\'ve helped 2 companies, a leading financial solution provider(Private) and another health service provider(Private) protect their customer bases from leaking. In 2021 November I have helped an aviation leader help protect their customer bases from leaking unintentionally.In December 2021, I have helped another leading Indian health service provider(Private) protect their customer bases from leaking. Today, I am a security professional with experience in Web Application Penetration Testing, Secure Code Reviews, Red teaming, Network Pentesting, Bug Bounty and Offensive Security Tool Development(Python), fully blown Cloud Infrastructure Audits (Azure, AWS,GCP)
Experience
Engineer Information Security
Oct 2024 — Present · Mumbai, IN
Drive security research across vulnerability research, OSINT, AI threat work, web/mobile security, and cloud attack/defense, with senior leadership backing.Build telemetry-driven insights using API discovery logs, WAF logs, and WSO2 data.Develop scalable OSINT + Attack Surface Management automation: remove low-hanging issues, maintain an asset/metadata DB, and run a self-managed ASM workflow.Perform external penetration testing for newly deployed critical apps to close gaps beyond internal assessments and improve end-to-end coverage.Serve as technical liaison during vulnerability triage to improve clarity, prioritization, and closure.Mentor junior consultants and interns to improve the quality and impact of vulnerability reporting.Improve security observability, SLAs, and metrics via custom tooling + API integrations across BlackDuck, Tenable, and Fortify.Lead product security evaluations before onboarding/replacement: threat modeling, code review, and technical analysis.Test new security tools and performance to validate fit and strengthen observability.Solve vulnerability management pain points through automated querying and timely reporting.Run contextual CVE alerting + PoC analysis to cut false positives, rapidly replicate,revalidate findings.Help developers unblock delivery by resolving container security blockersReduced Fortify False Positives and Blackduck resolution TATConfigure custom WAF policies, including validation and approval.Build and maintain DevSecOps container scanning automation (open-source) for cloud and air-gapped environments, including supply-chain detection via SBOM parsing.Deliver application security automation for BAU problems using scripting where applicable.Automate external attack surface workflows to improve pentester efficiency and repeatability.Perform manual + automated secure code reviews (Go, Python, PHP) and expand to Ruby/JavaScript/PHP (TBD).Provide developer security education and contribute to ongoing R&D.
Education
Not applicable
Competitive exams
Surana College
Bachelor of Computer Applications, Computer Science
2013 — 2016
RV College Of Engineering
Master of Computer Applications (M.C.A.), Computer Science
2016 — 2019
Rev.Ed
Reved Exclusive - Cinque
National Public School Koramangala
Class XII CBSE-AISSCE, Computer Science
2011 — 2013
The Indian High School Dubai
Class X AISSE(CBSE)
2002 — 2011
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.