Nayan Goel

Nayan Goel

Principal Application Security Engineer


Bio

A cybersecurity engineer and toolsmith passionate about offensive security, AI safety, and secure development. With a strong foundation in application security and automation, I have built cutting-edge tools that bridge the gap between traditional pentesting and modern technologies like GraphQL and large language models (LLMs). I am the creator of GraphQL Security Tester, a Burp Suite extension that uses GPT to generate malicious queries from GraphQL schemas, and PromptInjector, a powerful framework for identifying prompt injection vulnerabilities in LLM-based systems. His work emphasizes automation, reproducibility, and security testing at scale. I have also contributed as a peer reviewer for AI and cybersecurity journals, judged hackathons, and authored research papers on emerging attack surfaces. He actively participates in the security community and aims to make AI-centric systems more robust through practical, open-source tools.