Professor — Application Security & Secure SDLC

Dr. Neha Kapoor

PhD, CSSLP, OSWE

Specialises in application security and the secure software development lifecycle, from threat modelling to secure code review.

Application Security Secure Coding OWASP

Dr. Neha Kapoor is a Professor of Application Security and Secure Software Development at GICCT, where she teaches the discipline of building software that can withstand attack. As organisations increasingly live or die by their applications and APIs, she helps developers and security professionals find and fix the flaws that matter most — ideally before they ever reach production.

Background and career

Dr. Kapoor started as a software developer, writing the kind of code she now teaches others to secure. That background is central to how she approaches the field: she understands why vulnerabilities get introduced, not as careless mistakes but as the natural consequence of developers working under deadline pressure with incomplete information. This empathy for the developer’s situation makes her unusually effective at teaching secure development in a way that engineers actually accept.

She moved into application security as the discipline matured, working as a security engineer and consultant who assessed and hardened applications for organisations ranging from startups to large enterprises. Her doctoral research focused on automated vulnerability detection and the limits of static analysis — understanding not just what tools can find, but the dangerous gap of what they miss. She holds the CSSLP and OSWE certifications, credentials that span both the defensive and offensive sides of application security.

Areas of expertise

Dr. Kapoor’s expertise centres on the OWASP Top 10 and the broader landscape of web application and API vulnerabilities, secure coding practices across modern stacks, threat modelling, and security code review. She has particular depth in the secure software development lifecycle — the practices that weave security through every stage of development rather than treating it as a final inspection.

She is equally fluent in offensive and defensive techniques, able to attack an application to find its weaknesses and then guide the team in fixing them properly. This dual perspective is central to her teaching: she believes you cannot effectively defend an application without understanding how it will be attacked, and you cannot responsibly attack one without understanding how to make it better.

Teaching philosophy

Dr. Kapoor teaches application security from both sides of the keyboard. Her students attack deliberately vulnerable applications, experiencing firsthand how an injection flaw or a broken access control is actually exploited, and then learn to build defences against the very weaknesses they have just exploited. She finds this dual experience makes the lessons stick in a way that abstract instruction never can.

She emphasises that secure coding is not about memorising a list of forbidden practices but about developing a security mindset — the habit of asking, at every step, how something could be misused. Her goal is graduates who carry that mindset into their daily work, catching problems instinctively rather than relying solely on tools and reviews to find them later.

A practitioner’s perspective

Dr. Kapoor’s teaching reflects the reality that most application vulnerabilities are not exotic but depressingly familiar — the same categories of flaw appearing year after year because the underlying causes are organisational and human, not merely technical. She helps students understand why this is, and what genuinely works to break the cycle, rather than offering quick fixes that fail to address the root.

She keeps pace with a constantly shifting landscape, from the security challenges of modern JavaScript frameworks and single-page applications to the proliferation of APIs and the new attack surfaces they create. She frames these developments in terms of enduring principles, helping students build knowledge that adapts as technologies come and go.

At GICCT

At the institute, Dr. Kapoor leads the Web Application Security program and contributes to the secure development content across the curriculum. She is a strong advocate for shifting security earlier in the development process, regularly reminding students that a vulnerability caught in design costs a fraction of one discovered in production. For developers wanting to write more secure code, and for security professionals specialising in applications, her courses offer a rigorous, genuinely practical foundation.

Προγράμματα που διδάσκει

Web Application Security (OWASP)

DevSecOps Engineering