CFP Directory LogoCFP Directory
EventsSpeakersTalksOrganizationsFeaturesPricingWhy Us
Sign in

Company

  • About Us
  • Contact

Contact Info

Address:

13, Lorong Toh Aka

Georgetown 10100

Penang, Malaysia

Email:

info@cfp.directory

Website:

13thirtyseven.my

Business Hours

Monday - Friday:9:00 AM - 6:00 PM
Saturday:9:00 AM - 1:00 PM
Sunday:Closed

GMT+8 (Malaysia Standard Time)

© 2025 CFP Directory. All rights reserved.
13 Thirty Seven Sdn. Bhd. (1401538-A)
Privacy PolicyTerms of Service
Back to Speakers
Sayli ambure

Sayli ambure

Washington DC, USA
English
Virtual Events

0

Talks Delivered

0

Events Spoken At

0

Countries Visited

1

Years Speaking

0

Total Talks Given

About

I got into cybersecurity the messy, curious way - hacking games as a teenager to get extra coins and superpowers, then later reverse-engineering ransomwares to understand how they worked. That same curiosity and passion led me to a career in offensive cyber security.


In the past 5+ years of work experience across India, UAE & USA, I’ve worked on:


• Mobile application penetration testing (Android & iOS)

• Web application and API penetration testing

• Secure code review across C/C++, Python, Java, Golang, JavaScript, Typescript and C# .NET

• Custom Signature Code Analysis (Semgrep, YARA & Coverity CodeXM custom checkers)

• Adverserial tradecraft and Cyber threat intelligence

• Network and infrastructure assessments with Segmentation penetration tests for cloud and on-prem setups

• Software Composition Analysis (Coverity, Black Duck, GitHub Advisories, PlexTrac)

• Innovative research & automated pentest tools development (AI, OSINT, Python, Bash script)


Currently, I work as a Security Researcher at OnDefend, where I help secure user data of a large-scale social media platform & contribute to U.S. national security.


🌟 Key Achievements:


• Awarded the first-ever “Magical Mention” as an intern at Equinix for uncovering and reporting multiple critical security misconfigurations. Recognized for investigative persistence, curiosity, and successfully improving internal security workflows through proactive analysis and alerting.

• Bug Bounty & Hall of Fame mentions: Tesco, IKEA, SecureLayer7 live hacking event, Accenture, Ericsson, Springer Nature, OSIsoft


🔍CVE Research:

• CVE-2020-11539 : Access control issue in Tata Sonata Smartwatch

• CVE-2020-11540 : Access control issue in Tata Sonata Smartwatch

• CVE-2020-25498 : Chained CSRF & Stored XSS vulnerabilities in Beetel router

• CVE-2020-35262 : Stored XSS vulnerability in Digisol router


👾 Outside of work, I’m always exploring new tools, ways to use AI as leverage in security, hacking techniques & trying to level up. I love building my own custom IoT devices as well as hacking them.


🧑‍🤝‍🧑As an active member of 'Women in Cybersecurity', 'Women in Security & Privacy' and 'The Diana Initiative' volunteer at Defcon, I’m also passionate about making cyber security more inclusive and human, especially for women and underrepresented voices.

Speaking Topics & Expertise

Areas of Expertise

Cyber Security
Application Security
IoT Security
Mobile Security
Web Security
Web Application Security
Insider Threat Detection
Threat Hunting
Threat Intelligence
AI Security
Ethical Hacking
Bug Bounty
Hardware Hacking
Lock Picking
Offensive Security
Penetration Testing
Red Team
Reverse Engineering
Android Permissions
Android Rooting
Android Security
iOS Jailbreaking
iOS App Store Security
iOS Security
OSINT

Connect

@@sayli_ambureLinkedIn Profile

Experience Level

intermediate