About Credentials Education CVEs Talks Contact

Hi, I'm Kailash_

Senior Cybersecurity Engineer

Cybersecurity professional with 9+ years of experience securing modern applications and enterprise infrastructure across cloud platforms, containerized environments, and DevOps ecosystems. Expertise spans security architecture, cloud security, risk assessment, threat hunting, penetration testing, vulnerability management, and threat modeling. Strong experience in embedding security within CI/CD pipelines, container security monitoring, DevSecOps practices, and incident response to proactively detect and mitigate emerging threats. Passionate about building resilient, scalable, and secure infrastructure while actively mentoring and contributing to the cybersecurity community through OWASP Kathmandu and Pentester Nepal.

aboutme.md
kb@security

$ whoami

aboutme.md

$ cat role.txt

Senior Cybersecurity Engineer

$

9+ Years Experience
9 Certifications
5 CVE Disclosures
2 Communities Led
About

Who I am

Professional profile, skills, and organizations helped through responsible vulnerability disclosure.

About Kailash Bohara

Cybersecurity Engineer with 9+ years of experience designing and implementing secure systems across applications, networks, cloud, and containerized environments. My expertise includes security architecture, Zero Trust design, penetration testing (web, mobile, API, and network), application security, vulnerability management, and DevSecOps pipeline security.

Hands-on experience enhancing enterprise security through improvements in SOC, MDR, DLP, cloud security, and threat detection, as well as automating security processes to streamline operations and improve resilience. My work supports organizations in achieving and maintaining compliance with standards such as SOC 2, HITRUST, and ISO 27001 by strengthening audit readiness, risk management, and operational security practices.

Helped Secure

Helped secure Google, Facebook, Microsoft, AWS, Adobe, Adafruit, Alibaba, Toyota, Cloudinary, Dutch Government, OpenCart, MDaemon Webmail, Dell, United Nations, ManageEngine, GoDaddy, HP, and others by responsibly reporting security vulnerabilities in their systems.

Google Google
Facebook Facebook
Microsoft Microsoft
AWS AWS
Adobe Adobe
Adafruit Adafruit
Alibaba Alibaba
Toyota Toyota
Cloudinary Cloudinary
Dutch Government Dutch Government
OpenCart OpenCart
MDaemon MDaemon
Dell Dell
United Nations United Nations
ManageEngine ManageEngine
GoDaddy GoDaddy
HP HP

Skills & Expertise

Offensive Security

  • Penetration Testing (Web, API, Network, Mobile)
  • Vulnerability Assessment & Management
  • Secure Code Review
  • Threat Hunting

Cloud & DevSecOps

  • Cloud Security (AWS, GCP, Azure)
  • DevSecOps & CI/CD Security
  • Container & Kubernetes Security
  • Security Monitoring (SIEM/SOAR)

Architecture & Governance

  • Security Architecture & Zero Trust
  • Identity & Access Management
  • Risk Assessment & Threat Modeling
  • Compliance (ISO 27001, SOC 2, HITRUST, HIPAA)
Credentials

Experience & certifications

A decade of offensive and defensive security work, backed by industry credentials and trainings.

Experience

View all
2023 - Present

Senior Cybersecurity Engineer

Cedar Gate Technologies

  • Manage internal and external audits, vulnerability assessments, network/application penetration testing, and secure code review.
  • Analyze threat alerts from SIEM/EDR, Privilege Access Management (PAM), and Data Loss Prevention (DLP) tools.
  • Review and strengthen CI/CD pipelines, deployment configurations, and container security using SAST, DAST, and SCA scans.
  • Conduct secure code reviews, triage application security findings, and partner with development teams on remediations.
  • Perform cloud security posture assessments and support CSPM by monitoring, triaging, and remediating cloud findings.
  • Conduct red team assessments, proactive threat hunting, and external attack surface evaluations.
  • Manage container security across images, registries, and runtime environments.
  • Implement security controls for ISO 27001, HIPAA, HITRUST, and SOC 2 compliance.
  • Configure and fine-tune security controls to support zero-trust implementation.
2018 - 2023

Senior Penetration Tester

Eminence Ways Pvt. Ltd.

  • Perform Information Systems Audit and Vulnerability Assessment of network and application systems.
  • Conduct SAST, DAST, and SCA scans aligned with OWASP Top 10 and SANS Top 25 standards.
  • Execute penetration testing for web applications, APIs, networks, thick/thin clients, and Android/iOS mobile apps.
  • Develop CTF challenges and deliver security training for clients.
  • Perform red team assessments and threat hunting.
2022 - Present

Chapter Leader

OWASP Kathmandu

OWASP Kathmandu is a non-profit cybersecurity community dedicated to strengthening information security awareness and building a collaborative security ecosystem in Nepal. The chapter organizes regular cybersecurity meetups, Capture-the-Flag (CTF) events, and live hacking competitions to promote learning, knowledge sharing, and hands-on security skills

Certifications & trainings

View all
Certified Ethical Hacker (CEH)

Certified Ethical Hacker (CEH)

EC-Council · 2022

Certified in Cybersecurity (CC)

Certified in Cybersecurity (CC)

ISC² · 2023

Vulnerability Management Detection & Response

Vulnerability Management Detection & Response

Qualys · 2022

Network Security Associate

Network Security Associate

Fortinet

Splunk User Behavior Analytics

Splunk User Behavior Analytics

Splunk

ISO/IEC 27001 Information Security Associate

ISO/IEC 27001 Information Security Associate

Skillfront

Browser Security Workshop

Browser Security Workshop

Mario Heidrich

ISO/IEC 42001:2023 Lead Auditor

ISO/IEC 42001:2023 Lead Auditor

Mastermind · 2025

AWS Certified Cloud Practitioner

AWS Certified Cloud Practitioner

Amazon Web Services

Education

Academic background

Formal training in computer science and information technology.

2020

Tribhuvan University

Bachelor's in Computer Science & Information Technology (BSc. CSIT)

2025

Lincoln University College

Master's in Computer Science (MCS)

Research

CVE disclosures

Security vulnerabilities responsibly disclosed and published on NVD.

CVE-2020-10596 Medium

OpenCart

May 2020

Stored XSS vulnerability via crafted filename in image upload feature allowing authenticated attackers to execute malicious scripts.

View on NVD →
CVE-2020-18723 Medium

MDaemon Webmail

July 2020

Stored cross-site scripting (XSS) vulnerability allowing attackers to inject malicious scripts in webmail components.

View on NVD →
CVE-2020-18724 Medium

MDaemon Webmail

July 2020

Stored XSS vulnerability in contact name field of distribution list allowing execution of arbitrary scripts when viewed.

View on NVD →
CVE-2021-46065 Medium

Zoho ManageEngine ServiceDesk Plus

January 2022

Stored XSS vulnerability in Secondary Email field allowing attackers to inject arbitrary JavaScript code.

View on NVD →
CVE-2024-2301 High

HP Printers (LaserJet Pro)

May 2024

Cross-site scripting (XSS) vulnerability in printer web management interface that may allow execution of malicious scripts.

View on NVD →
Talks

Presentations & workshops

Conference talks, community meetups, and security awareness sessions.

Speaker

Security and Governance Challenges in AI

Google DevFest 2025 Lalitpur, Nepal December 2025

Why security and governance matter more than ever as organizations start using generative AI. How to securely adopt AI in systems, build secure AI models, mitigate risks from unsafe AI use, and more.

View details →
Speaker

Software Supply Chain Attacks and Preventions

Pentester Nepal Kathmandu, Nepal April 2023

Conduct security scan of third-party dependencies using SCA tools, SBOM analysis, and automated dependency checks. Evaluate software supply-chain risks—including compromised packages, malicious updates, and insecure build pipelines—to prevent large-scale security risks and maintain secure software releases.

View details →
Speaker

Present and future of infosec in Nepal

OWASP Kathmandu Eminence Ways, Kathmandu September 2022

Different domains of cybersecurity and how one can start cybersecurity. Introduction to security tools, frameworks, standards and rodmap

View details →
Speaker

Application Security: Tools and Techniques

TU-ERC Campus Dharan, Nepal November 2022

Advanced WebApp security testing techniques and emerging threats.Introduction to OWASP Top 10 risks

Speaker

Secure Development and Deployment

Security Professionals Meetup Cedar Gate Nepal, Lalitpur, Nepal January 2024

Secure coding practices, OWASP Top 10 prevention, DevOps mistakes

Let's connect

Interested in security consulting, speaking, or community collaboration? I'd love to hear from you.