RASP analysis: Android and iOS internals
Reversing runtime protections on both platforms, identifying what they detect and miss, and building and improving detections.
Principal Security Architect · Doverunner
Application, API and mobile security for 8+ years, now across product and internal security at Doverunner: RASP analysis and detections, multi-DRM content protection, and building security into how teams ship.
Interactive: query this portfolio like an API.
Host: sidharth.sec Accept: application/json User-Agent: recruiter/1.0
or Ctrl+Enter
{
"name": "Sidharth B Nair",
"role": "Principal Security Architect",
"company": "Doverunner Inc",
"location": "Kochi, Kerala, India",
"years": "8+",
"focus": ["product security", "internal security", "RASP detections", "multi-DRM content protection"]
}
01 Summary
I'm a Principal Security Architect at Doverunner, working across product and internal security. On the product side I analyze RASP and build detections for it, alongside multi-DRM content protection. Internally the scope runs from vulnerability management and incident response to identity and access, monitoring, cloud security, compliance, third-party risk and DLP. I joined in 2023 as a Senior Threat Analyst and moved into this role in June 2026.
Before Doverunner I led internal pentesting and third-party risk at Nykaa, and spent over four years doing application security consulting at SISA for clients across industries, most of them in banking and financial services. Across all of it the aim is the same: find what breaks early, and build the controls that keep it fixed.
I've spoken at droidcon India 2025 on secure mobile apps and at ISACA Silicon Valley on Log4Shell exploitation and mitigation, and I've done bug bounty research since 2016.
Pentesting and VAPT, SAST/DAST and source code review across web and thick-client applications.
API pentesting and review as part of web and mobile assessments for clients across industries, with a focus on banking and financial services.
Android and iOS assessments, including reversing runtime protections (RASP), finding what they detect and miss, and building new detections.
Multi-DRM content protection at Doverunner, including Widevine.
Threat modeling and architecture reviews early in design, secure SDLC integration, SAST/DAST testing frameworks, CI/CD security checks, and security training for development teams.
Vulnerability management, incident response, identity and access, security monitoring, cloud and infrastructure security, DLP, awareness programs reporting to executive leadership, and remediation across teams.
Security policy, compliance and audits including PCI-DSS, third-party and vendor risk assessments, and security architecture reviews.
Bug bounty since 2016, vulnerability research, and talks at droidcon India and ISACA Silicon Valley.
02 Experience
03 Talks & research
Reversing runtime protections on both platforms, identifying what they detect and miss, and building and improving detections.
Conference talk on building secure mobile apps, delivered at droidcon India 2025.
Webinar on the Apache Log4j vulnerability (CVE-2021-44228, CVSS 10.0): live exploitation, impact and mitigation.
Company-wide presentation at SISA on the Apache Log4j vulnerability and what it means for an organization.
Responsible disclosures through HackerOne, with acknowledgments from Fitbit and AlienVault Security.
Security assessment of multi-DRM implementations and content protection mechanisms, including Widevine.
04 Toolkit
05 Contact
Open to senior application and product security roles. Based in Kochi, Kerala, India.
Phone: available on request by email