A

Ashwath Kumar

CTO

Bengaluru, Karnataka, India16 yrs 10 mos experience
Most Likely To SwitchAI ML Practitioner

Key Highlights

  • Built a security automation team of 18 members.
  • Developed multiple PoCs using cutting-edge technologies.
  • Expert in cloud security and infrastructure protection.
Stackforce AI infers this person is a Cloud Security Architect with extensive experience in software security and team leadership.

Contact

Skills

Core Skills

Cloud SecurityInfrastructure SecurityTeam ManagementSecurity AutomationCloud ArchitectureMicroservicesTrainingAi ApplicationSecurity TestingApplication SecurityRed TeamingPenetration TestingThreat Modeling

Other Skills

AIAlgorithmsAppsecCC++Code reviewingComputer ArchitectureDebuggingDigital Signal ProcessorsEmbedded SoftwareEmbedded SystemsGoogle CloudHackingKubernetesLinux

About

Experienced Principal Consultant with a demonstrated history of working in the computer software industry. Skilled in Architecture Reviews, Cloud Security, Red teaming. Strong consulting professional with a Master of Science (M.S.) focused in Computer Engineering from Texas A&M University. Experience building a team of 13 FTE and 5 interns.

Experience

Razorpay

3 roles

Head of Security

Promoted

Apr 2024Present · 1 yr 11 mos

Principal Security Engineer

Promoted

Nov 2022Jun 2024 · 1 yr 7 mos

Staff Security Engineer

Jul 2021Dec 2022 · 1 yr 5 mos

  • Infrastructure security, Cloud security, Appsec
Infrastructure securityCloud securityAppsec

Synopsys inc

2 roles

Principal Consultant

Promoted

Dec 2018Present · 7 yrs 3 mos

  • Hired and built a security automation team of 13 FTE and 5 interns
  • Architected and helped develop a PoC for an internal product using Microservices, Kubernetes on Google Cloud
  • Created a light weight cloud security offering and trained multiple assessors on the offering
  • Created a PoC using AI to reduce false positives with security testing tools (Burp, Appscan)
  • Worked with Large Life Insurance, Airlines, Automobile, Payment Gateways, Banks

Associate Principal Consultant

Nov 2016Dec 2018 · 2 yrs 1 mo

  • Security consulting for architecture reviews, threat modeling, red teaming
  • Worked with Life Insurance companies, Large Private Banks, Product Companies and Pharma companies
  • Improve timeliness, quality and productivity for Managed Services
  • Identify areas for automation and work with the team to implement and operationalize the solution
  • Use automation to improve quality of findings and reduce repetitive manual effort
  • Setup a metrics program using Tableau to measure effectiveness of automation (Level of Effort & Quality)
  • Assisted with hiring (college and lateral) and helped scale the team from 35 to 130

Cigital, inc

Associate Principal Consultant

Mar 2016Nov 2016 · 8 mos · Bangalore

  • Cigital was acquired by Synopsys.
  • Security consulting for architecture reviews, threat modeling, red teaming
  • Worked with Life Insurance companies, Large Private Banks, Product Companies and Pharma companies
  • Improve timeliness, quality and productivity for Managed Services
  • Identify areas for automation and work with the team to implement and operationalize the solution
  • Use automation to improve quality of findings and reduce repetitive manual effort
  • Setup a metrics program using Tableau to measure effectiveness of automation (Level of Effort & Quality)
  • Assisted with hiring (college and lateral) and helped scale the team from 35 to 130

Microsoft

3 roles

Security Engineer II

Promoted

Feb 2014Mar 2016 · 2 yrs 1 mo

  • Team: Windows Devices Group Services - Windows Services, Xbox Live, Microsoft devices, Commerce Platform
  • Application security - Websites, web services, rest apis, Source code audit
  • Red teaming - Network audit, Infrastructure audit, reviewing applications
  • Tool development - security tools required for redteam efforts, automation of manual tasks during redteam and appsec. Creating custom tools to evade detection during Penetration tests and Red-team engagements
  • Collaboration with incident response - Coordinate with incident response teams to improve detection metrics.Assess third party security tools for effectiveness and risk introduced

Security Engineer

Jul 2012Feb 2014 · 1 yr 7 mos

  • Working on improving the security of Commerce Platform (central e-commerce platform for Microsoft products).
  • The core responsibilities include Penetration testing, threat modeling and code reviewing.
  • Penetration Testing - Parlaying research into actual exploits and doing in-depth hacking on Commerce Platform (CP). Identifying vulnerabilities through simulated external and internal attacks which validate Microsoft's ability to prevent, detect and respond.
  • Emerging Threat Research - Being on the forefront of emerging threats which affect online services. This includes research of externally found exploits as well as proactive research on technology CP utilizes and depends on. Performing case studies of recent incidents affecting cloud/payment providers.
  • Tool & Automation Development - Developing security toolset which increases the CP penetration testing team's ability to find network and web application vulnerabilities during security code reviews and live site attack & penetrate simulations.
  • Threat Modeling - Performing threat models/architecture reviews from a security perspective on the new features being released.
Application securityRed teamingTool development

SDET

Aug 2010Jun 2012 · 1 yr 10 mos

  • Working in the Online services group on the online commerce platform which handles the billing and commerce of various online products like Windows Azure, Office, Business Productivity Online Std suite etc.
Penetration testingThreat modelingCode reviewing

Ittiam systems

Engineer

May 2007Aug 2008 · 1 yr 3 mos

  • Worked on high speed embedded systems and mutimedia streaming.

Education

Texas A&M University

Master of Science (M.S.) — Computer Engineering

Jan 2008Jan 2010

National Institute of Technology Karnataka

B.Tech — Electrical and Electronics Engineering

Jan 2003Jan 2007

Stackforce found 100+ more professionals with Cloud Security & Infrastructure Security

Explore similar profiles based on matching skills and experience