Shoeb Patel

Shoeb Patel

Application Security Engineer, Amazon

London, United Kingdom

About

I am an Application Security Engineer at Amazon in London. I work on the Corporate Technology security team and own security for the web applications, APIs and AI systems behind HR, Finance and Legal. Before that I spent 3 years in AWS as the application security owner for the networking services: VPC, Load Balancing, Transit Gateway, PrivateLink, VPC Lattice and Cloud WAN, supporting 2000+ engineers.

Day to day I do threat modelling, code review, security testing, and automate the boring parts. The bugs I enjoy hunting most are design and authorisation flaws: broken object-level and function-level access checks and confused deputies. To scale that, I've encoded my review approach into Claude Code skills and PR-time checks that review every change across the portfolio against my own rules, an idea I first wrote about at Flipkart in How Flipkart Reacts to Security Vulnerabilities.

I have worked in application security for 7 years. Before Amazon I was a senior security engineer at Flipkart in Bangalore, owning security for the Seller and Support platforms, and before that one of the first hires on the security team at BrowserStack in Mumbai. I got my start through Google Summer of Code, building challenges for OWASP Juice Shop, and came back the next year as a mentor. I studied computer science at NIT Goa and moved to the UK in 2022.

Outside of work I do vulnerability research. I have reported issues to 30+ organisations, including Google, AWS, the U.S. Department of Defense, GitHub Security Lab, Oracle, Intel and Mastercard, hold 2 CVEs (CVE-2021-32817, CVE-2021-22255), and have contributed to OWASP Juice Shop, OWASP ZAP and other open-source security tools. I founded and captained the CTF team UnderDawgs from 2019 to 2021.

Experience

2025 - present
Amazon, Corporate Technology, Security Engineer II, London

Application security for the org's HR, Finance and Legal systems: threat modelling, design and code review, and penetration testing of new web applications, APIs and AI products, including prompt injection, MCP attack surface and authorisation architecture for agents.

  • Moved security review into the pull request: built a multi-agent review workflow and the org-wide detection ruleset behind it, which baselines each repository and then flags new issues and broken invariants on every change. Review time went from about a month to a week across 30+ repositories.
  • Security owner for an internal legal AI platform and for Amazon's identity-provider consolidation, finding and getting fixed a confused-deputy flaw in the former and a cross-tenant authorisation flaw in the latter before rollout.
  • Led bot-abuse mitigation for Amazon's public hiring portal, replacing several years of point fixes with a single layered strategy and the metrics to measure it.
  • Wrote the security training now given to every new apprentice engineer in the org.
2022 - 2025
Amazon Web Services, Security Engineer II, London

Application security owner for AWS networking services (VPC, Elastic Load Balancing, Transit Gateway, VPC Lattice, Cloud WAN): threat modelling, architecture and code review, and penetration testing across a portfolio serving 2000+ engineers.

  • Owned a full-scope security assessment of Transit Gateway, mapping an undocumented architecture end to end and surfacing 53 issues.
  • Influenced early-stage design of high-scale distributed systems, negotiating security trade-offs with service teams and leadership, and found critical flaws in production APIs that had been present since launch.
  • Found a remote code execution issue in a component deployed across thousands of internal services.
2019 - 2022
Flipkart, Security Engineer, then Senior Security Engineer (from Aug 2021), Bangalore

Application security owner for the Seller and Support platform teams: threat models, architecture and code reviews across web applications, microservices, the Kubernetes platform and mobile apps.

  • Designed the vulnerability feedback loop: every reported bug goes through root-cause analysis, variant analysis, a centralised fix, a permanent detection query in the scanning suite, and developer training material.
  • Deployed CodeQL across the top 50 repositories (10+ critical, 100+ valid findings) and led the triage programme.
  • Ran the private, invite-only bug bounty programme from triage to patch verification, and started an internal red team on the same model.
  • Built and hosted twice-yearly internal CTFs from real vulnerabilities found on Flipkart assets.
2019
BrowserStack, Security Engineer, Mumbai

One of the first hires on a new security team. Built application security from scratch: the company's first asset inventory, threat modelling and review process, red-team testing of production applications, continuous monitoring of public sources for leaked source code and credentials, and the team's first detection capability (Wazuh).

2018 - 2019
Google Summer of Code, OWASP Juice Shop, Student (2018), Mentor (2019)

Extended OWASP's flagship deliberately-vulnerable application with 11 new challenges (SSTI, SSRF, NoSQL injection, mass assignment, HTTP parameter pollution, XSSi, race conditions, Zip-Slip), each backed by working e-commerce features and tests (project report). Returned as a mentor the following year.

2015 - 2019
National Institute of Technology Goa, B.Tech. in Computer Science and Engineering

Writing and research

2022
Automata: a general-purpose automation platform. Reconnaissance and continuous leak monitoring at scale.
2022
How Flipkart reacts to security vulnerabilities. Flipkart Tech Blog (mirror). The vulnerability feedback loop described above.
2021
The secret parameter, LFR and RCE in Node.js apps. Assigned CVE-2021-32817 (collision with Github Security Lab).
2021
Server-side request forgery in Baserow. Assigned CVE-2021-22255.
2020
HTTP desync between HAProxy and Gunicorn. DEF CON CTF Qualifiers 2020.
2018
OWASP Juice Shop challenge pack. Google Summer of Code 2018 project report.

Older CTF write-ups and notes are on the archived blog.

Vulnerability research and open source

Reported vulnerabilities to 30+ organisations, including Google, Amazon Web Services, the U.S. Department of Defense, GitHub Security Lab (CodeQL), Oracle, Intel and Mastercard. Every report accepted as valid; maximum signal rating on HackerOne and Bugcrowd.

Open-source contributions: OWASP Juice Shop (19 merged pull requests, mostly the GSoC challenge pack), OWASP ZAP (XSLT injection scanner), NoSQLMap, Reconnoitre and Subfinder (Urlscan passive source).

Community and teaching

2025 - present
Author and instructor, application security course for apprentice engineers, Amazon Corporate Technology.
2019 - 2022
Organiser and challenge author, twice-yearly internal CTF, Flipkart.
2020
CTF organiser and challenge writer, BSides Ahmedabad.
2019 - 2021
Founder and captain, UnderDawgs CTF team.
2019
Mentor, Google Summer of Code (OWASP Juice Shop).

News

Jul 2025
Moved within Amazon to the Corporate Technology security team.
Oct 2022
Joined AWS in London as an application security engineer for the networking services.
Jul 2022
Published Automata.
Apr 2022
How Flipkart reacts to security vulnerabilities published on the Flipkart Tech Blog.
Aug 2021
Promoted to Senior Security Engineer at Flipkart.
2021
Assigned CVE-2021-32817 and CVE-2021-22255.
Jun 2020
Organised the CTF at BSides Ahmedabad.
Oct 2019
Joined Flipkart, Bangalore.
Jun 2019
Joined BrowserStack, Mumbai.
Apr 2019
Graduated from NIT Goa with a B.Tech. in Computer Science.
Apr 2018
Selected for Google Summer of Code with OWASP Juice Shop.

Miscellany