SecurityJunky

About Shantanu Ghumade

Who I Am

I am Shantanu Ghumade, better known in the cybersecurity community as SecurityJunky.

I am a Security Tech Lead - Security Assurance at Deriv with 6+ years of experience helping fast-moving engineering teams build safer systems. My day-to-day work sits across application security, secure code and architecture review, cloud hardening, DevSecOps, and AI-driven security automation.

I started with the usual hacker instinct: break things, understand why they broke, and learn how to find the next weakness faster. Over time, that turned into a builder's itch. These days I spend a lot of energy designing security systems that scale, especially with Artificial Intelligence (LLMs & RAG) for messy operational problems like triage, threat intelligence, and internal security support.

Professional Expertise

  • Offensive Security: OSCP, OSWE, and CREST CRT certified, with deep-dive testing experience across web, mobile (Android/iOS), and APIs.
  • Cloud Hardening: Hands-on work securing AWS, GCP, and Alibaba Cloud environments with CSPM automation and CIS-aligned controls.
  • DevSecOps: Building security into the SDLC through custom SAST/DAST pipelines, secret scanning, and IaC checks.
  • AI Automation: Developing RAG-based security agents for threat intelligence, vendor risk management, and vulnerability triage.

Key Projects & Research

AI & Automation

  • HackerOne Triage Bot: An automated agent that prescreens bug bounty reports and cuts down repetitive manual triage.
  • Threat Intel Feed: An AI-driven intelligence system that maps threat feeds to specific tech stacks so teams can spot relevant risk earlier.
  • Internal Security Assistant: A RAG-based assistant that helps employees query internal security policies without digging through scattered docs.

Open Source Tools

  • JSSCANNER: A tool for scanning JavaScript files and surfacing exposed endpoints, secrets, and other interesting strings.
  • FFUFPLUS: Extra automation around ffuf for fuzzing, directory discovery, VHOST checks, and recon workflows.
  • CVENOTIFIER: A real-time tracker and notification system for critical vulnerabilities.

Career Timeline

  • Security Tech Lead - Security Assurance @ Deriv (Apr 2026 - Present) Leading security assurance work across AppSec, AI security automation, cloud hardening, and DevSecOps.
  • Senior Security Engineer @ Deriv (Jan 2023 - Apr 2026) Worked on cloud hardening, AI security automation, secure reviews, bug bounty operations, and DevSecOps.
  • Lead Security Consultant @ SecureLayer7 (2020 - 2023) Led 50+ security assessments for global clients while helping manage consultant teams.
  • B.Tech in Computer Engineering (2015 - 2019) Government College of Engineering, Jalgaon.

Connect With Me

I am always up for a good conversation about AppSec, AI, bug bounty research, or security automation that actually saves people time.