Harsh Bhetaria
Lead Security Engineer
Welcome to my corner of the internet where I showcase my professional work and personal projects. Passionate about cybersecurity, infrastructure automation, and building secure, scalable solutions.
🔐 Resume SHA256: fb5b4c99a60f719669a36122aa952bfc2767e89ca4da5179da92f052435a1054 (click to copy)
💾 Pro tip: Try Ctrl+Shift+S for security mode, or type "hacktheplanet"
About Me
Building Secure Infrastructure, One System at a Time
Senior Product Security Engineer @ Slack
Proactive threat modeling & secure code review for millions of users
Click to learn more →What I Do at Slack:
- 🏗️ Architecture Reviews: Helping teams design secure system architectures and identify security risks
- 📱 Mobile Security Program: Designed and implemented comprehensive mobile security framework
- 🚨 Incident Response SME: Serving as subject matter expert for security incident response
- 🎯 Hacking Events: Running internal security events to improve security awareness and skills
- 🔧 Vulnerability Remediation: Advising teams on how to effectively fix security vulnerabilities
- 🛡️ Security Integration: Helping teams integrate security considerations into their planning processes
- 📋 Security Reviews: Performing comprehensive security assessments of systems and applications
3+ years of experience securing enterprise communication for millions of users worldwide
Security Engineer @ Amazon
Large-scale infrastructure security and cloud security architecture
Click to learn more →What I Did at Amazon:
- 🎯 Service Priority System: Designed priority framework to determine which services require security focus
- 🚨 Incident Response SME: Served as subject matter expert for security incident response
- 🔥 Critical Incident Support: Provided hands-on assistance during high-severity security incidents
- 🔐 AuthN/AuthZ Frameworks: Designed new authentication and authorization frameworks for product team adoption
Experience securing critical infrastructure serving millions of customers worldwide
Senior Security Consultant @ Synopsys
Application security testing and secure software development lifecycle
Click to learn more →What I Did at Synopsys:
- 👥 Team Leadership: Led a team of 5 security professionals
- 📚 Training Program Head: Led training initiatives for new hires and designed comprehensive onboarding courses
- 🎯 Recruiting Team Member: Conducted multiple interviews as part of the recruiting team
- 🏢 Practice Leadership: Led a security practice within the organization
Leadership experience in security consulting with focus on team development and organizational growth
CISSP Certified
Expert in penetration testing, vulnerability assessment & cryptography
Click to learn more →Cybersecurity Expertise:
- 🎯 Penetration Testing: Ethical hacking to identify vulnerabilities
- 🔐 Cryptography: Implementation of secure encryption protocols (AES, HMAC)
- 🌐 Network Security: Designing secure network architectures
- 🛡️ Application Security: Code analysis and secure development practices
- 📚 Continuous Learning: Staying current with emerging threats and security frameworks
CISSP certification demonstrates mastery across 8 domains of cybersecurity
Homelab Enthusiast
Self-hosted password vault, automation & secure remote access
Click to learn more →My Homelab Infrastructure:
- 🔐 Password Vault: Self-hosted Bitwarden for complete password control
- 🏠 Home Automation: Smart home integration with privacy-first approach
- 🌐 Reverse Proxy: Cloudflare Access for secure remote connections
- 📊 Monitoring Stack: Grafana + Prometheus for infrastructure visibility
- 🐳 Containerization: Docker swarm for service orchestration
Experimenting with enterprise security concepts in a controlled environment
Security-First Mindset
Every system designed with security as the foundation, not an afterthought
Click to learn more →My Security Philosophy:
- 🏗️ Security by Design: Integrating security from the ground up, not bolting it on later
- 🔄 Continuous Improvement: Regular security assessments and iterative hardening
- 👥 Education First: Training teams to think security-first in every decision
- ⚖️ Risk-Based Approach: Balancing security controls with business functionality
- 🔍 Transparency: Open communication about security posture and improvements
"Security is not a product, but a process" - Building resilient systems through thoughtful design
🚀 Skills
🏆 Certifications
🛡️ CISSP - Certified Information Systems Security ProfessionalFeatured Projects 🔍 View source for hidden flags
🏢 Professional Experience
Proactive Security Engineering
Leading product security initiatives at Slack, focusing on proactive threat modeling, secure code review, and vulnerability assessment across enterprise communication platform serving millions of users.
Application Security & Penetration Testing
Conducting comprehensive security assessments including penetration testing, vulnerability analysis, and application security reviews. Implementing security controls across cloud infrastructure and communication systems.
Cryptography & Network Security
Designing and implementing cryptographic solutions and network security protocols. Expertise in encryption technologies, secure communication protocols, and privacy protection for enterprise platforms.
🚀 Personal Projects
HMAC Implementation & Security Analysis
Custom implementation and analysis of Hash-based Message Authentication Code (HMAC) with comprehensive security testing and documentation.
Cloudflare Analytics Dashboard
A modern, Grafana-style dashboard for monitoring Cloudflare analytics in real-time. Built with React, TypeScript, and Recharts with dual-mode operation.
Homelab Monitoring Stack
Comprehensive monitoring solution for distributed homelab setups using Grafana, Prometheus, and AlertManager. Features Docker deployment, Home Assistant integration, and smart alerting.
Get In Touch
Interested in collaborating, discussing homelab setups, or just want to chat about tech? I'd love to hear from you!
🔐 PGP/GPG Public Key
1BCF 4D18 E05A F929 399A C0D3 CBAA B1F5 DCAD E586
For secure communication: Use this key to send me encrypted messages or verify my signed communications. You can import it with: gpg --import