Vineeth Sai Narajala

DevOps Manager

United States5 yrs 10 mos experience
AI EnabledAI ML Practitioner

Key Highlights

  • Pioneered GenAI security practices at AWS.
  • Developed automated vulnerability detection systems.
  • Integrated security tools into CI/CD pipelines.
Stackforce AI infers this person is a Cybersecurity expert specializing in AI/ML security and cloud security.

Contact

Skills

Core Skills

Artificial Intelligence (ai)Application SecuritySqlThreat ModelingPenetration TestingDevsecopsCyber Threat Hunting (cth)Disaster Recovery

Other Skills

Amazon BedrockAmazon Web Services (AWS)AutomationC (Programming Language)Code ReviewData AnalysisDesign ReviewHTMLInformation SecurityJavaScriptKali LinuxLeadershipLinuxPublic SpeakingPython (Programming Language)

About

Vineeth Sai Narajala is a highly skilled security professional currently working as a Generative AI Security Engineer at Amazon Web Services in New York. With a Bachelor's degree in Informatics Cybersecurity from the University of Washington, Vineeth has built a strong career in cybersecurity, specializing in AI/ML security, cloud security, and application security. His experience includes pioneering GenAI security practices at AWS, conducting comprehensive security assessments for major AWS services, and developing automated vulnerability detection systems. Prior to AWS, Vineeth worked at Nordstrom, where he integrated security tools into CI/CD pipelines and developed a Threat Intelligence Platform. His diverse skill set encompasses threat modeling, vulnerability assessment, IAM, malware analysis, and various programming languages, making him a versatile and valuable professional in the rapidly evolving field of cybersecurity.

Experience

Meta

Senior Security Engineer

Jul 2025Present · 8 mos · New York, New York, United States

Owasp® foundation

Co Leader and Founding Member of AIVSS: AI Vulnerability Scoring System and Agentic AI Top 10

Jun 2025Present · 9 mos

Owasp genai security project

Workstream Co Lead for Agentic Application Security at Agentic Security Initative (ASI)

Mar 2025Present · 1 yr

  • Working with the open source community to advance the security of Agentic AI and GenAI generally by Contributing and authoring White papers.

Amazon web services (aws)

3 roles

Senior Generative AI Security Engineer

Promoted

Jun 2024Jul 2025 · 1 yr 1 mo

  • Pioneered the development of comprehensive GenAI security best practices and standards for Amazon's flagship products (Amazon Q and Bedrock), including guardrails, prompt-injection protections, compute isolation, and session management, and implemented mechanisms to enforce them across the organization.
  • Accelerated GenAI feature integration, reducing launch timelines from 3 weeks to less than 1 week by creating efficient, security-compliant Golden Paths for various integrations.
  • Enhanced security for key features like Amazon QuickSight's Natural Language to SQL editor, reinforcing data protection and query integrity.
  • Led security assessments for AI model integrations across the AWS ecosystem, ensuring strict adherence to security standards, and spearheaded developer training initiatives, improving team-wide awareness and expertise in secure AI integration.
Threat ModelingArtificial Intelligence (AI)Application SecurityAmazon Bedrock

Application Security Engineer 2

Dec 2022Jun 2025 · 2 yrs 6 mos

  • Conducted threat modeling, design reviews, and security testing for over 150 new feature launches, continuously raising the security standards for AWS Analytics and Big Data Services within the Hadoop/Spark ecosystem, including Athena, EMR, and Lake Formation.
  • Led security reviews for major AWS Spark launches, including Native Fine-Grained Access Control, HBase Write-Ahead Logs, Native LDAP Integration within Spark, Remote Shuffle Protocol, Multi-Dialect (Trino, Spark, SQL) Views, and Predicate Pushdown security.
  • Core Security Contributor to Membrane: A Secure was to do FGAC in Native Spark
  • Helped Securely launch many SQL products which are being used in GovCloud and ADC regions for mission-critical workloads.
SQLApplication Security

Application Security Engineer

Nov 2021Dec 2022 · 1 yr 1 mo

  • 1. Threat model core AWS databases cloud architecture like RDS (Relational Database Service), EMR (Elastic MapReduce) and Managed blockchain and help the service and product remediate security findings.
  • 2. Conduct threat modeling, design reviews, testing of new infrastructure and raise the security bar for product and service team.
  • 3. Design and build tools to help eliminate attack vectors, harden the platform, and enhance monitoring of services and decrease developer frustrations by moving left in the software development lifecycle.
  • 4. Find and analyze vulnerabilities, rate their severity, and drive resolution to them. Work with testing team to help validate the fixes.
  • 5. Support SecOps with incident response in collaboration with products teams to remediate issues within SLA.
AutomationCode ReviewDesign ReviewThreat ModelingPenetration Testing

Nordstrom

3 roles

Security Engineer II, Developer Security and tooling

Aug 2021Nov 2021 · 3 mos · Seattle, Washington, United States

  • Integrate Security tools like static code analysis, dynamic code analysis, secret detection into the CI/CD pipeline.
  • Automate some aspects of threat modeling, design, security, and architecture reviews and build a system to ensure applications are compliant after the review stage.
sastDevSecOps

Security Engineer, BCDR

Nov 2020Feb 2021 · 3 mos · Seattle, Washington, United States

  • 1) Improve Business Continuity and Disaster Recovery solutions at Nordstrom by creating an infrastructure-as-code solution for data protection and data loss.
  • 2) Enhance protection against permanent data loss, corruption, seizure, or ransom by Isolating and reducing permissions surface area on both short-term and long-term storage.
  • 3) Configure and deploy object lock policies to enable WORM protection with legal and compliance requirements in mind.
  • 4) Implement least-privilege permissions controls to manage backups and configuration.
Amazon Web Services (AWS)data protectionDisaster Recovery

Security Engineer, Threat Intelligence

May 2020Aug 2021 · 1 yr 3 mos · Seattle, Washington, United States

  • 1. Architected and built the Threat Intelligence platform from scratch using open-source tools like MISP.
  • 2. Supported and performed a deep-dive analysis of TTP’s of both internal and external threats as well as performed threat modeling for applications to defend Nordstrom’s infrastructure, to improve the ability to defend vulnerabilities, and make Security-in-depth a default concept during SDLC.
  • 3. Reverse engineered malware, triaged threat intelligence, researched attacker infrastructure to curate previously unknown Indicators of Compromise, and created actionable results and remediation plans for internal stakeholders to proactively improve the security posture and maturity.
  • 4. Conduct Design Reviews, Security assessments and threat modeling for new applications as well as ad hoc automated and manual penetration testing.
Cyber Threat Hunting (CTH)SplunkRed Teaming

University of nevada-las vegas

Adjunct Professor

Feb 2021Oct 2021 · 8 mos · Las Vegas, Nevada, United States

  • Lead Instructor teaching Cybersecurity courses through @HackerUSA at UNLV.

University of washington information school

Teaching Assistant

Sep 2019Aug 2020 · 11 mos · Seattle, Washington, United States

  • 1. Taught over 100 students in various classes including Introduction to programming, Design for personal heal as well as Data and privacy ethics.
  • 2. Conducted lab section meetings, prepared and graded assignments, and maintained grading records.
  • 3. Held regular office hours, tutor students, manage and respond to course-related e-mail.

Nordstrom

Penetration Tester

Jun 2019Aug 2019 · 2 mos · Greater Seattle Area

  • 1. Identified vulnerabilities by simulating external and internal attacks, which exercise and validate Nordstrom’s ability to prevent, detect, respond, and recover to cyber risks.
  • 2. Developed a security toolset that increased the Red Team’s ability to find and exploit network, Active directory operating system, application, and datacenter vulnerabilities.
  • 3. Researched and analyzed known hacker methodology, system exploits, and vulnerabilities to support Red team assessment activities and created written reports, detailing assessment findings and recommendations.

University of washington - school of medicine

Data Analyst

Dec 2017Jun 2019 · 1 yr 6 mos · Greater Seattle Area

  • 1. Developed custom Plugins and Macros in ImageJ (JAVA) to remove bottlenecks, improved analysis time from hours to seconds, and automated multiple processes using Python and Macros.
  • 2. Used Statistical methods to analyze large MRI Datasets to produce create descriptive visualizations in order to derive insights about the multiple diseases including Cancer and Muscular Dystrophy

Education

University of Washington

Bachelor’s Degree - Informatics

University of Washington Information School

Bachelor of Science - BS — Informatics - Information Assurance and Cybersecurity

University of Washington, Henry M. Jackson School of International Studies

Fellowship — Cybersecurity Policy Trask force

Stackforce found 100+ more professionals with Artificial Intelligence (ai) & Application Security

Explore similar profiles based on matching skills and experience