Saransh Rana

DevOps Manager

Bengaluru, Karnataka, India7 yrs 2 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Pioneered AI-driven security solutions for cloud environments.
  • Achieved top security scores across multiple audits.
  • Published critical research in leading security conferences.
Stackforce AI infers this person is a Cloud Security Expert specializing in Fintech and AI-driven security solutions.

Contact

Skills

Core Skills

Cloud SecuritySecurity EngineeringAi/ml Security

Other Skills

AI-driven securityAPI SecurityAWS SecurityAkamai FirewallAmazon CloudFrontAmazon EC2Amazon ECSAmazon EKSAmazon VPCAmazon Web Services (AWS)Android SecurityAnsibleApplication SecurityApplication Security ArchitectureAppstream

About

Staff Security Engineer and published security researcher specializing in cloud-native attack vectors and AI-powered defense systems. I architect security for CRED's fintech infrastructure serving millions, while conducting cutting-edge research on cloud platform vulnerabilities. My work sits at the intersection of offensive security research and defensive security engineering at scale. Published Research & Discoveries: - AWS Security: Discovered CloudTrail detection bypass via AppStream, GuardDuty container runtime evasion, and novel ECS task metadata credential exfiltration techniques - GCP Security: Uncovered privilege escalation via Cloud Workstation shared sessions - demonstrated complete account takeover - Built first Model Context Protocol (MCP) servers enabling autonomous AI-driven cloud security remediation - Research presented at BlackHat Arsenal USA, DefCon CloudVillage, NoNameCon Engineering Leadership at CRED: - Secure 50+ AWS accounts processing millions of daily transactions with zero critical findings across 55+ audits (PCI DSS 4.0, RBI, ISO 27001) - Lead threat modeling for 15+ critical platforms (UPI, lending, payments etc) - implemented 110+ preventive controls - Drive security strategy while maintaining hands-on technical depth - Built open-source tools: aws-security-mcp, IMDShift (imdsv2 migration), DIAL (sub-5s misconfiguration detection) Technical Expertise: - Cloud Security: AWS, GCP, Kubernetes (CKA), container runtime security, infrastructure as code - Offensive Security: Red team collaboration, vulnerability research. - Security Engineering: Threat modelling, vulnerability management, security automation, DevSecOps, Python, NodeJS, Terraform - AI/ML Security: Created first MCP Server implementation for cloud security, enabling LLMs (Claude, GPT) to autonomously query and fix AWS misconfigurations, translate security requirements to code From bypassing cloud detection mechanisms to building AI that fixes security issues autonomously - I transform security research into scalable defensive solutions. AWS Community Builder (Security) | Synack Red Team Alumni | Bug bounty: Apple, AWS, GCP, AT&T, PaloAltoNetworks Open to Staff/Principal roles where I can push the boundaries of cloud security through research and engineering.

Experience

7 yrs 2 mos
Total Experience
2 yrs 4 mos
Average Tenure
5 yrs 1 mo
Current Experience

Cred

3 roles

Staff Security Engineer

Promoted

Apr 2024Present · 2 yrs 2 mos · On-site

  • Container Security Architecture: Leading container security initiatives across ECS/EKS - implemented image scanning pipelines, runtime protection with Upwind Enterprise, and discovered critical vulnerabilities including AWS GuardDuty container runtime detection bypass and ECS task metadata credential exfilteration
  • Security Automation & AI: Pioneered AI-driven security with Model Context Protocol servers - aws-security-mcp enables LLMs to autonomously detect AWS misconfigurations, aws-inspector-mcp automates vulnerability management. Reduced operational costs by $15,000/month through automation
  • Open Source Contributions: Published MCP servers on GitHub enabling natural language security queries. Developed automated attack surface management tool for proactive public exposure detection across AWS infrastructure
  • Security Evangelist: Speaker at DefCon CloudVillage demonstrating UEBA on AWS infrastructure using LLMs. Leading research on solving cloud security challenges with AI - translating natural language queries to optimized security context
Container Security ArchitectureSecurity AutomationAI-driven securityOpen Source ContributionsSecurity EvangelismCloud Security+1

Senior Security Engineer

Promoted

Jul 2022Mar 2024 · 1 yr 8 mos · On-site

  • Led 55+ infrastructure security initiatives across critical business verticals (Cred Money, Cred Cash, Cred Garage, Cred Travel etc) - completed 50+ security reviews identifying and remediating 120+ vulnerabilities
  • Drove security transformation for M&A: Improved security maturity from 72% to 93% in 4 months, implemented 140+ Day-0 cloud security controls, deployed CSPM(Cloud Security Posture Management) across 100+ AWS accounts, identified and remediated multiple critical risks
  • Achieved 97% AWS Security Improvement Plan (SIP) score - recognized as top score in APJC region. Won 1st place in AWS Security GameDay competing against 140+ participants from 60 teams
  • Published critical security research: Discovered AWS AppStream CloudTrail bypass, AWS CloudShell container breakout, GCP Cloud Workstations privilege escalation - research featured in AWS Security Digest and CloudSec newsletters
  • Architected enterprise security frameworks: AWS EKS Security Baseline, Cloud Security Policy, Common Control Framework, UAT Security Guidelines - adopted across multiple engineering teams
  • Open sourced DIAL (Did I Alert Lambda?) - centralized security monitoring detecting misconfigurations in < 3 seconds. Presented at BlackHat USA 2023, Ekoparty demonstrating real-time cloud security at scale
  • Led M&A security for 4+ acquisitions including Happay (expense management), Kuvera (wealth management), and CreditVidya (lending platform) - ensured compliance with RBI and PCI DSS mandates without blocking business velocity
  • built, processed and optimised! - established infrastructure security review process, reduced operational costs by $10,000/month through tool consolidation
Infrastructure SecuritySecurity TransformationSecurity FrameworksOpen Source ContributionsCloud SecuritySecurity Engineering

Infrastructure Security Engineer

Mar 2021Jun 2022 · 1 yr 3 mos · On-site

  • Built foundational security automation tools: DIAL (centralized misconfiguration detection <5s), TOM(Tenable over Ansible Master) - an automated security patching, Xenon (credential compromise detection), ARKVP (AWS resource mapping), AccessKeyDict (centralized access key management)
  • Achieved 96% AWS WAR(Well Architecture Review) Security score (improved from 85%) - implemented SCPs, conducted cloud security audits, audited IAM Policies and established security baselines
  • Led comprehensive red team exercise on aws cloud infrastructure - identified critical security gaps in authentication, access controls, and network segmentation that prompted organization-wide production security hardening initiative
  • Automated security operations: Created ECR(Elastic Container Registry) image scanner, egress traffic monitoring, infrasec auditor for public resources, and integrated Deep Security with Slack
  • Established threat modeling practice for critical datastores - created detailed plans and structured processes for Infrastructure Security Reviews
  • Contributed to security community: Spoke at NoNameCon and Ekoparty, participated in AWS Security GameDay APJC Region(came 2nd), wrote Q3 Security Blog
Security Automation ToolsCloud Security AuditsRed Team ExercisesCloud SecuritySecurity Engineering

Synack red team

Red Team Member

Jan 2020Jul 2024 · 4 yrs 6 mos

Oyo

Security Engineer

Oct 2019Feb 2021 · 1 yr 4 mos · Gurgaon, India

Signzy

Security Engineer

Jan 2019Oct 2019 · 9 mos · Bangalore

Kratikal tech private limited

Security Analyst Intern

May 2018Jul 2018 · 2 mos · Noida Area, India

Education

Manipal University Jaipur

B.Tech

Jan 2013Jan 2017

Delhi Public School, NTPC Vidyut Nagar

Stackforce found 100+ more professionals with Cloud Security & Security Engineering

Explore similar profiles based on matching skills and experience