With 16 years of experience in application security across web, mobile, and API ecosystems, I focus on finding real-world vulnerabilities and building practical defenses across the SDLC. I hold OSWE, OSCP, and CISSP certifications and have worked on large-scale security programs in global organizations.
I have presented and delivered training at security conferences and community events, including HOPE, BSides, OWASP Boston Chapter, and other industry venues, covering topics such as application security, mobile security, and post-quantum risks in modern applications.
My recent work has focused on AI and agentic system security, especially how autonomous agents, tool integrations, and emerging protocols like MCP introduce new attack surfaces that traditional AppSec approaches do not fully cover. This talk is based on hands-on experience evaluating MCP-connected AI systems and highlights the trust gaps that security teams need to address now.
@security_sesha
linkedin.com/in/sheshanandak/
sheshakandula.github.io (blog)