Home

Application Security · Vulnerability SME

Security findings need context,
not noise.

Application Security | Vulnerability SME | AI-powered AppSec Workflows

I help enterprise teams assess, prioritize, and remediate vulnerabilities across large application portfolios. With 10 years of experience across technology, application security, vulnerability assessment, and remediation governance, I focus on turning security findings into clear risk decisions, practical remediation paths, and scalable AppSec workflows.

I also design and explore AI-powered AppSec workflows that improve triage, reduce cognitive overload, and help teams solve the right security problems with better context.

Himanshu JoshiAVP · Citi · AppSec VA
10Years in technology, security & AppSec
100+Global applications supported across VA remediation, risk assessment & remediation guidance
25+Security cases reported and remediated across Zoom, Atlassian, Asana, Red Hat, Google and more.
4×Microsoft MSRC acknowledgements

About

Bridging enterprise AppSec and intelligent remediation.

As a Subject Matter Expert in Vulnerability Assessment and remediation, I bring 10 years of experience across technology, application security, vulnerability analysis, risk assessment, and remediation guidance for enterprise applications.

My work spans DAST, SAST, enterprise penetration testing, API security, global VA compliance, security governance, and process optimization. I focus on helping teams understand which vulnerabilities matter, why they matter, and how they can be remediated in a practical, risk-based way.

At Citi, I serve as Assistant Vice President, Senior Application Vulnerability Assessment Analyst, supporting vulnerability remediation, severity assessment, risk guidance, and stakeholder alignment across global application portfolios.

Previously, as Head of Security Research at ProtectOnce, I led security research and contributed to AWS-focused cloud security work, API security, and AppSec capabilities. Before moving deeper into application security, I spent 3 years as a Project Manager in technology startups, coordinating product, engineering, delivery, and stakeholder communication.

As an Independent Security Researcher, I have reported security issues across organizations including Zoom, Atlassian, Asana, Red Hat, and Google, with multiple cases remediated. I have also received Microsoft MSRC acknowledgements and delivered technical talks on security best practices.

“The real challenge isn’t just finding vulnerabilities — it’s knowing which ones matter, why they matter, and how to get them fixed.”

Vulnerability AssessmentSAST / DASTOWASP Top 10API SecurityCloud SecurityRisk GovernanceAI-powered Workflows

Focus Areas

Where I create impact

Depth across assessment, remediation, governance, and the emerging frontier of AI-assisted AppSec.

VA

Vulnerability Assessment & Risk Management

Enterprise-scale assessment, prioritization, and risk-based decision support across complex portfolios.

AST

Application Security Testing

SAST, DAST, penetration testing, API security, and OWASP-aligned practices across modern application stacks.

RS

Remediation Strategy

Lifecycle guidance, severity evaluation, stakeholder alignment, and closure-focused remediation.

GRC

Security Governance & Compliance

Global VA compliance, reporting discipline, risk tracking, and process optimization to strengthen security posture.

CLD

Cloud & API Security

Security focus across AWS environments, cloud-native architectures, API security, and enterprise systems.

AI

AI-powered Security Workflows

Designing and exploring AI-assisted AppSec workflows for contextual triage, intelligent prioritization, remediation guidance, and better security decision-making.

Experience

Selected experience

A focused view of roles where I’ve driven security, remediation, research, and technology outcomes.

Current · Enterprise Security

Citi — AVP, Senior Application Vulnerability Assessment Analyst

Enterprise vulnerability remediation, VA lifecycle management, severity assessment, risk guidance, and stakeholder coordination across global application portfolios.

Security Research

ProtectOnce — Head of Security Research

Led research across OWASP Top 10, API security, AWS cloud security, vulnerability assessment, and modern AppSec product capabilities.

3 Years · Technology Startups

Project Manager, Technology Startups

Coordinated product, engineering, delivery, and stakeholder communication across fast-moving technology environments.

Independent Research

Security Researcher

Reported and responsibly disclosed security issues across organizations including Zoom, Atlassian, Asana, Red Hat, and Google, with multiple cases remediated.

Future of AppSec

Building intelligence into AppSec remediation.

Beyond day-to-day enterprise security work, I explore how AI can help AppSec teams reason through vulnerability context, prioritize remediation, and reduce cognitive overload. My focus is on designing and building AI-powered security workflows that help teams understand risk, make better decisions, and solve the right AppSec problems faster.

  • AI-powered workflows that bring context to every finding
  • Contextual triage that surfaces what actually matters
  • Remediation guidance built around risk, ownership, and practical closure
  • Modern AppSec intelligence for enterprise-scale teams

Contact

Let’s connect

Interested in Application Security, vulnerability remediation, AI-powered AppSec workflows, or security product collaboration? I’d be glad to hear from you.

© 2026 Himanshu Joshi · Application Security & Vulnerability Assessment