About Me

My name is Pratik Amin. I’m a security person who has spent the last 15+ years doing a bunch of different stuff. Starting off I was mostly focused on infrastructure security testing and then eventually went more and more into application security - but still focused on pentesting apps. I’ve spent the last several years being pretty heavily involved in many different aspects of our consulting practice.

I’ve had a pretty long journey in the security space - I started working as a sysadmin back in 2010 at Security Compass when it was a small 10-person company operating out of a closet. In the decade and a half since then the consulting practice has grown (through multiple acquisitions) into a team of over 100 people. During that time I went from being a shy, starry-eyed youth to a pretty opinionated leader on the team. I’ve had a chance to interview, hire, train and in many cases see folks graduate into really amazing security talents.

People tend to not spend a lot of time in pentesting, especially without moving to management or just shunning the industry all together - one of the things that has kept me sane over the last decade and a bit has been working with and teaching people who are new to the industry. Part of the reason I wanted to start this site was to put down (in something I control) some of my general thoughts about AppSec, security and just other ramblings.

I also put together a collection of AppSec and cloud security challenges for fun, and some presentations I’ve given over the years. If you want to get in touch, see Contact.