In an era where digital threats evolve rapidly, application security has become paramount for businesses of all sizes. Featured.com presents a curated directory of leading application security experts, each bringing years of experience in secure software development, vulnerability management, and cybersecurity best practices. These professionals have been quoted in top tech publications, offering insights on everything from DevSecOps to threat modeling. For publishers and journalists, our directory provides quick access to authoritative voices in application security, ensuring your content is backed by current, real-world expertise. For security professionals, it's an opportunity to showcase your knowledge and connect with major media outlets seeking expert commentary. Whether you're looking to strengthen your organization's security posture or need an expert source for your next cybersecurity article, our directory puts you in touch with trusted application security specialists. Explore the profiles below to find the perfect application security expert for your project or story.
Connect directly with our network of vetted application security experts for interviews, quotes, or in-depth analysis.
Many experts respond within hours to media requests
All experts undergo background and credential verification
No fees to connect with experts for legitimate media requests
Join our network of professionals and connect with journalists and publishers looking for your expertise.
Showing 20 of 815 experts
Manager-AppSec at Cognizant
I am a Cybersecurity expert with ~15 years of hands-on experience in Application Security. I have a proven track record of building robust security frameworks and Security Testing Strategies to help organizations safeguard their Application landscape. I have worked with leading Industry Clients, across diverse Line of Business in implementing Vulnerability Assessment and Penetration Testing services. I am currently pivoting to AI Safety and AI Security.
Senior Application Security Analyst
Application Security and AI Security professional with 13 years of experience in secure software development, DevSecOps, vulnerability management, and security architecture. I specialize in SAST, DAST, SCA, threat modeling, secure design reviews, and secure SDLC. I provide practical insights on AI security, generative AI risk, OWASP guidance, and building security into the software development lifecycle.
Connectively In:
Founder & Lead Researcher at AppSec Santa
Application security researcher and founder of AppSec Santa, a curated comparison of 163+ application security tools across 10 categories. Published original research including the AI Code Security Study 2026 (tested 6 LLMs against OWASP Top 10 with 534 code samples) and the Security Headers Adoption Study (scanned 10,000+ websites). Helps security teams select the right AppSec tools through data-driven analysis.
Connectively In:
Penetration Tester at ZeroThreat.ai
I’m a Penetration Tester with a solid background in cybersecurity, specializing in uncovering vulnerabilities in web applications, APIs, and cloud environments. I focus on simulating real-world attack techniques to help organizations understand their risks and strengthen their security posture. My work includes ethical hacking, threat analysis, and integrating security automation into modern development workflows. I’m currently working at ZeroThreat.ai, building an automated penetration testing tool powered by AI.
Connectively In:
Cybersecurity Evangelist at Infinite Security
I am an Information Security Professional with years of experience in Application Security, Penetration Testing & Information Risk Management. I have rich experience with working on complex security engagements, from designing and executing of Application Security Strategy, Supply Chain Security to Compliance Consulting. Some of the topics that is fascinating to me is DevSecOps, Advancement and usage of AI in Application Security, Security Awareness and Vulnerability Management. My mission is to use my existing knowledge and expertise to assist organizations in making their applications more resilient. Always enthusiastic about sharing my insights and best practices with other security professionals and enthusiasts via talks and coffee chats.
Connectively In:
Senior DevOps & Cybersecurity expert at cyberupdates365
I am a Senior DevOps Engineer and Cybersecurity Analyst with extensive experience in cloud infrastructure security, threat intelligence, and zero-trust architecture. As the founder of CyberUpdates365, I actively track and analyze Advanced Persistent Threats (APTs), zero-day vulnerabilities, and global ransomware syndicates. I frequently provide media commentary and actionable insights on: • Major corporate data breaches and their technical fallout • Nation-state cyber warfare and espionage tactics • Consumer cyber safety (sextortion scams, phishing, card fraud) • DevSecOps and securing cloud deployments I am always available for quick, jargon-free, and fact-based quotes for journalists on tight deadlines.
Connectively In:
Cybersecurity Solutions Engineer
For over 20 years I've been on the front lines of cybersecurity, working for security vendors alongside global organisations to answer one critical question: how effective are your security measures against a real cyber attack? Day to day I'm a solutions engineer, helping leadership teams evaluate their security stack and build actionable roadmaps. These days I specialise in AI security: how organisations adopt AI safely, and how attackers already use it. I'm also the founder of CyberDesserts.com, a cybersecurity skills and knowledge hub, where I write about AI security, supply chain risk and cybersecurity careers. Topics I can comment on with confidence: • AI security: LLM and agent risks, prompt injection, and attacker use of AI • Security validation and exposure management: does your stack actually work • Software supply chain attacks and dependency risk • Ransomware and attacker innovation • Enterprise security strategy, culture and cyber resilience • Cybersecurity careers, skills and the talent market Track record: quoted by IT Brew and Cybernews, byline in The AI Journal, guest on the Smashing Security and Cybercrime Magazine podcasts, and recently on stage at the FCA for the ISC2 London Chapter. I respond quickly, speak in plain English, and back opinions with hands-on experience rather than vendor talking points. Ready-to-use bio and headshot: shakelahmed.com/bio
Connectively In:
Head of AI Security at Symosis Security
Pranav Saji is an AI Security and Generative AI expert based in the San Francisco Bay Area, currently Head of AI Security at Symosis Security and a Machine Learning Consultant at LinkedIn. He has delivered over $50M in business impact across Fortune 100 enterprises and startups, founded or led AI at 5+ companies, and built production AI systems spanning security analytics, agentic workflows, and large language model applications. A recognized voice on AI agent and MCP security, he publishes thought leadership in outlets such as HackerNoon and advises enterprises on securing generative AI and agentic systems. He is an accepted trainer at OWASP Global AppSec USA 2026 and a Core Judge for the USAII Global AI Hackathon. He holds a Master's in Computer Science (AI specialization) and CompTIA Security+ and Azure AI Engineer certifications.
Connectively In:
Principal Consultant in Vulnerability Management
Nikolas Lamprou is a Principal Consultant in Vulnerability Management with 15 years of hands-on experience in IT, spanning web development and e-commerce before specialising in cybersecurity. He holds an MSc and industry certifications including GCFR, SC-200, Security+, PNPT, eJPT, and BTL1, and works daily at the intersection of vulnerability management, penetration testing, and practical security defence. He is also the founder of Solve Tech Today, where he writes clear, no-nonsense guidance on security, Windows, and everyday tech problems.
Connectively In:
Senior Information Security Engineer at Scott Altiparmak
Scott Altiparmak is a Senior Information Security Engineer with 8+ years of experience spanning identity and access management, email security, and cloud security, with a focus on building and automating enterprise security programs end to end. He is the creator of Threat Terminal, a live game-based research platform studying how humans detect phishing in the generative AI era, and maintains open-source tools including Enterprise-Zapp and Threat Intelligence Tarot. He serves as Director of Programming for the South Florida ISSA chapter and speaks regularly at industry and academic events including Tech Hub Pulse 2026, PBSC CyberWeek, and the PBSC Cybersecurity Symposium.
Connectively In:
Chief Hacker at ioSENTRIX
Omair Manzoor is the Founder and CEO of ioSENTRIX, a cybersecurity firm specializing in Penetration Testing as a Service (PTaaS), application security, and AI/ML security assessments. ioSENTRIX serves mid-market and enterprise clients across financial services, healthcare, SaaS, and critical infrastructure — delivering continuous security testing through a hybrid human-AI approach with audit-ready deliverables mapped to SOC 2, ISO 27001, HIPAA, and PCI DSS frameworks. The company has been featured in FOX News, NBC, CBS, AP, ABC News, Business Insider, and Yahoo Finance, and is listed on AWS Marketplace and G2. Omair's areas of expertise include penetration testing strategy, PTaaS implementation, AI/LLM security and red teaming, application security program development, vibe coding security risks, compliance-driven security testing, and continuous threat exposure management (CTEM).
Connectively In:
Security Engineer at Turo
An experienced security professional helping security folks discover their best with HealthyByte. Previously built and led secure design functions at Insight, secured and protected thousands of websites per day at SiteLock alongside malware research at Sectigo, and currently building and scaling security for millions of rental cars at Turo. I’m curious and a lifetime learner across every field. Areas of Expertise & Interest: ‣ Enterprise/Corporate Security ‣ Infrastructure Security ‣ AWS Cloud Security ‣ Offensive Security (Red Teaming) ‣ Incident Detection and Response
Cybersecurity Lead Member of Technical Staff
Karthikeyan Ramdass a seasoned cybersecurity professional with over 18 years of experience securing mission-critical systems for leading Fortune 500 companies across industries including aviation, finance, automotive, and technology. I have played a pivotal role in protecting organizations such as Southwest Airlines, Wells Fargo, Morgan Stanley, Toyota Motors North America, AIG, Cognizant, Salesforce, and Deluxe Corporation. Specializing in application security, vulnerability management, secure architecture, and supply chain defense, led the design and implementation of enterprise-scale security frameworks, CI/CD pipelines, and advanced security testing solutions. Extensive experience in SAST, DAST, SCA, zero-day vulnerability management, and penetration testing, ensuring compliance with global standards such as NIST CSF, PCI DSS, and OWASP Top 10.
Connectively In:
Director and Cyber Security Consultant at Positiwise InfoTech PVT. LTD
Cyber Security Consultant and Tech Enthusiast with 10+ years of experience helping businesses strengthen digital security, optimize technology strategies, and drive innovation across the Cyber Security, Business Consulting, Technology, and SaaS industries. Skilled in identifying security risks, implementing resilient solutions, and advising organizations on secure digital transformation initiatives. Passionate about emerging technologies, PKI, cloud security, SaaS ecosystems, and helping startups and enterprises build scalable, secure, and future-ready systems. Known for combining technical expertise with business insight to deliver practical solutions that enhance operational efficiency, compliance, and cybersecurity resilience.
Connectively In:
Independent Security Researcher at Independent
Independent security researcher and penetration tester with 12 CVEs published through MITRE and credited by Apple, CISA, and the NSA, plus contributions to open-source projects including yt-dlp and AutoGPT. Coined EPI-SSRF (Egress-Path-Incomplete SSRF), a class of server-side request forgery affecting AI agent platforms. Author of two open-access papers on SSRF beyond HTTP and file-write attacks from untrusted archive and download metadata. M.S. in Cybersecurity, Pace University. Available to comment on vulnerability research, web application security, SSRF, AI agent security, and post-quantum cryptography.
Connectively In:
Cybersecurity specialist, researcher at centurialabs
Cybersecurity Expert | Cyberwarfare Strategist | Founder, Centuria Labs Research With over 25 years of specialized experience, Giovanni Battista Caria is a prominent figure in the European cybersecurity landscape. As the head of Centuria Labs Research, he has dedicated his career to advanced research in digital crime prevention and the development of impenetrable defensive architectures. His work bridges the gap between technical innovation and strategic analysis, making him a sought-after speaker at major international forums, including the International Security & Digital Council. Literary Contribution & Strategic Insight Caria’s extensive research has culminated in a series of influential works that address the evolving nature of digital threats from both a technical and legal perspective: The Black Book of Cybersecurity (Il Libro Nero della Cybersecurity): A deep dive into the structural flaws of modern digital infrastructure and the methodologies of high-level cyber attacks. The Invisible Front (Cybersecurity & Cyberwarfare): Co-authored as a comprehensive guide to the convergence of law, technology, and national security, this work serves as a manual for understanding state-sponsored digital conflict. The Architects of Shadow (PsyOps & Information Warfare): An analytical exploration of psychological operations and social engineering, detailing how digital influence can compromise national stability and institutional trust. Innovation in Defensive Systems Throughout his two-decade-long career, Caria has focused on creating innovative defensive frameworks designed to be mathematically and structurally resilient. His approach at Centuria Labs emphasizes proactive threat hunting and the implementation of security layers that go beyond traditional firewalls, focusing instead on system-level integrity and zero-trust principles. Strategic Vision A recognized expert in the legal and technical facets of the GDPR and cyber-law, Caria integrates regulatory compliance with hard-core technical defense. His philosophy is rooted in the belief that true cybersecurity requires a holistic understanding of the "invisible front"—the space where software engineering, international law, and geopolitical interests collide. "Cyber defense is not a static wall, but a dynamic architecture of constant anticipation and research." — Giovanni Battista Caria
Cybersecurity Director at ITRES
Co-Founder of SG6, ITRES and DEV6. Cybersecurity consultant with a deep technical background. More than 20 years of experience in the fields of IT Security, Cybersecurity, Security Research and IT Best Practices. Dozens of acredited CVE vulnerabilities since Y2K. I publish practical offensive/defensive research: vulnerability analysis, exploitation notes, reverse engineering, and hardening/detection takeaways.
Connectively In:
Security Engineer at NDIT
I have been working in security operations for nearly 2+ years, protecting 20,000+ state devices through automation. In my free time, I focus on learning and applying my knowledge to current problems in the industry, focusing on defending against AI devices. I have worked with cutting-edge security and AI tools built by companies like Microsoft, Palo Alto Networks, and Meta.
Connectively In:
Managing Director at Peneto Labs
I am a cybersecurity professional with over 18 years of experience in offensive security, penetration testing, and cyber defense. I focus on deeply understanding complex security challenges and developing practical, real-world solutions that strengthen organizations against evolving threats. I enjoy working across various security domains and approaching problems with a hands-on, analytical mindset. My colleagues and clients describe me as a hardworking, disciplined professional who remains calm and solution-oriented when handling high-risk incidents and challenging environments. My areas of expertise include vulnerability assessment, exploit development, incident response, network security architecture, and enterprise systems administration. I hold industry-recognized certifications such as OSCP, OSCE, GWAPT, GCIH, CCNA, and RHCE, which demonstrate my commitment to continuous learning and technical excellence.
Connectively In:
CEO at Software Secured
Connectively In:
Showing 20 of 815 experts
Publishers often seek expert quotes on timely Application Security topics such as zero-day vulnerabilities, secure API design, container security, and the implementation of security in CI/CD pipelines. Other popular areas include mobile app security, IoT device protection, and strategies for combating evolving cyber threats in web applications. Our experts provide valuable insights on best practices, industry standards, and innovative security solutions.
By joining Featured.com, Application Security experts can enhance their professional visibility and credibility. Our platform offers opportunities to be quoted in top-tier publications, potentially leading to increased industry recognition, speaking engagements, and consulting opportunities. It's an excellent way to share your insights on topics like threat modeling, secure code review, and emerging cybersecurity trends with a wider audience.
Featured.com offers access to a diverse range of Application Security experts, including penetration testers, secure coding specialists, cloud security architects, and DevSecOps professionals. Our platform connects you with thought leaders who have hands-on experience in areas such as web application firewalls, API security, and secure software development lifecycle (SDLC) practices.
Featured.com simplifies the connection process by maintaining a curated directory of Application Security experts with detailed profiles highlighting their specific areas of expertise. Publishers can easily search for and identify the most suitable experts for their articles or reports. Our platform facilitates efficient communication, allowing publishers to reach out to experts directly through our secure messaging system, streamlining the quote gathering process.