Application Security
Security reviews, web security, secure design, authentication and authorization thinking.
yash@yashhacks:~$ whoami
Security Engineer @ Amazon
I work across application security, threat modeling, cloud security and vulnerability management—finding security risks early, reviewing designs, and helping engineering teams build secure services.

yash@yashhacks:~$ cat about.txt
Security Engineer with experience in application security, cloud security and vulnerability management. My work includes identifying security risks, conducting security reviews, threat modeling, and helping engineering teams build secure services.
I’m continuing to go deeper into penetration testing, exploit research and offensive security to strengthen my application-security and product-security perspective.
Security reviews, web security, secure design, authentication and authorization thinking.
Trust boundaries, attack surfaces, abuse paths, mitigations, and risk-driven design review.
AWS security, identity and access, service architecture, networking, and defense in depth.
Python and AWS automation for vulnerability correlation, prioritization, remediation, and reporting.
yash@yashhacks:~$ cat experience.txt
Apr 2026 — Present · Sunnyvale, CA
Mar 2025 — Mar 2026
Built Python + AWS automation to correlate and prioritize vulnerabilities, streamline remediation, and improve risk visibility for security and engineering teams.
Aug 2023 — Feb 2025
Jan 2022 — Nov 2022
yash@yashhacks:~$ ls certs/
yash@yashhacks:~$ ls projects/
projects/yashhacks
This portfolio: a dependency-light, interactive shell experience built with semantic HTML, CSS and vanilla JavaScript, with a strict CSP and hardened browser security headers.
source ↗projects/simple-siem-tool
A lightweight security project for log monitoring and SIEM fundamentals.
repository ↗projects/basic-firewall-configuration
A hands-on repository for learning and documenting firewall-rule configuration.
repository ↗YashHacks shell v3.0
Type help, try ls, or run cat about.txt.
Use ↑/↓ for history and Tab for completion. Commands are local-only and are never sent to a server.
yash@yashhacks:~$ cat recommendations.txt
“Strong ownership and impact to security and automation initiatives.”— Prasanna Shrestha, Senior Software Engineer
“A standout security professional… able to take complex security challenges and build practical, automated solutions.”— Sean Nikbosh
yash@yashhacks:~$ cat learning.txt
Also active as an HTB CTF player.
yash@yashhacks:~$ cat education.txt
Master’s — Computer & Information Systems Security / Information Assurance
BTech — ECE
yash@yashhacks:~$ cat contact.txt
Security, AppSec, cloud security, threat modeling, or building something interesting.