Hrishi P.
Senior Application Security Engineer @Cengage
Signup · Get unlimited contacts
WORK HISTORY
Senior Application Security Engineer @Cengage
Designed and in process of implementing an enterprise-wide Secure Software Development Lifecycle (Secure SDLC) framework, enabling application teams to integrate security-by-design principles and shift security left- Created and implemented Application Security requirements checklist for application development teams to adhere to secure coding practices- Created and deployed a developer-centric remediation workflow integrating Snyk with GitHub Copilot, significantly accelerating backlog reduction and proactive vulnerability resolution- Established AI security assessment criteria for onboarding third-party vendors using AI technologies, ensuring alignment with internal security standards- Co-Authored comprehensive internal AI security standards governing the secure implementation of Large Language Models (LLMs), Retrieval-Augmented Generation (RAG) pipelines, and Agentic AI systems- Spearheaded the development of an AI red-teaming exercise to evaluate and validate the security posture of both internal and vendor-provided AI implementations- Developing an AI-powered security automation using Relevance.ai to facilitate AI-assisted threat modeling and security assessment automation - Led advanced training programs and enablement initiatives focused on application security fundamentals, secure coding, threat modeling, and Secure SDLC best practices for engineering teams- Continued active engagement in vulnerability management, providing expert analysis and strategic direction for complex security issue resolution- Set up and operationalized Dynamic Application Security Testing (DAST) services, enhancing comprehensive testing coverage for web and API-based applications.
EDUCATION
New Jersey Institute of Technology
Bachelor's of Science, Information Technology
INDUS UNIVERSITY
Bachelor's of Science in Engineering, Automotive Engineering
ABOUT HRISHI P.
Empowering development teams at Cengage Group by integrating secure SDLC frameworks and DevSecOps practices, fostering a security-first approach. Collaborated with teams to address vulnerabilities through Snyk and delivered regular training on secure coding, enabling seamless adoption of security principles. Designed an education program covering critical components like threat modeling and lifecycle security. Solid foundation in vulnerability management, application security, and AI security assessments. Dedicated to promoting secure application development and aligning security policies with modern cloud environments to drive organizational resilience and innovation.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.