I'm Sidharth B Nair,
Information Security Professional

Information Security Professional with 7+ years securing web, mobile (Android/iOS), API and Thick-Think client platforms. Expertise in penetration testing, vulnerability research, and runtime security analysis across product and service environments.

Former Senior Security Engineer at Nykaa and Security Consultant at SISA, specializing in vulnerability discovery and building robust security frameworks. Speaker at ISACA Silicon Valley demonstrating Log4Shell vulnerability exploitation and mitigation.

Sidharth B Nair

About Me

Security professional with expertise in identifying and mitigating vulnerabilities across web, mobile, and API platforms. My approach combines thorough security testing with strategic threat modeling to build robust product security frameworks. Certified security specialist with hands-on experience in both offensive security testing and defensive control implementation.
Application Security Testing
Mobile Security (Android/iOS)
Threat Modeling
Product Security

Security Focus Areas

Specialized security assessment domains

Security Testing

Comprehensive penetration testing of applications and security controls including static/dynamic analysis, binary analysis, and runtime security testing.

Threat Modeling

Systematic analysis of application architectures to identify potential threats and recommend appropriate security controls.

Content Security

Assessment of DRM implementations and content protection mechanisms including Widevine security analysis.

Product Security

End-to-end security implementation for products including secure SDLC integration and security control validation.

Professional Experience

Doverunner Inc
Senior Threat Analyst - Product Security

Oversee end-to-end security operations including DLP implementation, policy development, and security testing frameworks. Conduct comprehensive penetration testing (SAST/DAST) across web/mobile applications, identifying critical vulnerabilities and driving remediation.

Serve as Security Awareness Manager, developing security awareness programs and reporting directly to executive leadership. Align security initiatives with business objectives through cross-functional collaboration, establishing robust security frameworks for organizational growth.

Nykaa E-Retail Pvt Ltd
Senior Security Engineer - Technology

Led internal penetration testing initiatives and third-party risk management programs, conducting vendor security assessments and VAPT activities. Facilitated client security collaborations to resolve critical issues while ensuring regulatory compliance specifically for PCI-DSS.

Integrated security best practices across business operations through architecture reviews and CI/CD pipeline enhancements, reducing security incidents by 50% through improved authentication mechanisms.

SISA Information Security Pvt Ltd
Consultant - AppSec- WarLabs

Directed enterprise security assessments, managing teams to deliver comprehensive penetration testing and PCI DSS compliance audits. Developed standardized testing methodologies that improved assessment efficiency by 30%.

Presented security findings to C-level executives while mentoring junior team members in advanced vulnerability identification techniques.

SISA Information Security Pvt Ltd
Senior Associate Consultant - AppSec- WarLabs

Performed vulnerability assessments and penetration testing for web/mobile applications following OWASP methodologies. Specialized in PCI DSS compliance assessments and source code reviews.

Developed comprehensive reports outlining security findings and remediation strategies. Conducted security training sessions for development teams and junior security consultants.

SISA Information Security Pvt Ltd
Associate Consultant - AppSec- WarLabs

Conducted security assessments of web/mobile applications and APIs for clients across banking and financial sectors. Performed vulnerability scanning and manual penetration testing.

Assisted in developing client relationships by providing excellent customer service and technical expertise. Demonstrated live attack sessions including Log4Shell vulnerability for ISACA Silicon Valley Chapter.

Bug Bounty Research
Independent Security Researcher

Identified and responsibly disclosed vulnerabilities in various platforms through bug bounty programs including HackerOne. Contributed to securing web/mobile applications by discovering and reporting security issues.

Received acknowledgments from multiple organizations including Fitbit and AlienVault Security for vulnerability discoveries and security improvements. Developed expertise in identifying zero-day threats and complex security flaws.

Certifications & Achievements

Android Application Security

Advanced certification covering Android security architecture, vulnerability assessment, and penetration testing techniques for mobile applications.

iOS Application Security

Specialized training in iOS platform security, jailbreak detection bypass techniques, and secure coding practices for Apple ecosystems.

Practical IoT Hacking

Hands-on certification in embedded device security and IoT vulnerability assessment methodologies.

InCTF National Level

Diploma Certification in Capture the Flag competition, demonstrating practical security skills in competitive environment.

Cybersecurity Essentials

Cisco Networking Academy certification covering core security principles, network defense, and vulnerability management.