Skip to main content
arun kumarAK
Open to opportunities

arun kumar

@arunkumar29

Staff product security engineer securing SaaS, distributed backends, and cloud-native systems with SDLC-first AppSec.

India
Message

What I'm looking for

I’m looking to embed application security in fast-moving product teams—securing AI/agentic systems across the SDLC with threat modeling, hands-on remediation, and practical governance—while partnering closely with engineers and product/executive stakeholders.

I’m a product security engineer with 12+ years securing SaaS platforms, distributed backend services, and cloud-native systems on AWS. I work directly inside engineering teams across the full SDLC—threat modeling and architecture review through hands-on remediation—so risk gets closed, not just reported.

At Revenera (part of Flexera), I own product security across multiple engineering teams and product lines. I set security policies and review practices that ship alongside the product, run ISO 27001-aligned governance with evidence coordination and risk treatment tracking, and deliver executive-facing updates on priorities, risks, and progress.

I’m comfortable triaging customer-reported security concerns and coordinating fixes across the right product teams. I also manage external security posture using BitSight and SecurityScorecard, and validate remediation safely with SRE and service owners—focusing on configuration hygiene, patch cadence, certificate management, and web security posture.

My current focus is securing AI and agentic systems and embedding application security into fast-moving product teams without slowing delivery down. Earlier roles strengthened my threat modeling and VAPT leadership, plus DevSecOps tool evaluations and integrations (SAST/DAST/SCA and CI/CD security), so security controls connect cleanly to engineering execution.

Experience

Work history, roles, and key accomplishments

IL

Technology Analyst, Application Security

Nov 2017 - Sep 2020 (2 years 10 months)

Ran VAPT across Infosys and public-facing applications with deep OWASP coverage across web, mobile, and cloud environments (AWS/Azure). Evaluated and deployed application security tooling on-prem with project plans and SLAs, and integrated security testing into DevSecOps and vulnerability management workflows.

Education

Degrees, certifications, and relevant coursework

MC

MEPCO Schlenk Engineering College

Bachelor of Engineering, Electrical and Electronics Engineering

2009 - 2013

Bachelor of Engineering in Electrical and Electronics Engineering from MEPCO Schlenk Engineering College (2009–2013).

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan