Anupam Mehta

Product Security Engineer

Product security at scale.

I help product and infrastructure teams turn complex security risk into clear decisions, secure designs, and durable engineering guardrails.

  • Product Security Engineer at Stripe
  • Former Principal Product Security Engineer at Salesforce
  • 12+ years across product, cloud, application, and software supply-chain security
  • Master's in Security Informatics, Johns Hopkins University

About

Bridging security depth and engineering velocity.

My work spans financial technology, enterprise SaaS, and security consulting. I partner with product, platform, and infrastructure teams to embed security from concept to production—combining hands-on technical analysis with programs that operate at organizational scale.

Experience

Selected professional work

A career focused on making complex technology safer without making engineering slower.

October 2024 — Present

Stripe

Product Security Engineer

Product and infrastructure security for core financial systems.

  • Lead end-to-end product and infrastructure security reviews, partnering with engineering teams from design through production.
  • Assess integrity across source, build, third-party dependencies, and deployment pipelines.
  • Develop automation and standardized threat-modeling approaches that scale reviews without slowing delivery.

December 2019 — October 2024

Salesforce

Principal Product Security Engineer

Cloud, infrastructure, product, and software supply-chain security.

  • Led security architecture and threat modeling for foundational services supporting large-scale public-cloud migrations.
  • Designed secure software supply-chain practices across source control, CI/CD, and artifact storage.
  • Built secure-by-default services and third-party package controls used across a large engineering ecosystem.

February 2014 — December 2019

Cigital / Synopsys

Senior Security Consultant

Security consulting across cloud, applications, infrastructure, and DevSecOps.

  • Performed architecture risk analysis, threat modeling, AWS configuration reviews, and application security assessments.
  • Integrated SAST, DAST, SCA, network scanning, and defect-management systems into CI/CD workflows.
  • Developed cloud and DevSecOps training environments using Terraform, Docker, and AWS.

Areas of focus

Security built into the system.

Deep technical work translated into repeatable practices and clear outcomes.

01

Product Security

Secure design reviews, architecture analysis, and actionable engineering guidance.

02

Threat Modeling

Repeatable methods and automation for finding material risks earlier.

03

Software Supply Chain

Controls spanning source, dependencies, builds, artifacts, and deployment.

04

Cloud Infrastructure

Security architecture for cloud-native and multi-tenant systems.

05

DevSecOps

Practical controls that strengthen delivery pipelines without creating drag.

06

Security Automation

Scalable frameworks that turn expert judgment into durable guardrails.

PythonTerraformAWSDockerKubernetesOPAJavaScript

Books

Making security knowledge useful.

Published books for engineers, security practitioners, and everyday technology users.

Speaking & teaching

Lessons from the field, shared with the next generation.

I speak with students and practitioners about cybersecurity careers, cloud-native security, threat modeling, and building safer systems.

  • Johns Hopkins UniversityCybersecurity careers and professional practice
  • Vellore Institute of TechnologyCybersecurity foundations and industry experience

Education

Johns Hopkins University

Master's in Security Informatics

2012 — 2013

Vellore Institute of Technology

Bachelor's in Information Technology

2008 — 2012