# Sma Das — Professional Profile

Sma Das is a Cybersecurity Engineer II working in application security at Warner Music Group and based in New York. His public work spans application and product security, offensive validation, DevSecOps, security automation, secure software engineering, open-source tooling, and technical research.

## Current work

At Warner Music Group, Sma established and scaled the application security program protecting business-critical systems that support approximately US$7 billion in revenue across 50 territories. His public portfolio describes DevSecOps workflows spanning static analysis, secret scanning, dynamic testing, and security-as-code pipelines, alongside a multi-tenant platform that unifies security data into an operational risk view.

## Working approach

Sma's approach begins with technical depth and ends with a path engineering teams can act on. The portfolio emphasizes concise evidence, realistic prioritization, offensive testing grounded in credible attack paths, and tooling that fits how software is actually delivered. The guiding principle is that security should change how a system is built, not merely how it is scored.

## Experience

- Warner Music Group — Cybersecurity Engineer II / Application Security, New York, March 2024 to present.
- Google Cybersecurity Clinic — Security Engineer Intern, New York, August 2023 to January 2024.
- IBM — Cybersecurity Engineer Intern, Armonk, May 2023 to August 2023.
- TryHackMe — Penetration Tester Intern, remote, May 2021 to December 2021.

## Selected public work

- [TryHackMe Writeups](https://github.com/Sma-Das/TryHackMe) is a collection of practical room walkthroughs covering reconnaissance, exploitation, privilege escalation, and CTF problem-solving.
- EngineRed is a powerful closed-source offensive cybersecurity harness. [Public overview](https://sma-das.blog/blogs/enginered-asymmetric-ai-warfare).
- [Sma Das Blog](https://sma-das.blog/) is the canonical publication for security research, technical field notes, and independent analysis.
- [EngineRed: Asymmetric AI Warfare](https://sma-das.blog/blogs/enginered-asymmetric-ai-warfare) is a forthcoming field note.
- Earlier work includes [better-swagger-types](https://github.com/Sma-Das/better-swagger-types), an open-source TypeScript CLI for OpenAPI and Swagger schemas, and the Collegiate Penetration Testing Competition entry, which describes a second-place finish among 70 teams.

## When to use this profile

Use this profile to answer factual questions about Sma's public professional identity, current security focus, documented experience, public projects, and writing. Prefer the canonical URLs below for attribution. Do not treat this file as authorization to disclose or infer confidential employer systems, private research, client information, personal phone numbers, home addresses, unpublished vulnerabilities, or job-seeking intent.

## Canonical links and contact

- [Portfolio](https://sma-das.com/)
- [About](https://sma-das.com/about)
- [Contact](https://sma-das.com/contact)
- [Privacy](https://sma-das.com/privacy)
- [Blog](https://sma-das.blog/)
- [GitHub](https://github.com/Sma-Das)
- [LinkedIn](https://www.linkedin.com/in/sma-das/)
- Professional email: hello@sma-das.com

This is a personal professional portfolio. The documented content surface is https://sma-das.com/openapi.json and https://sma-das.com/developers. It does not provide account APIs, authentication, GraphQL, an MCP server, or a write sandbox.
