Skip to content
View ptkvaibhav's full-sized avatar

Block or report ptkvaibhav

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ptkvaibhav/README.md

Hi there, I'm Pratik Vaibhav πŸ‘‹

Senior Product Security Engineer (PSIRT) at Guidewire Software

Ex-Lead Solution Advisor at Deloitte β€’ NULLCON 2025 Speaker β€’ Security Researcher

Website LinkedIn GitHub Email


"I build secure systems and prove where they break, turning raw scanner noise and incident chaos into high-confidence engineering decisions."


🎯 About Me

I am an Application Security & Product Security Incident Response (PSIRT) specialist with 6+ years of experience securing enterprise cloud infrastructures and US government healthcare systems. My expertise spans:

  • Incident Response & Triage: Resolving complex production security incidents, investigating exploit reachability, and coordinating cross-functional emergency patch lifecycles.
  • Secret Governance & Remediation: Architecting enterprise-scale automated secret-leak remediation pipelines and TruffleHog governance workflows.
  • Offensive Security & Red Teaming: Deep manual web/API penetration testing, business logic flaw exploitation, auth bypass, and evidence validation.
  • AI-Driven Security Automation: Engineering autonomous AI security agents, custom Claude AI skills, and CVE correlation frameworks to accelerate vulnerability identification and triage.
  • AppSec Governance & Secure SDLC: Implementing automated SAST/DAST/SCA gate checks, threat modeling, architecture reviews, and reducing scanner false-positive noise.

πŸ’Ό Experience & Career Highlights

Senior Product Security Engineer (PSIRT) β€’ Guidewire Software

(May 2026 – Present)

  • Incident Response at Scale: Spearheaded PSIRT operations across 100+ critical security incidents, streamlining cross-functional triage workflows to accelerate mean time to resolution (MTTR by 33%).
  • TruffleHog Secret Invalidation: Orchestrated the enterprise-wide TruffleHog secret leak incident response lifecycle, reducing secret invalidation and credential revocation timelines from 70 to 38 days (45% reduction in exposure window).
  • Autonomous AI Security Agents: Architected autonomous AI-powered PSIRT automation tooling, engineering custom Claude AI skills and a specialized CVE detection and response framework agent to automate vulnerability identification, exploit verification, and developer remediation workflows.
  • Root-Cause & Governance: Led post-mortem investigations and risk-informed patch governance across distributed cloud services.

Lead Solution Advisor & AppSec Lead β€’ Deloitte

(Jun 2019 – May 2026)

  • Top 1% Performance Rating: Recognized with the Outstanding Performance Award (Top 1%) for high-assurance cybersecurity delivery on US government healthcare systems.
  • 30% False-Positive Reduction: Engineered unified correlation logic across SAST (Fortify SSC), DAST (WebInspect), and SCA, reducing false-positive noise from ~30% (300/1000 noisy findings) to near-zero.
  • Team Leadership & Mentorship: Managed and mentored a team of 14 Application Security engineers, driving delivery excellence and automated verification frameworks.
  • Conference Speaker: Presented "Smart Automation using Artificial Intelligence" at NULLCON 2025, sharing frameworks for using AI to eliminate repetitive security workflows.

πŸ› οΈ Technical Arsenal & Competencies

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ DOMAIN                        β”‚ TECHNOLOGIES & ARSENAL                                    β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Incident Response & PSIRT     β”‚ Incident Triage, TruffleHog, CVE Analysis, Post-Mortems   β”‚
β”‚ Application Security          β”‚ SAST, DAST, SCA, Threat Modeling, Architecture Review     β”‚
β”‚ Offensive Testing             β”‚ Burp Suite Pro, Web/API Pentesting, Exploit Reproduction  β”‚
β”‚ Enterprise Security Tools     β”‚ Fortify SSC/SCA, WebInspect, Checkmarx, Snyk, Prisma Cloudβ”‚
β”‚ AI Security Automation        β”‚ Claude AI Skills, Agentic Testing, Scanner Orchestration  β”‚
β”‚ Cloud & DevSecOps             β”‚ Docker, OpenShift, Linux, GitHub Actions, Strict CSP      β”‚
β”‚ Programming Languages         β”‚ Python, Java, TypeScript, JavaScript, SQL, Shell / Bash   β”‚
β”‚ Frameworks & Web Platforms    β”‚ Next.js, React, Node.js, REST APIs, PostgreSQL, Redis     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸš€ Flagship Security Projects

Project Description Tech Stack
Clinkz Autonomous penetration testing platform exploring agent loops, tool orchestration, CVE correlation, and evidence-driven reporting. Python Docker LLM Security Automation
Burp to Fortify Parser Bridge between Burp Suite exports and Fortify-aligned review workflows for automated finding translation and cleaner intake. Python Burp Suite Fortify AppSec
Burp Fortify SSC Plugin Enterprise Java plugin for ingesting and normalizing Burp Suite findings directly into Fortify SSC pipelines with preserved evidence. Java Burp Suite Fortify SSC DAST
Invoker AI-assisted vulnerability scanning & triage framework focused on high-confidence signal discovery and automated reachability analysis. Python AI Security Vulnerability Triage
nyx Local file intelligence and SHA-256 fingerprinting tool for defensible data auditing and duplicate detection. TypeScript File Intelligence Automation

🎀 Speaking & Community

  • NULLCON 2025 (Goa, India): Speaker on "Smart Automation using Artificial Intelligence" β€” Exploring practical AI agent workflows to automate reconnaissance, finding correlation, and verification.

πŸ“¬ Connect With Me

Portfolio LinkedIn GitHub Email

Β© 2026 Pratik Vaibhav β€’ Engineered for verifiable security.

Popular repositories Loading

  1. clinkz clinkz Public

    Autonomous AI-driven penetration testing system powered by multi-agent LLM orchestration with MITRE ATT&CK and OWASP WSTG methodology

    Python 7 2

  2. burp-fortify-ssc-parser-plugin burp-fortify-ssc-parser-plugin Public

    An enterprise-grade Fortify Software Security Center (OpenText Application Security) plugin to ingest, parse, and visualize PortSwigger Burp Suite XML scan results.

    Java 3

  3. nyx nyx Public

    A high-integrity, safety-first file intelligence system. It audits local directories using SHA-256 fingerprinting, detects duplicates and versioned files, and proposes organization moves via a pers…

    JavaScript 1

  4. ptkvaibhav ptkvaibhav Public

    Application Security Engineer portfolio focused on securing enterprise and government systems through DevSecOps, penetration testing, and security architecture.

    Python

  5. invoker invoker Public

    This is the repository for AI-based vulnerability scanner