Sidharth B NairPrincipal Security Architect

Principal Security Architect · Doverunner

Sidharth B Nair

Application, API and mobile security for 8+ years, now across product and internal security at Doverunner: RASP analysis and detections, multi-DRM content protection, and building security into how teams ship.

Interactive: query this portfolio like an API.

Request
GET HTTP/1.1
Host: sidharth.sec
Accept: application/json
User-Agent: recruiter/1.0

or Ctrl+Enter

Response 200 OK
{
  "name": "Sidharth B Nair",
  "role": "Principal Security Architect",
  "company": "Doverunner Inc",
  "location": "Kochi, Kerala, India",
  "years": "8+",
  "focus": ["product security", "internal security", "RASP detections", "multi-DRM content protection"]
}

01 Summary

Security that holds up from design to production.

I'm a Principal Security Architect at Doverunner, working across product and internal security. On the product side I analyze RASP and build detections for it, alongside multi-DRM content protection. Internally the scope runs from vulnerability management and incident response to identity and access, monitoring, cloud security, compliance, third-party risk and DLP. I joined in 2023 as a Senior Threat Analyst and moved into this role in June 2026.

Before Doverunner I led internal pentesting and third-party risk at Nykaa, and spent over four years doing application security consulting at SISA for clients across industries, most of them in banking and financial services. Across all of it the aim is the same: find what breaks early, and build the controls that keep it fixed.

I've spoken at droidcon India 2025 on secure mobile apps and at ISACA Silicon Valley on Log4Shell exploitation and mitigation, and I've done bug bounty research since 2016.

Sidharth B Nair speaking at a podium at droidcon India 2025
Speaking at droidcon India 2025
  • 8+years in application security
  • −50%security incidents after authentication overhaul (Nykaa)
  • +30%assessment efficiency from standardized methodology (SISA)

Focus areas

  • Application security

    Pentesting and VAPT, SAST/DAST and source code review across web and thick-client applications.

  • API security

    API pentesting and review as part of web and mobile assessments for clients across industries, with a focus on banking and financial services.

  • Mobile security

    Android and iOS assessments, including reversing runtime protections (RASP), finding what they detect and miss, and building new detections.

  • Content protection

    Multi-DRM content protection at Doverunner, including Widevine.

  • Product security (shift-left)

    Threat modeling and architecture reviews early in design, secure SDLC integration, SAST/DAST testing frameworks, CI/CD security checks, and security training for development teams.

  • Internal security

    Vulnerability management, incident response, identity and access, security monitoring, cloud and infrastructure security, DLP, awareness programs reporting to executive leadership, and remediation across teams.

  • Governance, risk & compliance

    Security policy, compliance and audits including PCI-DSS, third-party and vendor risk assessments, and security architecture reviews.

  • Research & threat analysis

    Bug bounty since 2016, vulnerability research, and talks at droidcon India and ISACA Silicon Valley.

02 Experience

Where I've worked

Jun 2026 – PresentDoverunner IncPrincipal Security Architect
  • Promoted from Senior Threat Analyst after nearly three years at Doverunner.
  • Product security: analyze RASP across Android and iOS internals, build and improve its detections, and work on multi-DRM content protection.
  • Internal security: vulnerability management, incident response, identity and access, security monitoring, cloud and infrastructure security, compliance and audits, third-party risk, and security architecture.
Jul 2023 – May 2026Doverunner IncSenior Threat Analyst, Product Security
  • Worked across product and internal security, including RASP and multi-DRM content protection.
  • Owned end-to-end security work: DLP implementation, policy, and SAST/DAST testing frameworks across web and mobile.
  • Ran security awareness as Security Awareness Manager, reporting to executive leadership.
  • Drove remediation of critical findings with cross-functional teams.
Jun 2022 – Jul 2023Nykaa E-RetailSenior Security Engineer, Technology
  • Cut security incidents by 50% by improving authentication mechanisms.
  • Led internal pentests, vendor risk assessments and VAPT; kept PCI-DSS compliance on track.
  • Added architecture reviews and CI/CD security checks.
Dec 2017 – May 2022SISA Information SecurityAppSec Consultant (WarLabs)
  • Progressed Associate Consultant → Senior Associate → Consultant over 4.5 years.
  • Standardized testing methodology, improving assessment efficiency by 30%.
  • Led pentests and PCI DSS audits for clients across industries, with a focus on banking and financial services; presented findings to C-level; mentored juniors.
  • Demonstrated live Log4Shell exploitation and mitigation for ISACA Silicon Valley.
2016 – PresentBug bountyIndependent Security Researcher
  • Responsible disclosures via HackerOne and vendor programs; acknowledged by Fitbit and AlienVault.

03 Talks & research

Talks and research

ResearchAndroidiOS

RASP analysis: Android and iOS internals

Reversing runtime protections on both platforms, identifying what they detect and miss, and building and improving detections.

Talkdroidcon India 2025

Don’t Trust the Device: A Developer’s Guide to Secure Mobile Apps

Conference talk on building secure mobile apps, delivered at droidcon India 2025.

Watch the recording ↗

WebinarISACA Silicon Valley · Jan 2022

Log4Shell: exploit & mitigate

Webinar on the Apache Log4j vulnerability (CVE-2021-44228, CVSS 10.0): live exploitation, impact and mitigation.

Event page ↗

PresentationSISA

How Apache Log4j vulnerability can impact your organization

Company-wide presentation at SISA on the Apache Log4j vulnerability and what it means for an organization.

Watch the recording ↗

Research2016 – Present

Bug bounty acknowledgments

Responsible disclosures through HackerOne, with acknowledgments from Fitbit and AlienVault Security.

Product securityMulti-DRM

Content protection analysis

Security assessment of multi-DRM implementations and content protection mechanisms, including Widevine.

04 Toolkit

Skills and tools

Testing
Web & API pentestingSAST / DASTSource code reviewBinary & runtime analysisThick/thin client
Mobile & RASP
RASP analysisRASP detection engineeringReverse engineeringAndroid & iOS internalsRoot / jailbreak detectionAnti-hooking & anti-tamperMASVS-RESILIENCE
Tools
FridaobjectionGhidraIDA ProjadxapktoollldbMobSFBurp Suitemitmproxy
Shift-left & design
Threat modelingArchitecture reviewSecure SDLCCI/CD securityDeveloper security training
Internal & governance
Vulnerability managementIncident responseIdentity & accessSecurity monitoringCloud & infrastructure securityCompliance & auditsPCI-DSSThird-party riskSecurity architectureDLPSecurity policySecurity awareness
Domains
Product securityMulti-DRM content protectionIoT

05 Contact

Get in touch

Open to senior application and product security roles. Based in Kochi, Kerala, India.

Phone: ██████████ available on request by email