profile-pic

Yash Singh Chauhan

I’m a security engineer with hands-on experience across application security, cloud security, and security automation. Currently at BrowserStack, I work on strengthening cloud infrastructure (AWS/EKS), improving detection and monitoring (Wazuh, Suricata), and securing edge systems (Cloudflare WAF).

Previously, I worked as a Senior AppSec Engineer where I delivered end-to-end penetration testing and built security labs for Fortune 500 companies across modern stacks (Django, Node, React, Go, Ruby). I’ve also contributed as a co-trainer at BlackHat and built security portals/products that reduced manual effort significantly.

I enjoy building scalable security systems, reducing noise into meaningful signal, and shipping practical security automation.

  • Role

    Application Security Engineer

  • Years of Experience

    3 years

  • Professional Portfolio

    View here

Skillsets

  • Snyk
  • Kubernetes
  • Linux
  • Nessus
  • nginx
  • NMAP
  • Python
  • Rce
  • SAST
  • Secrets detection
  • Secure SDLC
  • Idor
  • SonarQube
  • Ssrf
  • threat modeling
  • TypeScript
  • vulnerability triage
  • Web exploitation
  • Workflow automation
  • ZAP
  • Supply-chain controls
  • Checkmarx
  • Application Security
  • authN
  • authZ
  • AWS
  • Bandit
  • Bash
  • Browser extension security
  • Burp Suite
  • Business logic abuse
  • Api Security
  • Cicd security
  • Code Reviews
  • container security
  • DAST
  • Dependency security
  • Docker
  • Go
  • Graphql security
  • IaC scanning

Professional Summary

3Years
  • Dec, 2024 - Present1 yr 5 months

    Security Engineer

    BrowserStack
  • Jun, 2024 - Dec, 2024 6 months

    Senior Application Security Engineer

    we45
  • Oct, 2023 - Jun, 2024 8 months

    Application Security Engineer

    we45
  • Apr, 2023 - Oct, 2023 6 months

    Product Security Engineer Intern

    Harness

Work History

3Years

Security Engineer

BrowserStack
Dec, 2024 - Present1 yr 5 months
    Architected and executed the migration of EKS clusters to IAM Roles for Service Accounts (IRSA), replacing static credentials to enforce least-privilege principles and harden cloud infrastructure. Optimized Wazuh SIEM alert logic, achieving a 70% reduction in noise by filtering over 5 million (50 lakhs) non-critical alerts, transforming raw logs into a reviewable monitoring stream. Enhanced network defense by upgrading and tuning Suricata NIDS rules, significantly reducing false positives while successfully detecting and alerting on valid attack vectors. Managed Cloudflare WAF and edge security configurations, performing real-time reviews to mitigate active spam campaigns and bot attacks. Spearheaded the end-to-end development and maintenance of an internal IAM portal, building custom access modules to streamline user provisioning and providing on-call debugging support. Conducted daily Code and Architecture reviews while leading Vulnerability Management efforts, prioritizing critical remediation to secure the software development lifecycle (SDLC). Orchestrated security operations including organizational-wide phishing campaigns Led Root Cause Analysis (RCA) for security incidents to prevent recurrence.

Senior Application Security Engineer

we45
Jun, 2024 - Dec, 2024 6 months

Application Security Engineer

we45
Oct, 2023 - Jun, 2024 8 months
    Developed comprehensive application security labs encompassing diverse technologies (Python - Django, Node.js, React.js, Vue.js, Go, Ruby) for multiple Fortune 500 companies, enabling hands-on training and skill enhancement. Served as a co-trainer at prestigious industry events such as BlackHat, sharing expertise and facilitating knowledge transfer in application security. Crafted cloud security training content (Azure) tailored to the specific needs of various clients, ensuring effective knowledge dissemination. Conducted in-depth research on emerging trends in application security and cloud security, leveraging findings to design cutting-edge training programs. Spearheaded end-to-end penetration testing processes for a wide range of web applications, mobile applications, and infrastructure, delivering comprehensive security assessments for multiple Fortune 500 clients.

Product Security Engineer Intern

Harness
Apr, 2023 - Oct, 2023 6 months
    Developed the companys security advisory portal from scratch, taking charge of frontend development using Reactjs. This portal allows users to easily access vulnerability information, significantly reducing the teams manual effort in crafting advisories by 95%. Worked on penetration testing of the platform and verification of the reported findings. Contributed to the enhancement of the product by focusing on vulnerability management aspects.

Major Projects

2Projects

VALLUMFLOW Security Automation Platform

    Designed and built a security automation platform with a DAG-based workflow engine supporting complex AppSec and DevSecOps pipelines. Implemented dynamic input resolution, AI Agent node support, webhook-triggered workflows, and architectural improvements for parallel task execution.

OWASP PROACTIVE CONTROLS Open Source Contributor

    Authored structured threat scenarios mapped to OWASP Proactive Controls, bridging secure-coding guidelines and real-world attack techniques.

Education

  • B.A. (Political Science With English Language)

    Chhatrapati Shahu Ji Maharaj University (2023)
  • M.C.A. (Masters of Computer Application)

    GLA University (2025)