Saransh Rana — DevOps Manager
Staff Security Engineer and published security researcher specializing in cloud-native attack vectors and AI-powered defense systems. I architect security for CRED's fintech infrastructure serving millions, while conducting cutting-edge research on cloud platform vulnerabilities. My work sits at the intersection of offensive security research and defensive security engineering at scale. Published Research & Discoveries: - AWS Security: Discovered CloudTrail detection bypass via AppStream, GuardDuty container runtime evasion, and novel ECS task metadata credential exfiltration techniques - GCP Security: Uncovered privilege escalation via Cloud Workstation shared sessions - demonstrated complete account takeover - Built first Model Context Protocol (MCP) servers enabling autonomous AI-driven cloud security remediation - Research presented at BlackHat Arsenal USA, DefCon CloudVillage, NoNameCon Engineering Leadership at CRED: - Secure 50+ AWS accounts processing millions of daily transactions with zero critical findings across 55+ audits (PCI DSS 4.0, RBI, ISO 27001) - Lead threat modeling for 15+ critical platforms (UPI, lending, payments etc) - implemented 110+ preventive controls - Drive security strategy while maintaining hands-on technical depth - Built open-source tools: aws-security-mcp, IMDShift (imdsv2 migration), DIAL (sub-5s misconfiguration detection) Technical Expertise: - Cloud Security: AWS, GCP, Kubernetes (CKA), container runtime security, infrastructure as code - Offensive Security: Red team collaboration, vulnerability research. - Security Engineering: Threat modelling, vulnerability management, security automation, DevSecOps, Python, NodeJS, Terraform - AI/ML Security: Created first MCP Server implementation for cloud security, enabling LLMs (Claude, GPT) to autonomously query and fix AWS misconfigurations, translate security requirements to code From bypassing cloud detection mechanisms to building AI that fixes security issues autonomously - I transform security research into scalable defensive solutions. AWS Community Builder (Security) | Synack Red Team Alumni | Bug bounty: Apple, AWS, GCP, AT&T, PaloAltoNetworks Open to Staff/Principal roles where I can push the boundaries of cloud security through research and engineering.
Stackforce AI infers this person is a Cloud Security Expert specializing in Fintech and AI-driven security solutions.
Location: Bengaluru, Karnataka, India
Experience: 7 yrs 2 mos
Skills
- Cloud Security
- Security Engineering
- Ai/ml Security
Career Highlights
- Pioneered AI-driven security solutions for cloud environments.
- Achieved top security scores across multiple audits.
- Published critical research in leading security conferences.
Work Experience
CRED
Staff Security Engineer (2 yrs 2 mos)
Senior Security Engineer (1 yr 8 mos)
Infrastructure Security Engineer (1 yr 3 mos)
Synack Red Team
Red Team Member (4 yrs 6 mos)
OYO
Security Engineer (1 yr 4 mos)
Signzy
Security Engineer (9 mos)
Kratikal Tech Private Limited
Security Analyst Intern (2 mos)
Education
B.Tech at Manipal University Jaipur
at Delhi Public School, NTPC Vidyut Nagar