Aashish Malhotra

Senior Security Engineer @Praetorian | OSCP | AWS SAA | CSAM @ IIITD‘23

Abu Dhabi, Abu Dhabi Emirate, United Arab Emirates

About

Senior Security Engineer specializing in vulnerability research and offensive security automation. Working on continuous vulnerability management across 20+ Fortune 500 and Global 500 enterprise clients while architecting self-scaling agentic plugins that enables teams of engineers to investigate in depth and flag risks across external attack surfaces

Experience

  • Praetorian (Austin, Texas, United States)
    • Senior Security Engineer
      Apr 2025 - Present · 1 yr 3 mos

    • Security Engineer
      May 2023 - Apr 2025 · 2 yrs

  • Indraprastha Institute of Information Technology, Delhi (10 mos)
    • Teaching Assistant (Usable Security)
      Jan 2023 - May 2023 · 5 mos

    • Teaching Assistant (Foundations of Computer Security)
      Aug 2022 - Dec 2022 · 5 mos

      Aided Dr. Arun Balaji (https://www.iiitd.ac.in/arunb) with instructional responsibilities and helped the students with doubts regarding development of secure applications and potential attack vectors.

  • Security Researcher at TavLab
    Aug 2022 - May 2023 · 10 mos

    The Integrated Federated Healthcare Platform (IFHP) is an application developed to allow the sharing of patient data between hospitals and researchers in order to facilitate computational biology research. The team's project was to ensure the security of the IFHP in order to protect the privacy of both patients and hospitals using the platform.

  • Security Researcher at MIDAS: Multimodal Digital Media Analysis Lab
    Aug 2022 - Nov 2022 · 4 mos

    – Worked on securing MIDAS Lab’s latest product Kyron which holds assessments and recruitment drives for various companies including the likes of Adobe and Berlitz – Worked with the developers to secure and fix various critical endpoints which if exploited could have serious consequences.

  • Security Engineer at Deutsche Telekom Digital Labs
    Jul 2022 - Nov 2022 · 5 mos

    – Conducted various Red Team Assessments and External Pentests across Deutsche Telekom domains to look for existing vulnerabilities in the applications. – Developed various tools and scripts for the purpose of reconnaissance and exploitation that aided the pentests.