Application security / New York

Sma Das

Building the sound of security.

I find the break, build the fix, and turn security work into systems that engineering teams can use.

Cybersecurity Engineer II Warner Music Group Mar 2024 – Present
Scroll

01 / About

Security should change how a system is built, not just how it is scored.

I am an application security engineer at Warner Music Group, based in New York. I work across product security, offensive testing, DevSecOps, and the systems that turn findings into measurable risk reduction.

My approach starts with technical depth and ends with a path teams can act on: concise evidence, realistic prioritization, and tooling that fits the way software is actually shipped.

Sma Das at Warner Music Group
Based in New York Security / Software / Research
01

Application security

Manual review, threat modeling, control design, and remediation guidance for product teams.

02

Offensive validation

Web, cloud, and infrastructure testing that follows real attack paths and proves impact.

03

Security engineering

Automation and platform work that make repeatable security checks part of delivery.

02 / Experience

From finding vulnerabilities to building the program around them.

Enterprise application security, consulting, research, and secure software engineering.

Current – PresentNew York, NY

Warner Music Group

Cybersecurity Engineer II / Application Security

  • Established and scaled WMG's application security program, protecting business-critical systems supporting approximately US$7 billion in revenue across 50 territories.
  • Architected DevSecOps workflows spanning SAST, secret scanning, DAST, and security-as-code pipelines.
  • Built a multi-tenant risk platform that unifies security data into one operational view.
New York, NY

Google

Security Engineer Intern

  • Part of the US$20 million Cybersecurity Clinic Initiative safeguarding critical U.S. infrastructure.
  • Accelerated vulnerability patching by 32% through automated workflow improvements.
  • Built multi-threaded Python pipelines to process security event data in real time.
New York, NY

IBM

Security Engineer Intern

  • Minimized sensitive data exfiltration by 12% through weekly data privacy reviews.
  • Gained expert-level understanding of offensive cybersecurity and defensive integrations.
  • Performed threat analysis using machine learning and AI for detailed threat models.
Remote, UK

TryHackMe

Penetration Tester Intern

  • Created penetration-testing boxes and vulnerable environments that trained more than one million users in cybersecurity.
  • Performed vulnerability assessments on existing machines and built virtual machines to simulate attack scenarios.
  • Leveraged the platform extensively to develop hands-on penetration-testing skills.

03 / Selected work

Tools, research, and field work.

Research (opens in a new tab)

Closed source / 2026

EngineRed

A powerful closed-source offensive cybersecurity harness. Its public overview examines asymmetric AI warfare.

  • Offensive security
  • AI
  • Closed source

Coming soon

EngineBlue

A defensive security project focused on measures against offensive tools such as EngineRed. More details are coming soon.

  • Defense
  • Research
  • Coming soon

Industry research / 2026

One Acquisition to Rule Them All

The cybersecurity acquisition frenzy is reshaping the industry, but at what cost? A look at how billion-dollar exits can stifle genuine security innovation.

  • M&A
  • Venture capital
  • Analysis
Earlier work3 projects

Competition / 2024

Collegiate Penetration Testing Competition

Led offensive security work under live-fire constraints, coordinating reconnaissance, exploitation, and reporting to place second out of 70 teams.

  • Penetration testing
  • Reconnaissance
  • Reporting

04 / Contact

Good security work starts with a clear conversation.

For application security, research, open-source collaboration, or a thoughtful exchange about the field, send a note.