Product Management
ExpertTurning deep technical understanding of the browser and cloud attack surface into requirements, roadmap and shipped capability — and holding the technical bar with engineering.
Currently at Zscaler · Zero Trust Browser
I build secure products — and the teams that ship them. Twelve years of hands-on security engineering and research sits behind every product decision I make.
Product Management // Browser Security // Team Building // Applied Research
me@nishantsharmax.com · nishantsharmax.com · linkedin.com/in/nishantsharmax · github.com/nishantsharmax · medium.com/@nishantsharmax
Hello! I'm Nishant Sharma. I build products — and the teams that build them. My track record is starting things from zero: standing up cost-effective, high-performing remote technical organisations, hiring and training them, and pointing them at hard problems.
Over a decade in cybersecurity and product development has convinced me that the best security products come from people who have done the work themselves. I've led world-class research teams, shipped open-source tooling the industry actually uses, and taught thousands of students and professionals across 125+ countries from the stages of DEF CON, Black Hat, HITB and RootCon.
Today I serve as Director, Product Management at Zscaler, working on Zero Trust Browser — the product family that lets people work securely in the browser, whether through the Zscaler browser extension, the purpose-built enterprise browser, or cloud browser isolation. Knowing first-hand how browsers, extensions and AI agents fail is exactly what lets me define what a product has to do about it, and hold a technical bar with the engineers building it.
Previously I was Head of Cybersecurity Research at SquareX (Browser Detection-Response, acquired by Zscaler), VP of Labs, R&D at INE, Head of R&D at Pentester Academy (acquired by INE), and MTS at Mojo Networks (acquired by Arista Networks) — building products, platforms and research programmes from the ground up at each.
Turning deep technical understanding of the browser and cloud attack surface into requirements, roadmap and shipped capability — and holding the technical bar with engineering.
Building agentic and sub-agentic systems that break problems too big for a single model into work that can actually be finished — and putting AI into the team's daily workflow so we ship more, and ship it faster.
First-hand understanding of how browsers, AI agents, WiFi and VoIP actually fail — the input that keeps a security product solving real problems instead of imagined ones.
Extension analysis, MCP and agent abuse, enterprise-browser and isolation architectures, plus AWS / Azure / GCP attack & defence at lab scale.
Built remote engineering and research orgs from zero — grew an India team 4× in four months, and hired, trained and retained 12+ engineers through two acquisitions.
Cut lab cloud spend 25%, release effort 80% and turnaround 70% — while simultaneously scaling content output and headcount.
at Zscaler
Feb 2026 — Present
at SquareX (acquired by Zscaler)
Jun 2025 — Feb 2026
at INE.com
Jan 2025 — May 2025
at INE.com
Oct 2021 — Dec 2024
at Pentester Academy (acquired by INE)
Nov 2015 — Oct 2021
at Mojo Networks (acquired by Arista Networks)
Jun 2014 — Oct 2015
at KPMG, India
May 2013 — Jul 2013
from IIIT Delhi
2012 — 2014
2008 — 2012
from Jawahar Navodaya Vidyalaya (CBSE)
2001 — 2008








