Hello, I'm
Aruneesh Salhotra
Technologist, Founder & Investor. I build companies, back early-stage teams, and contribute to open source security research — currently focused on AI security with OWASP AIBOM and OWASP AI Exchange.

About
I'm a technologist, founder, and investor working at the intersection of software, security, and AI. I've spent my career building products and companies, and I'm currently founding Zenjin AI alongside backing early-stage teams and contributing to open source security research.
I care about building healthy technical communities — helping practitioners share what they learn, and making sure the tools we build for AI and security are open, well-governed, and genuinely useful.
Community
I organize and support communities of security and AI practitioners — through OWASP chapters, meetups, and mentorship — because the best ideas in this field are still being worked out in the open, together.
Experience & Ventures
- 2025 — Present
Founder · Zenjin AI
Building at the intersection of AI and cybersecurity.
- 2023 — Present
Limited Partner · Emergent Ventures & Preface Ventures
Backing early-stage cybersecurity and enterprise infrastructure founders as an LP in venture funds.
- 2015 — Present
CEO & Principal · SNM Consulting Inc.
Fractional CISO and security advisory practice — application security, AI security and assessments, DevSecOps, and cloud security.
- 2015 — 2025
Global Head of Application Security · Nomura
A decade at the investment bank, rising from DevSecOps program management and the Office of the CTO to leading application security globally, then the US practice for third-party cyber risk.
- 2024 — 2025
Co-Founder · Suraksha Catalyst
Co-founded an early-stage security venture.
- 2011 — 2012
Co-Founder · Stealth Startup
Co-founded an early-stage startup through to a successful exit.
- 2007 — 2015
TPM, DevOps Lead, Developer & Trade Reporting Architect · Liquidnet (now TP ICAP)
Eight years in New York across engineering and program leadership — moving from developer to DevOps Lead running release management, then Technical Program Manager, and ultimately Trade Reporting Architect for the firm.
- 2005 — 2007
Enterprise Architect · Miletus Trading
- 2004 — 2005
DevOps Lead & Release Management · FatWire (now Oracle)
- 2002 — 2003
Development Lead · Lucent
- 2002
Development Lead · Sony
- 2001
Lead Developer · Ciena
- 1999 — 2001
Developer · Nortel Networks
- 1999
Global Consultant · DCM Data Systems (now DCM Infotech)
Boards & Councils
- Forbes Technology CouncilMember
- GlobalCISO Leadership FoundationCo-Chair, Governing Board
- AI & Cloud Governance CouncilCouncil Member
- RiskProfilerInvestor & Advisory Board
- DazzAdvisory Board Member
- Virsec SystemsAdvisory Board Member
- Pocket SecurityStrategic Advisor
- AI Security AcademyStrategic Advisor
- Institute of MERITAdvisory Board Member
- StrategioAdvisor
Open Source
I help build the open standards behind application and AI security — through OWASP and the Cloud Security Alliance.
Talks
Talks presented
Prestigious conferences
Past
- KeynoteFrom Black Box to Glass Box. Leading AI before it leads youHuman Driven AI Summit · Sep 2026
- PanelistTechnology Panel 4: When AI Starts Taking Action — Securing the Agentic EnterpriseGlobal Security Tour · Seattle Data/AI/Security — Dallas · Aug 2026
- TalkCode with Confidence: The Legal, Security, and Governance Framework for Vibe CodingAI DevSummit New York · Jun 2026
- WorkshopHow to Conduct AI Impact AssessmentIAPP AI Governance Global Europe 2026 · Jun 2026
- TalkContextual Excitement and the Human PsycheThreatcop · Feb 2026
- TalkOWASP AIBOM: Pioneering AI Transparency Through Community-Driven StandardsOWASP Global AppSec USA 2025 · Nov 2025
- TalkScaling OWASP's Impact: Strategy, Standards, and Sustainable GrowthOWASP Global AppSec USA 2025 · Nov 2025
- WorkshopConducting AI Impact AssessmentsIAPP Privacy. Security. Risk. 2025 · Oct 2025
- PanelistPanel: Leadership in Cybersecurity — Driving Organizational ChangeCorinium CISO / DevSecOps / Cloud Security NY · Sep 2025
- TalkAI Code Generation: Benefits, Risks and Mitigation ControlsOWASP Foundation · Mar 2025
- TalkBreaking Down Silos: Enhancing Security in AppSec ProgramsDeveloperWeek 2025 · OWASP Security Summit · Feb 2025
Writing
- WritingThe Velocity of Risk: Why Your Quarterly Board Deck Can't Keep Up with AISNM Consulting · Feb 2026
- Book97 Things Every Application Security Professional Should KnowO'Reilly Media · 2024
- WritingGuarding the Gates: Detecting and Preventing Prompt Injection Attacks in Generative AI with Open-Source SolutionsSNM Consulting · Oct 2024
- WritingModel Cards: The Key to Transparent and Ethical AI DevelopmentSNM Consulting · Oct 2024
- WritingOWASP LLM Top 10 – Let's Dig Into ItSNM Consulting · Mar 2024
- WritingRed Team and GenAISNM Consulting · Mar 2024
- Writing10-K and 8-K – Reporting RequirementsSNM Consulting · Mar 2024
- WritingNavigating the AI Frontier: Use Cases, Implementation, Security, Privacy, and Ethical DilemmasSNM Consulting · Mar 2024
- WritingNavigating the Exciting World of Code Generation with an Eye on Mitigating RisksSNM Consulting · Feb 2024
- WritingModern Approach to Software Composition Analysis – Call Graph and Runtime SCASNM Consulting · Jan 2024
- WritingModern Approach to Vulnerability Management – EPSSSNM Consulting · Jan 2024
- WritingEmbracing the Importance of AI: The Necessity of Regulations in the AI LandscapeSNM Consulting · Jan 2024
- WritingSecuring the Cyber Frontier: Vulnerability Management Approaches and Prioritization StrategiesSNM Consulting · Jan 2024
- WritingGuardians of Cyber Realms: The Power of Security Awareness in OrganizationsSNM Consulting · Nov 2023
- WritingFortify and Thrive: Elevating Your Defenses with an Application Security UprisingSNM Consulting · Oct 2023
- WritingExternal Attack Surface ManagementThe Purple Book Club · Oct 2023
- WritingSecuring the Vision: Guiding Non-Profit Organizations through the Digital EraSNM Consulting · Sep 2023
- WritingSecuring Your Mobile Applications – Why It Matters and How to Do It EffectivelySNM Consulting · Sep 2023
- WritingCI/CD Top TenSNM Consulting · May 2023
- WritingEvolving Domain of External Attack Surface ManagementSNM Consulting · May 2023
- WritingThe Importance of Signing Container Images: Ensuring Security and TrustSNM Consulting · May 2023
- WritingConcerns Around Intentional Bias in GenAI by Data PoisoningSNM Consulting · May 2023
- WritingScaling Safely: The Crucial Role of Application Security Maturity ModelsSNM Consulting · May 2023
- WritingWhy Maturity Models Are Needed in the First PlaceThe Purple Book Club · May 2023
- WritingBreaking Organizational SilosSNM Consulting · May 2023
- WritingScoring a Touchdown in AppSec: Risk-Based Strategies from the NFL PlaybookSNM Consulting · May 2023
- WritingBreaking Organizational SilosThe Purple Book Club · Mar 2023
- WritingWhat Parallels Can We Draw From the NFL to Take a Risk-Based Approach for AppSec?The Purple Book Club · Feb 2023
Media
Podcasts
- From Transparency to Trust: Shaping AI Security with OWASP AIBOM & AI ExchangeCyberRisk TV · Nov 2025
- Volunteer Work in Cybersecurity NonprofitsDejan Kosutic · Oct 2025
- Helen Fu Thomas AQ24 Interview: Aruneesh Salhotra, Technology Generalist and Angel InvestorHelen Fu Thomas · Mar 2024
- The Future of Attack Surface ManagementThe Tech Trek · Jan 2024
- Views from a Fractional CISO Delivering Complete Security: A Conversation with Aruneesh SalhotraLacework · Nov 2023
Contact
Best way to reach me is email. Always happy to talk about products, investing, or open source AI security work.
Also open to speaking engagements — keynotes, workshops, and panels. Connect with me if you're organizing one.











