Product & Application Security
Secure architecture, STRIDE threat modeling, secure SDLC, application reviews, API security, and abuse-case analysis.
Lead Product Infrastructure Security Engineer
I partner with product, application, infrastructure, and leadership teams to turn security architecture, threat modeling, vulnerability data, and DevSecOps automation into practical controls that reduce risk.
I specialize in full-scope product and application security reviews, STRIDE-based threat modeling, architecture risk assessments, vulnerability management, secure SDLC programs, and CI/CD security gates. My work spans cloud environments, identity platforms, WAF controls, cryptography, privileged access, and GenAI/ML workloads.
A mix of architecture review, engineering partnership, automated security controls, and executive-ready risk visibility.
Secure architecture, STRIDE threat modeling, secure SDLC, application reviews, API security, and abuse-case analysis.
AWS, Azure, Prisma Cloud CSPM, infrastructure vulnerability management, compliance monitoring, and remediation governance.
Checkmarx, Black Duck, GitHub Advanced Security, Trivy, JFrog Xray, Jenkins gates, and Python reporting pipelines.
OAuth, OIDC, SAML, JWT, PKCE, passkeys, least privilege, CyberArk, JIT access, and access governance.
AES, HMAC, HSMs, HashiCorp Vault, mTLS, certificate lifecycle management, and enterprise crypto standards.
OWASP Top 10 LLM, MITRE ATLAS, Databricks controls, Unity Catalog RBAC, secret management, and egress control.
Mastercard | Arlington, VA
Lead product, application, cloud, AI/ML, and identity security reviews across critical technology portfolios. Drive secure-by-design adoption, DevSecOps gates, cloud posture management, zero trust controls, cryptographic standards, mTLS lifecycle management, and M&A security due diligence.
MobileComm Professionals Inc | Richardson, TX
Performed application, API, mobile, and infrastructure assessments, including manual and automated DAST, secure code review, mobile reverse engineering, STRIDE threat modeling, and developer security training.
Tekreant Inc | Irving, TX
Delivered vulnerability assessments, application testing, POA&Ms, risk mitigation plans, SIEM validation, firewall administration support, endpoint security, and SOX and PCI control assessments.
Lince Soft Solutions Pvt. Ltd | Hyderabad, India
Conducted vulnerability assessments, network security audits, intrusion detection analysis, firewall reviews, penetration testing, packet analysis, and monthly risk reporting.
Translated STRIDE threat models into security requirements and design changes before production deployment.
Built Python reporting pipelines and Domo dashboards to track remediation progress across engineering portfolios.
Implemented Prisma Cloud CSPM to monitor multi-cloud environments, enforce compliance, and detect misconfigurations.
Secured Databricks GenAI and ML workloads with RBAC, service principals, encrypted secrets, PrivateLink, and egress controls.
California University of Management Standards, Arlington, VA
Electronics and Communication Engineering, Jawaharlal Nehru Technological University Kakinada
AWS Certified Security Professional | CISSP In Progress
Based in Arlington, VA. Available for security leadership, product security, cloud security, and DevSecOps conversations.