Security Analyst @ MetaLondon, UK

Sahil Ahamad

Application security, vulnerability research, and bug bounty and security program management.

I'm a cyber security enthusiast with 10+ years of cybersecurity experience and 8+ years specialising in application security, vulnerability research, and bug bounty and security programs management.

I've worked with companies including Nykaa and Zomato, leading the security engineering function at Zomato with a strong focus on application security and security program development. For the past 5 years, I've also been involved with Meta's Bug Bounty program, working closely on vulnerability triage, root-cause analysis, and translating real-world findings into shift-left security improvements.

I work closely with engineering teams to embed security early in the development lifecycle and help ship secure products at scale.

HackerOne profile →

Experience

  1. Feb 2021 — Present

    Security Analyst, Bug Bounty (Whitehat Program)

    Meta · London, UK
    • Triage and validate high-impact vulnerabilities across Meta-owned products and services.
    • Root-cause analysis (Hack, Python), turning bug bounty findings into shift-left fixes.
    • AI automation for triage workflows; researcher experience and coverage of under-researched surfaces.
  2. Mar 2019 — Feb 2021

    Security Engineer II

    Zomato · Gurgaon, India
    • Led the security engineering function across product verticals.
    • Helped build a company-wide vulnerability disclosure program.
    • Manual web and mobile pentesting, secure-by-design practices, and internal secure coding training.
  3. Aug 2018 — Mar 2019

    Security Engineer

    Nykaa · Mumbai, India
    • Application security assessments for e-commerce and mobile platforms.
    • Identified and remediated critical vulnerabilities; raised baseline security standards.
  4. 2018

    Winner, Hacken Cup

    HackenProof · Ukraine

    Won the HackenProof CTF at Hacken Cup 2018 and was invited to hack on site at the live event in Kyiv.

  5. Earlier

    Client application auditing

    SecurityEscape

    Where Swiftness originated, built for client auditing work.

  6. 2013 — Present

    Independent bug bounty researcher

    HackerOne · Bugcrowd · Intigriti · HackenProof

    Subdomain takeovers, broken access control and IDOR, authentication bypasses and data exposure, across public and private enterprise programs.

Tooling

SwiftnessX

Co-created with Rishiraj Sharma

Cross-platform note-taking and target-tracking app for penetration testers. Checklist management by target type, per-target notes for endpoints and recon data, and importable OWASP testing checklists. Originally a macOS app built at SecurityEscape, later rebuilt from scratch on Electron for Windows and Linux.

847 stars · GPL-3.0 · Electron

Recon-My-Way

Open-source automation scripts and workflows for asset discovery, DNS resolution, port scanning and cloud storage bucket auditing.

Community repositories

Wordlists, Android reverse-engineering setup notes (class-dump-z), and collaborative security documentation.

Writing

  • Medium Recon — my way

    The reconnaissance process for web application testing: where to start, subdomain pipelines, data storage buckets, and using GitHub for recon.

On this site

All posts →