Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings
View emgaurav's full-sized avatar

Block or report emgaurav

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
emgaurav/README.md

Gaurav Arora

Head of Security Engineering @ Zepto

Review Board Member, OWASP AppSec Days Singapore and BSides Vizag


I joined Zepto as the first security hire with a blank slate and a mandate: build it. No team, no program, no playbook. Three roles and 2.5 years later, I lead the full cybersecurity function across AppSec, Cloud Security, Infrastructure Security, and Incident Response across 250+ microservices and 3M+ daily orders, as Zepto moves toward the public markets.

I am a builder first. I architect and ship alongside the teams I lead.


What I build

Optimus — Zepto's internal AI-native security platform. Multi-agent system built on Claude tool-use APIs and Bedrock embeddings. Covers SAST, SCA, secrets scanning, IaC, SBOM-powered zero-day detection, AI-assisted threat modeling (STRIDE-DP), auto-fix PRs, WAF explorer, data classification, API inventory, and natural-language querying over security data. Replaces $1M+ in commercial tooling annually.

Supply chain security — Real-time SBOM graph across 250+ microservices with sub-15-minute MTTD on newly disclosed CVEs. Responded to Axios, Trivy/TeamPCP, LiteLLM PyPI poisoning, and TanStack worm incidents.

Agentic system security — MCP audit tooling to discover unauthorized MCP servers across engineering. Security rules embedded into Cursor, Claude Code, and Copilot org-wide. Internal policy on AI agent access and zero-data-leakage requirements.

Cloud security — Unified CSPM across AWS via Wiz, PingSafe, and Prisma Cloud. IAM human user cleanup from 600+ to zero in production. SCP rollout. SentinelOne CNAPP onboarding.


Career arc

Security Analyst, Spice Money (2017) Secured UMANG — Government of India's unified citizen services platform — solo, as first security hire.

Security Engineer / Senior Security Engineer, Spice Money (2018-2021) Built security from zero across RBI, UIDAI, PCI DSS regulated fintech: PPI, B2B lending, AePS, BBPS, UPI.

Senior Security Engineer, Boutiqaat (2021-2022) First international role. Secured one of MENA's largest influencer-driven e-commerce platforms ($500M+ valuation) across cloud, WAF, and DevSecOps.

Senior / Lead Security Engineer, Slice (2022-2024) Founding security engineer. Built program from zero across UPI payments, PPI wallet, and B2C lending under RBI and PCI DSS oversight.

Lead Security Engineer / Engineering Manager / Head of Security Engineering, Zepto (2024-Present) First security hire. Built team, program, and Optimus. Now leading the full cybersecurity function at IPO-track quick commerce scale.


Community

Review Board Member, OWASP AppSec Days Singapore Review Board Member, BSides Vizag


Certifications

eWPTXv2 | eCPPT | ITIL 4 Foundation


Connect

LinkedIn | X / Twitter | emgaurav.github.io


Security is not a product, it is a program. You build it, you earn it, and you never stop.

Pinned Loading

  1. objectify-s3 objectify-s3 Public

    Objectify-s3 is a tool that recursively checks AWS S3 buckets and objects for misconfigured permissions.

    Shell 15 4

  2. HookMyKeys HookMyKeys Public

    HookMyKeys is a simple python based keylogger designed for linux.

    Python 1

  3. threat-modeling-101 threat-modeling-101 Public

    An essential approach towards threat modeling an application.

    1 1

  4. trending-cve-tracker trending-cve-tracker Public

    Shell 1

  5. AI-Review-Analyzer AI-Review-Analyzer Public

    AI-Review-Analyzer" is a web app utilizing OpenAI's GPT model to analyze user reviews for sentiment, categorization, emotion, and security threats, etc.

    Python 1

  6. aws-access-keys-auditor aws-access-keys-auditor Public

    This script scans through all access keys for all IAM users and returns the keys which are unused for 90+ days

    Python

Morty Proxy This is a proxified and sanitized view of the page, visit original site.