gaurav deore
@gauravdeore1
Application Security Engineer driving vulnerability lifecycle closure across web, APIs, and LLM features at Netcracker.
What I'm looking for
Application security engineer at Netcracker Technology. Three years finding vulnerabilities one application at a time — now moving to managing exposure across an enterprise estate.
What I do today
Security testing across product releases and 10+ enterprise customer deployments. Web and API penetration testing (Burp Suite Pro, OWASP ZAP, Nuclei, sqlmap), static analysis with Checkmarx SAST, and open-source dependency risk with OWASP Dependency-Check. I validate every finding manually before it reaches an engineering backlog — no developer should lose an afternoon to a scanner's false positive.
GenAI / LLM application security
I security-test generative-AI and LLM features in production telecom software, working against the OWASP Top 10 for LLM Applications (2025). The attack surface is genuinely different — the model processes instructions and untrusted data in the same context window, so there's no clean parser boundary to sanitize at. In practice that means testing for prompt injection and guardrail bypass (LLM01), insecure output handling where model output reaches the UI or downstream systems as XSS or HTML injection (LLM05), and authorization and excessive-agency issues when an agent can call tools and APIs (LLM06). Two of the ten map straight onto classical AppSec — LLM03 Supply Chain is SCA for models, LLM05 is the old lesson that output is untrusted input — which is exactly the bridge I bring.
Security research
Independent security researcher. Accepted vulnerability disclosures across 9+ organizations including Apple, PagerDuty, Fastly, Coca-Cola and QNAP Systems. Reconnaissance and asset discovery, then validate and responsibly disclose — a good school for learning what "exploitable" actually means.
Where I'm heading — vulnerability and exposure management
CTEM's five stages are scope, discover, prioritize, validate, mobilize. Validation is the one most programs skip: proving a finding is genuinely exploitable in this environment, not merely present. That's the work I've been doing for three years. The other half is risk-based prioritization — CVSS, EPSS, CISA KEV, SSVC — and why severity alone makes a bad queue.
Building
OIXLY — NVD/CVE intelligence pipelines with enrichment and prioritization context.
Sigyl — zero-credential Android platform using Ed25519 keypairs as identity. Provisional patent filed.
Bengaluru. Open to conversations about vulnerability management, exposure management, and application security.
Experience
Work history, roles, and key accomplishments
Application Security Engineer
Netcracker Technology
Jun 2024 - Present (2 years 1 month)
Deliver security testing across product releases and 10+ enterprise customer deployments, including manual and automated assessment of web applications, REST APIs and generative-AI/LLM features.
Junior Data Security Analyst
Netcracker Technology
Apr 2023 - May 2024 (1 year 1 month)
Administered an enterprise data anonymization platform protecting customer data across deployments, and reviewed data export requests to prevent leakage of sensitive data.
Education
Degrees, certifications, and relevant coursework
North Maharashtra University
Master of Computer Applications, Computer Applications
2020 - 2022
Grade: 74.63%
Master of Computer Applications (MCA) degree from North Maharashtra University, Jalgaon from 2020 to 2022 with 74.63%.
SSMM Arts and Science College
Bachelor of Science, Computer Science
2017 - 2020
Grade: 73.87%
Bachelor of Science in Computer Science from SSMM Arts and Science College, Pachora from 2017 to 2020 with 73.87%.
Availability
Location
Authorized to work in
Salary expectations
Social media
Skills
Interested in hiring gaurav?
You can contact gaurav and 90k+ other talented remote workers on Himalayas.
Message gauravGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
