Cybersecurity
10 application security experts
These ten professionals have led application security programs inside banks and other companies, with titles such as head of application security and application security director. A reader can learn how companies build application security into the way their software is developed and tested.
Professionals to explore
01—10Christine Rodriguez
LinkedInExperience: Director of Application Security · Barclays
Director of Application Security at Barclays since 2026, a role the profile describes as responsible for the AppSec Program. Former Application Security, Director at Citi (2013–2026), alongside a role as Cyber Security Operations, SVP at Citi from 2013 to 2022.
Gajanan Shanbhag
LinkedInExperience: Service Head, Application Security · Standard Chartered
Service Head, Application Security at Standard Chartered since 2021 and former Head of Application Security (interim) there in 2021. Other roles include Vice President - Application Security at Standard Chartered (2019–2021) and Delivery Manager Engineering Head - Identity & Access Management at ANZ (2015–2019).
Ismeet Dhillon
LinkedInExperience: Managing Director, Global Head Application Security · Goldman Sachs
Former Managing Director, Global Head Application Security at Goldman Sachs (2022–2025), with other Goldman Sachs roles including Vice President, Global Head Application Security (2019–2022), Vice President, Application Security Assurance and Secure SDLC (2017–2019) and Managing Director, Co-head Technology Risk Advisory since 2025.
Khalil Othman
LinkedInExperience: Global Head of Application Security · Stellantis
Former Global Head of Application Security at Stellantis (2020–2024) and Executive Director - Digital Products of AppSec at Wells Fargo since 2024. Other roles at FCA Fiat Chrysler Automobiles include Cloud Security Engineer & Global G-Suite Security (2018–2020) and Business Continuity and Disaster Recovery Lead (2017–2018).
Nirav Mistry
LinkedInExperience: Vice President - Application Security · Barclays
Vice President - Application Security at Barclays since 2022 and former AVP - Application Security there (2017–2022). The profile describes building and scaling security programs that integrate with modern software development lifecycles, using intelligent automation and data-driven insights to secure software development.
Pardhiv Reddy
LinkedInExperience: Director - Head of Application Security · S&P Global
Director - Head of Application Security at S&P Global since 2024, with other S&P Global roles including Associate Director - Application Security (2022–2024), Lead Application Security Architect (2020–2022) and Lead Application Security Engineer (2018–2020). Former Senior Security Engineer at Oracle (2017–2018).
Patrick Crabtree
LinkedInExperience: Head of Application Security Program and Governance, Director · Citi
Head of Application Security Program and Governance, Director at Citi since 2026 and former Manager, Application Security (SVP) there (2023–2026). The profile describes leading enterprise-wide security testing policies, governance and program management for application security automated scanning and penetration testing. Other roles include Lead Application Security Engineer at Royal Caribbean Group (2021–2023).
Ritu Saxena
LinkedInExperience: Director Application security & Vulnerability Management · Citizens
Director Application security & Vulnerability Management at Citizens since 2026 and former Application Security Manager there (2023–2026). The profile describes owning the strategy, governance and execution of enterprise-wide programs in this role, which reports to the CISO. Other Citizens roles include Principal Vulnerability Engineer (2018–2023).
Sabyasachi Dhal
LinkedInExperience: Executive Director, Application Security · Wells Fargo
Executive Director, Application Security at Wells Fargo since 2024 and former Vice President, Cybersecurity and Threat Management there (2022–2024). Other roles include Senior Staff, Product Owner & Architect at GE (2019–2020) and Staff, Cyber Security Researcher at GE (2018–2019).
Shyam Singh
LinkedInExperience: Executive Director - Application Security Automation & Engineering · Wells Fargo
Former Executive Director - Application Security Automation & Engineering at Wells Fargo (2024–2026) and Vice President - Head of Product Security, Security Architecture & Engineering at Zelis since 2026. The profile describes leading the product and enterprise application security team at Zelis, including security scanning solutions and tooling across SAST, SCA, DAST, secrets management and API security.
Choose the right perspective
Match the person's setting to yours, since running application security across thousands of developers at a large bank differs from building a first program at a smaller company. Also decide whether your main need is governance and policy or hands-on tooling and automation, since leaders often lean toward one.
Questions to take into the conversation
- 01Which application security controls do you put in place first when a company has almost none?
- 02How do you get development teams to fix findings from code scanning and testing without slowing releases?
- 03How do you measure whether an application security program is reducing real risk?
Reaching application security experts
How can I contact one of these application security experts?
Pick one of the 10 people on this page and choose "Book a paid call", or describe your project to find others. You offer a fee for a 15-minute call or a written answer, Instant Expert finds the person's work email and sends the invitation, and they decide whether to accept. The list covers 8 companies, including Barclays, Standard Chartered and Goldman Sachs, based on profile data retrieved on October 4, 2026. Being listed here doesn't mean someone has agreed to take calls.
How much does it cost to reach application security experts?
You choose the offer, starting at $5 per person. It includes Instant Expert's 20% fee, so an offer that pays the person $100 costs you $125. You're charged only when the person books the call or sends the answer.
What if they don't reply?
You pay nothing. Instant Expert sends follow-up reminders, and if the person hasn't booked or answered within 7 days, the request expires and any hold on your card is released. You can invite several of the 10 people on this list at once and cap your total spend, so you pay only for the ones who accept.
About this directory
This is a professional research starting point based on business profile data retrieved on . Titles and companies reflect that source snapshot and may describe past or present roles. Check the linked profiles for current details. Inclusion does not imply Instant Expert membership or availability.
Request a correction or removal