Senior Security Engineer · Google · CA, USA

Vaibhav Agrawal

Cybersecurity expert with 13 years of experience securing global-scale platforms with over 1 billion app downloads. Leading security for Google's Fitbit AI Health Coach and formerly Google Home ecosystem.

13+
Years Experience
Vaibhav Agrawal
CISSP Certified OSCP Certified OWASP AIVSS Technical Contributor AIUC-1 Consortium Member IEEE SVCC Program Committee BSides Chicago CFP Reviewer CRTP Certified CISSP Certified OSCP Certified Google AI Security Hackathon Winner OWASP AIVSS Technical Contributor AIUC-1 Consortium Member IEEE SVCC Program Committee BSides Chicago CFP Reviewer CRTP Certified
Technical Domains

Areas of Deep Expertise

Spanning application security, AI/ML risk, cloud infrastructure, mobile platforms, and IoT at global scale.

🤖

AI/LLM Security

Security architecture and review for AI agents. Contributing author to OWASP AI Vulnerability Scoring System (AIVSS) and AIUC-1 — the world's first certifiable AI agent security standard.

LLM Red-Teaming Prompt Injection OWASP AIVSS PHI/HIPAA
🏠

IoT & Smart Device Security

Ensuring the security of smart devices, protocols and the developer ecosystem that allows integration from thousands of vendors.

Matter Protocol IoT 750M+ Devices
☁️

Cloud & Infrastructure

Led security architecture for multi-cloud enterprise environments. Design and Implemented Vulnerability scanning engines, CSPM, HIDS.

FedRAMP CSPM Multi-cloud HIDS
📱

Mobile App Security

Secured apps with 100M+ app downloads (Fitbit) and 1B+ downloads (Google Home). Original research on Android de-obfuscation with LLMs via Androidmeda.

Android iOS SAST Reverse Engineering
📚

Security Research & Publications

Published across IEEE, Journal of Computer Information Systems, and major trade outlets.

AI security Cloud security Static application security testing
🔐

Security Tooling

Author of two widely-adopted open-source tools (Androidmeda, See-SURF) now part of BlackArch Linux. Androidmeda adopted in the MobileHackingLab AI/ML pentesting course.

Open Source SSRF Detection Android app deobfuscation
Career History

Professional Experience

Thirteen years of impact across Google, enterprise cloud platforms, and global financial systems.

July 2021 — PRESENT
Senior Security Engineer (Fitbit and Google Home)
Google · CA, USA
  • Leading security for Fitbit's entire ecosystem and its AI Personal Health Coach — a Gemini LLM-driven health platform with 100 Million+ app downloads.
  • Led security for the Google Home ecosystem — over 1 billion mobile app downloads and 750 million smart devices from thousands of vendors worldwide.
MARCH 2018 — JULY 2021
Senior Security Engineer
Coupa Software · CA, USA
  • Led security architecture of Coupa's Total Spend Management (TSM) cloud platform — orchestrating billions in spend for 3,000+ enterprise customers including Microsoft, Hilton, and UPS.
MAY 2014 — JUNE 2015
Software Security Engineer
Cognizant Technology Services · India
  • Lead developer for Enterprise Security Authentication, Authorization and Access Controls for Barclays global banking platforms.
MARCH 2011 — APRIL 2014
Software Developer
Capgemini India · India
  • Developed enterprise-scale software for SCOR, a leading global reinsurance organization based in France. Implemented data integrity controls for critical financial systems.
Scholarly & Industry Output

Research & Publications

Peer-reviewed research at the intersection of AI, cloud, and mobile security — cited globally by researchers and practitioners. Google scholar profile

2018

Log-Based Cloud Monitoring System for OpenStack

IEEE Conference Paper

IEEE
2025

Reducing Noise: Hybrid SAST-LLM Pipeline for Code Security

IEEE Security & Privacy Magazine

IEEE
2026

LLM Scalability Risk for Agentic-AI and Model Supply Chain Security

Journal of Computer Information Systems (JCIS)

Journal
2025

Dual-Use of Large Language Models (LLMs) and Generative AI in Cybersecurity

TechRxiv Pre-print

Pre-print


Trade Press Contributions

Industry Expert Analysis

InfoWorld
How pairing SAST with AI dramatically reduces false positives in code security
CSO Online
The 2 Faces of AI: How Emerging Models Empower and Endanger Cybersecurity
Cyber Defence Magazine
Prompt is Mightier Than the Phish: A Security Take on AI Agents
HelpNet Security
Engineering trust: A security blueprint for autonomous AI agents
Open Source Contributions

Original Security Tools

Two independently created security tools vetted and adopted into BlackArch Linux — a premier penetration testing distribution used by security researchers worldwide.

Androidmeda

AI-Powered Android Security Framework

First-of-its-kind framework utilizing Large Language Models to de-obfuscate Android application code and autonomously identify latent security vulnerabilities. Created in 2024.

Adopted into BlackArch Linux (2026)
Benchmarked by Fuzzinglabs for Android De-obfuscation
Integrated into MobileHackingLab AI/ML Pentesting Course
Presented at IEEE SVCC International Security Conference
See-SURF

SSRF Vulnerability Detection Engine

Advanced open-source scanner for automated detection of Server-Side Request Forgery (SSRF) vulnerabilities — a critical attack vector enabling access to internal infrastructure and cloud metadata. Enhanced with AI-driven analysis to detect complex patterns evading traditional scanners. Created in 2019.

Adopted into BlackArch Linux repository (2021)
Covered by Intigriti — crowdsourced security platform
Used by security professionals worldwide

OWASP AI Vulnerability Scoring System (AIVSS) — Technical Contributor

Contributing author to the OWASP AIVSS — one of the first comprehensive risk-scoring frameworks specifically designed for AI agents and agentic AI systems. This scoring system was adopted by AIUC-1.

AIUC-1 — Consortium Member

Contributing member to AIUC-1 — world’s first independent certification standard designed specifically for AI agents, focused on establishing benchmarks for safety, security, and reliability in autonomous AI systems.

Expert Recognition

Leadership & Professional Recognition

Appointed as peer reviewer, judge, and committee member for premier international security conferences and journals.

Peer Review

ACM CHI, ACM IUI, ACM DIS, ECIS, SAIS

Reviewed security research at the world's flagship covering security of Human computer interactions, enterprise-scale information frameworks and AI systems.

Program Committee

IEEE SVCC Proceedings · USA & South Korea

Appointed to lead technical evaluation for this international IEEE proceedings conference on AI, cloud, and infrastructure security.

Planning and Programm Committee

CISSE — Colloquium on Information Systems Security Education

Reviewed scholarly submissions on "Age of AI, Automation and Ambiguity" for one of the longest-running cybersecurity education forums (30-year history).

CFP Reviewer

BSides Chicago

Selected to curate the technical program for one of the most prominent practitioner-led security conferences in the U.S.

Advisory Board

BSides Vizag — India

Appointed Advisory Board Member, providing strategic technical guidance and oversight for the conference's international expansion and content selection.

AI Hackathon Judge

SVCC — USA & South Korea

Appointed as judge for AI Hackathon Demo & Co-Chair, evaluating security solutions built by industry professionals and researchers using AI.

Speaking Engagements

Conference Talks & Lectures

Invited speaker at premier international security conferences and universities, presenting original research.

Mobile Hacking Conference
March 2026
SAST-Genius — Hybrid LLM Framework for Code Scanning and Security
IEEE SVCC
June 2025
Android Security with AI/LLM as a Force Multiplier — Androidmeda Tool Presentation
BSides New Orleans
May 2025
Android App Security — with a dash of LLM
Credentials & Memberships

Certifications & Distinctions

🏆

CISSP

Certified Information Systems Security Professional · 2025

⚔️

OSCP

Offensive Security Certified Professional · 2020

🔴

CRTP

Certified Red Team Professional · 2020

OCWCD / OCJP

Oracle Certified Web Component & Java Developer

AIUC-1 Consortium Member

World's first AI agent security standard — developed alongside security executives from Salesforce, JP Morgan, and Oracle

IEEE Senior Member

Elevated to Senior Member grade — reserved for the top 10% of IEEE's 450,000+ global membership

ISC2 Professional Member

Member of the world's leading cybersecurity professional organization (CISSP designation)

Get In Touch

Open to Collaboration

I'm always open to discussing new security challenges, research, and collaboration opportunities.