Shubham Golam

Shubham Golam

Senior Security Consultant

NotSoSecure

About Me

Shubham is an information security professional with 7+ years of experience in penetration testing, vulnerability research, and security tooling. He specializes in web, mobile, API, AI/LLM, and thick client security, with a sharp focus on manual exploitation and real-world attack simulation. Beyond security, he enjoys creative pursuits, reading about science and space, and unwinding in nature.

Interests
  • Web and API Security
  • Mobile Security
  • AI/LLM Security
  • Network Assessment
  • Security Automation
  • Thick Client Assessment
  • Source Code Review
Education
  • Bechlor of Engineering, 2018

    Goa University

Professional Journey

 
 
 
 
 
Senior Security Consultant
April 2022 – Present

Responsibilities include:

  • Leading end-to-end penetration testing for Web apps, Mobile apps, AI/LLMs, Networks, Thick Clients, and Source Code Review for enterprise clients
  • Building and maintaining training labs and CTF environments
  • Researching new vulnerabilities, attack vectors and pentest techniques
  • Developing custom scripts, automated testing pipelines, and internal pentesting utilities
  • Coordinating scope, timelines, and deliverables with client teams
  • Conducting technical debriefs explaining vulnerabilities, impact, and remediation
  • Performing technical report reviews
 
 
 
 
 
Associate Product Developer
June 2020 – April 2022 Pune

Responsibilities include:

  • Performing security assessments of web, mobile, and thick client for product features across new releases and existing product lines
  • Documenting vulnerabilities with technical severity ratings, reproduction steps, and proof-of-concept exploits
  • Coordinating with product and engineering teams for vulnerability triage, patch validation, and regression retests
  • Designing and developing CTF challenges with real-world attack scenarios for technical hiring evaluation
  • Triaging newly disclosed zero-days and CVEs against internal product tech stacks to identify vulnerable products and coordinating with development teams for prioritized fixes
 
 
 
 
 
Associate Security Consultant
March 2019 – June 2020 Pune

Responsibilities include:

  • Performing manual security assessments of web, mobile, and APIs
  • Documenting vulnerabilities with severity ratings, reproduction steps, and proof-of-concept exploits
  • Monitoring emerging threats, CVEs, and offensive techniques to stay current with the attack landscape
  • Delivering hands-on web and Android security training for recruitment program
 
 
 
 
 
Associate IoT Security Consultant
December 2018 – March 2019 Pune

Responsibilities include:

  • Conducting security research on IoT devices including firmware analysis and vulnerability identification
  • Assisting in web, mobile, and API penetration testing engagements under senior guidance
  • Analyzing IoT communication protocols and identifying attack surfaces across embedded systems