Nishant SharmaProduct Management

Currently at Zscaler · Zero Trust Browser

Nishant Sharma.

I build secure products — and the teams that ship them. Twelve years of hands-on security engineering and research sits behind every product decision I make.

Product Management // Browser Security // Team Building // Applied Research

Nishant Sharma
Now
Director, Product Management
Zscaler — Zero Trust Browser: the extension, the enterprise browser and cloud browser isolation.
12yrsExperience
58Research in the press
20Trainings delivered
18Conference talks
9Open-source tools
4×Team scale-up
01

About

Hello! I'm Nishant Sharma. I build products — and the teams that build them. My track record is starting things from zero: standing up cost-effective, high-performing remote technical organisations, hiring and training them, and pointing them at hard problems.

Over a decade in cybersecurity and product development has convinced me that the best security products come from people who have done the work themselves. I've led world-class research teams, shipped open-source tooling the industry actually uses, and taught thousands of students and professionals across 125+ countries from the stages of DEF CON, Black Hat, HITB and RootCon.

Today I serve as Director, Product Management at Zscaler, working on Zero Trust Browser — the product family that lets people work securely in the browser, whether through the Zscaler browser extension, the purpose-built enterprise browser, or cloud browser isolation. Knowing first-hand how browsers, extensions and AI agents fail is exactly what lets me define what a product has to do about it, and hold a technical bar with the engineers building it.

Previously I was Head of Cybersecurity Research at SquareX (Browser Detection-Response, acquired by Zscaler), VP of Labs, R&D at INE, Head of R&D at Pentester Academy (acquired by INE), and MTS at Mojo Networks (acquired by Arista Networks) — building products, platforms and research programmes from the ground up at each.

Product
Zero Trust Browser — extension, enterprise browser, cloud browser isolation
Domain
Browser security · AI-browser threats · Cloud · WiFi & RF
Builds
Products, research teams, lab platforms and open-source tooling — from zero
Stage
DEF CON · Black Hat · HITB · RootCon · BSides · OWASP
Education
M.Tech Information Security, IIIT Delhi
02

Professional Skills

6 domains

Product Management

Expert

Turning deep technical understanding of the browser and cloud attack surface into requirements, roadmap and shipped capability — and holding the technical bar with engineering.

DiscoveryRoadmapTechnical specs0→1Security products

AI & Agentic Systems

Expert

Building agentic and sub-agentic systems that break problems too big for a single model into work that can actually be finished — and putting AI into the team's daily workflow so we ship more, and ship it faster.

Agent orchestrationSub-agentsTool useEvalsTeam velocity

Cybersecurity Research

Master

First-hand understanding of how browsers, AI agents, WiFi and VoIP actually fail — the input that keeps a security product solving real problems instead of imagined ones.

Browser internalsAI agents802.11VoIPDisclosure

Browser, WiFi & Cloud Security

Master

Extension analysis, MCP and agent abuse, enterprise-browser and isolation architectures, plus AWS / Azure / GCP attack & defence at lab scale.

ExtensionsMCPOAuthIsolationAWSAzureGCP

Team Building & Management

Expert

Built remote engineering and research orgs from zero — grew an India team 4× in four months, and hired, trained and retained 12+ engineers through two acquisitions.

Remote-firstHiringTrainingMentoringPost-M&A

Startup Ops & Optimisation

Expert

Cut lab cloud spend 25%, release effort 80% and turnaround 70% — while simultaneously scaling content output and headcount.

Cost controlProcess designScale-up
03

Work Experience

7 roles · 2013 → now
  1. Director, Product ManagementNOW

    at Zscaler

    Feb 2026 — Present

    • Product management for Zero Trust Browser — Zscaler's browser security family spanning the browser extension, the enterprise browser and cloud browser isolation.
    • Defining what secure browsing has to look like for enterprises: translating first-hand knowledge of browser, extension and AI-agent attack surface into requirements, roadmap and shipped capability.
    • Working across research, engineering and design to ship protection that customers can actually deploy.
  2. Head of Cybersecurity Research

    at SquareX (acquired by Zscaler)

    Jun 2025 — Feb 2026

    • Built and led the cybersecurity research function, bridging offensive research and defensive product innovation to redefine enterprise browsing security.
    • Built flagship initiatives from zero with the team:
    • Stood up the India team end to end — operations, hiring and capability building.
  3. Vice President — Lab, Research & Development

    at INE.com

    Jan 2025 — May 2025

    • Led multi-cloud capacity expansion and major efficiency improvements.
    • Served as cybersecurity SME providing leadership across engineering and R&D.
    • Built and maintained scalable infrastructure and drove key innovation projects.
    • Automated platform change and lab release processes, reducing effort by 80%.
    • Streamlined workflows to cut turnaround times by 70%.
    • Built DevSecOps pipelines with GitHub Actions and dashboards for quality and security checks.
    • Developed regional performance testing and logged-in flow automation to surface critical issues.
    • Drove security scanning and application-security posture improvements.
    • Hired, developed and retained a fully remote engineering team of 12+ across India.
  4. Director, Lab Platform

    at INE.com

    Oct 2021 — Dec 2024

    • Worked closely with the Senior Leadership Team to set objectives and deliver the development/content roadmap.
    • Managed hiring and daily operations for a 12+ person technical team working remotely from India.
    • Adopted DevSecOps practices across the platform.
    • Guided the team to create cutting-edge labs on Supply Chain Attacks, Windows Active Directory and Azure Active Directory.
    • Reduced operational cloud expenses of the lab platform by 25%.
    • Led multiple initiatives to build in-house monitoring, marketing and analytics portals.
    • Conducted 8+ presentations/trainings/workshops at Black Hat, DEF CON, RootCon and OWASP Seasides to promote brand visibility.
    • Led the team in developing and releasing 4 open-source tools to the community.
    • Led the team to create 200+ labs for Azure, GCP and AWS cloud training.
    • Increased engineering team size (4 → 16 members) within four months of the Pentester Academy acquisition by INE.
    • Coded Azure Playground Labs and Azure-based GNS3 networking labs.
    • Migrated 200+ legacy eLS labs to the PTA lab platform, improving uptime and reducing failures/errors by 80%.
    • Conducted knowledge transfer and sharing sessions with instructors and cross-developer teams.
  5. Head, Research & Development

    at Pentester Academy (acquired by INE)

    Nov 2015 — Oct 2021

    • Played a pivotal role in Pentester Academy's growth across product development, sales and marketing — working directly with Founder/CEO Vivek Ramachandran, and eventually in its acquisition by INE.
    • Led multiple initiatives including Hacker Arsenal, the PA YouTube channel and AttackDefense.
    • Led a 6-member content team to build 2000+ challenges across 125+ infosec sub-topics for AttackDefense.
    • Delivered 6+ paid trainings, 15+ tools/talks at top conferences (Black Hat, DEF CON, HITB, RootCon, OWASP NZ) and 10+ live online boot camps.
    • Developed and released 6 open-source tools.
    • Developed course content and labs for courses.
  6. Member of Technical Staff

    at Mojo Networks (acquired by Arista Networks)

    Jun 2014 — Oct 2015

    • Developed upgrades and patches for the WIPS and Mojo Networks WiFi access-point platform.
    • Developed access-point features:
      • IPSec / EoGRE tunnels
      • IPv6 communication and QoS
      • 802.11r Fast BSS Transition roaming
      • Client reporting and NTP time sync
  7. Cyber Forensics Intern

    at KPMG, India

    May 2013 — Jul 2013

    • Recovered digital evidence (files, images, emails) as a member of the Data Evidence Recovery team.
    • Seized evidence, maintained chain of custody, recovered deleted data and submitted meaningful information to lawyers.
04

Trainings

20 sessions
DEF CON Plug and Prey: Scanning and Scoring Browser Extensions Recon Village, DEF CON 33 ▶ Video
DEF CON Serverless but Not Defenseless: A Security Deep Dive into Cloud Run Cloud Village, DEF CON 33
DEF CON No Radios, No Problem — Hacking WiFi in a Virtual World Radio Frequency Village, DEF CON 33
Black Hat Attacking and Defending AWS Cloud Environment Black Hat USA 2022
DEF CON Introduction to Azure Security DEF CON 30 Workshops
Black Hat Advanced WiFi Exploitation for Red and Blue Teams Black Hat USA 2021
Other Advanced WiFi Exploitation BSides Canberra 2021
Black Hat Advanced Real-World Penetration Testing Black Hat Asia 2020
DEF CON Introduction to WiFi Security Radio Frequency Village, DEF CON 28 ▶ Video
Other 1-day in-person workshop for ISEA and IIT Guwahati ISEA / IIT Guwahati, 2020
Other 2-day virtual workshop for 350+ Govt. of India officials Government of India, 2020
Black Hat Advanced WiFi Exploitation for Red and Blue Teams Black Hat USA 2019
RootCon Advanced Real-World Penetration Testing RootCon Philippines 2019
HITB Advanced Real-World Penetration Testing HITB GSEC Singapore 2019
HITB Advanced Real-World Penetration Testing HITB Amsterdam 2019
Other Advanced Real-World Penetration Testing OWASP NZ Day 2019
Other Information Security Awareness Private clients
Online WiFi Pentesting Online Bootcamp (5 batches) INE
Online Container Security Beginners Online Bootcamp (5 batches) INE
Online DevSecOps Online Bootcamp (2 batches) INE
05

Tools and Presentations

Research Presentations

18
Black Hat AWSGoat: A Damn Vulnerable AWS Infrastructure BH USA 2022 Arsenal · DEF CON 30 Demolabs
Black Hat AzureGoat: A Damn Vulnerable Azure Infrastructure BH USA 2022 Arsenal · DEF CON 30 Demolabs
RootCon ReconPal: Leveraging NLP for Infosec RootCon Philippines 2020
Other Wi-Bear: Intelligent Autonomous Wi-Fi Honeypot Detection (contribution) BSides Canberra 2019 ▶ Video
Black Hat AD VoIP Toolkit: VoIP Analysis Wireshark Plugins Black Hat Asia 2019 Arsenal
HITB WiCy: Monitoring 802.11ac Networks at Scale HITB Amsterdam Haxpo 2019 ▶ Video
DEF CON VoIPShark: Open Source VoIP Analysis Platform DEF CON China main stage & Demolabs 2019 ▶ Video
DEF CON Developing Access Point Rootkits Wireless Village, DEF CON 27 ▶ Video
DEF CON Writing Wireshark Plugins for Security Analysis Radio Frequency Village, DEF CON 28
Other Writing Wireshark Plugins for Security Analysis Infosec In The City 2020, Singapore ▶ Video
DEF CON Writing Wireshark Plugins for Security Analysis Radio Frequency Village, DEF CON 27
RootCon Hunting Threats with Wireshark Plugins RootCon Philippines 2019 ▶ Video
Black Hat BLEMystique: Affordable Custom BLE Target Black Hat USA 2018 Arsenal & DEF CON 26 Demolabs
Black Hat PA-Toolkit: Wireshark Plugins for Pentesters Black Hat USA 2018 Arsenal & DEF CON 26 Demolabs
DEF CON Deceptacon: Deception in WiFi Radio Frequency Village, DEF CON 25
DEF CON Wimonitor: OpenWRT Package for Remote Sniffing DEF CON 25 Demolabs
DEF CON IIDS: IoT Intrusion Detection System IoT Village, DEF CON 25
Black Hat WiDy: WiFi 0wnage under $5 Black Hat Asia 2017 Arsenal & DEF CON 25 Demolabs

Podcasts

2
Podcast Cloud Security Podcast — AWSGoat & cloud penetration testing Jan 2023 ▶ Video
Podcast SecTools Podcast, Episode 22 Sep 2020

Discovered Vulnerabilities / Issues

4
9.8 CRIT CVE-2020-24264 NVD
8.8 HIGH CVE-2020-24263 NVD
HALL OF FAME AV evasion vulnerability on Bitdefender's flagship complete PC protection "Bitdefender Total Security 2018" product. Bitdefender
HALL OF FAME Security and Privacy issues in Ola's in-cab WiFi offering (OLA Play). Problem was not in the implementation but with the design/architecture. Ola
06

Education

Master of Technology (Information Security)

from IIIT Delhi

2012 — 2014

  • Grade: 9 / 10
  • Member of Student Council.
  • Top-10 finalist of Infosys Hashers (National Coding Competition) 2012 — over 450+ teams from premier colleges participated.
  • Member of the Cryptology group.

Bachelor of Technology (Computer Science)

from Himachal Pradesh University

2008 — 2012

  • Grade: Hons (Ist Division)
  • Member of the organising committee of the technical festival.

Secondary and Senior School Education

from Jawahar Navodaya Vidyalaya (CBSE)

2001 — 2008

  • Scored 87.8% in 10th and 82.3% in 12th (PCM).
07

Professional Chronicles

9 moments
08

Research Talk Playlist

11 recordings