HimalayasHimalayas logo
YC
Open to opportunities

Yash Chhabria

@yashchhabria

Senior AppSec architect building zero-to-one programs, cutting vulns and MTTR.

United States
Message

What I'm looking for

I’m looking to build or scale AppSec programs end-to-end—pairing hands-on reviews with tooling, threat modeling, and AI security guardrails—so engineering ships faster with measurable risk reduction and audit-clean outcomes.

I’m a Senior Application Security Architect and hands-on AppSec program builder with 7+ years in application security. I’ve built an AppSec program from zero, cutting critical vulnerabilities by 90%, securing $8M+ in executive investment, and reducing MTTR from 45 to 7 days across a $25B+ enterprise portfolio.

I build and continuously improve AppSec strategy, policies, tooling, and controls across the full SDLC—from design review through deployment gates. I integrate SAST, DAST, and SCA into CI/CD workflows (including GitHub Actions and GitLab CI), and I’ve delivered “zero compliance violations across all audit cycles.”

I’m deeply technical in secure code review and vulnerability remediation across web, mobile, and API products—manually catching issues automated scanners miss. I’ve reduced critical findings from 40+ to under 5 in 18 months, hardened REST and GraphQL API security, and governed 200+ annual penetration testing engagements to protect the remediation pipeline quality.

I also lead AI/LLM security practice, assessing LLM integrations and RAG pipeline trust boundaries as AI features move into production. Using OWASP LLM Top 10 and prompt-injection threat modeling, I embed AI security checkpoints into the SDLC, deliver developer-ready remediation guidance, and pair security awareness with incident response and compliance governance.

Experience

Work history, roles, and key accomplishments

AS

Application Security Engineer

Altria Client Services

Nov 2019 - Mar 2026 (6 years 4 months)

Built an AppSec program from zero and led a risk-based SDLC integration across 50+ web, mobile, and API products, reducing critical/high vulnerabilities by 90% and driving zero recurring critical findings. Secured $8M+ in security investment and reduced MTTR from 45 to 7 days while governing penetration testing and delivering hands-on remediation, incident response, and developer enablement.

Education

Degrees, certifications, and relevant coursework

University of Texas at Arlington logoUA

University of Texas at Arlington

Master of Science in Engineering, Engineering

Earned a Master of Science in Engineering from the University of Texas at Arlington in May 2018.

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan