About

I’m Shoeb Patel, an Application Security Engineer at Amazon in London. I work on Web, API, Cloud and AI security of the Corporate Technology org. Before that I spent three years in AWS owning security for the networking services (VPC, Load Balancing, Transit Gateway, PrivateLink, VPC Lattice, Cloud WAN).

Day to day I do threat modelling, code review, security testing, and automate the boring parts. The bugs I enjoy hunting most are design and authorisation flaws: broken object-level and function-level access checks, and confused deputies. Lately that means encoding my review approach into agent skills and PR-time checks, and poking at the security of AI agents themselves.

I have worked in application security for seven years: senior security engineer at Flipkart in Bangalore, one of the first security hires at BrowserStack in Mumbai, and before that a Google Summer of Code student (and later mentor) building challenges for OWASP Juice Shop. I studied computer science at NIT Goa and moved to the UK in 2022.

Outside of work I do vulnerability research. I have reported issues to 30+ organisations including Google, AWS, the U.S. Department of Defense, GitHub Security Lab, Oracle, Intel and Mastercard, hold two CVEs (CVE-2021-32817, CVE-2021-22255), and have contributed to OWASP Juice Shop, OWASP ZAP and other open-source security tools. I founded and captained the CTF team UnderDawgs from 2019 to 2021; several of the older posts here are CTF write-ups from that time.

This blog collects my writing since 2018: security research, CTF write-ups, tooling and automation.

Elsewhere