About / Sma Das
Security should change how a system is built.
I am an application security engineer at Warner Music Group in New York. I work across product security, offensive testing, DevSecOps, and the systems that turn technical findings into measurable risk reduction.
Depth first. Action always.
My work starts with understanding how a system can fail: reviewing architecture and code, modeling credible threats, validating controls through offensive testing, and following attack paths far enough to establish real impact. The outcome should not be a score or a long queue of disconnected findings. It should be evidence, priority, and a practical route to a stronger system.
At Warner Music Group, I established and scaled the application security program protecting business-critical systems that support approximately US$7 billion in revenue across 50 territories. My public portfolio also documents DevSecOps workflows spanning static analysis, secret scanning, dynamic testing, security-as-code pipelines, and an operational platform that unifies security data.
Public work and writing
Outside day-to-day security engineering, I build open-source developer tools and write about the changing shape of security. My projects include better-swagger-types, a TypeScript CLI for OpenAPI and Swagger schemas, and a focused publication for long-form research and technical field notes. The canonical writing site is sma-das.blog.
Earlier experience includes security engineering work with the Google Cybersecurity Clinic and IBM, plus penetration-testing and training-environment work with TryHackMe. Public profile links are available through GitHub and LinkedIn.