A

Akshay Bhaskaran

Security Engineer

Austin, Texas, United States8 yrs 11 mos experience
Highly Stable

Key Highlights

  • Expertise in cryptography and data protection methodologies.
  • Led significant projects in key management and security architecture.
  • Strong background in application security and threat modeling.
Stackforce AI infers this person is a Fintech Security Engineer with extensive experience in cryptography and application security.

Contact

Skills

Core Skills

Cryptography And Data Protection/data SecurityApplication SecurityInformation Security

Other Skills

AWSAutomationCComputer SecurityCryptographic AlgorithmsCryptographyCybersecurity EventsData ProtectionData SecurityEncryptionEthical HackingFinancial ServicesFirewallsGrafanaHSM

About

I started my career with a Bachelors in Information Technology from India. Couple networking-based courses along with a strong introduction and final year project on cryptography got my interest spiked in Cybersecurity. So, I came to Boston to get a Masters from Northeastern University majoring in Information Assurance and Cybersecurity. Here, I'd the opportunity to explore, and learn various pillars of security such as network security, system security, identity and access management, digital forensics, applied cryptography, penetration testing, risk management, and much more. A sneak peek into the industry to see how this field functions was given to me through couple of internships - one at a healthcare firm dealing with security architecture reviews, threat modeling, and penetration testing, and the other at a media company dealing with incidents, performing malware analysis and much more. Post graduation, I'd landed up in my first security engineer role with Visa Inc., Here, I was dealing with developing and maintaining cryptographic components/agents that performs encryption, tokenization etc. Also was responsible for performing data security architecture reviews to understand, and evaluate the sensitive data elements from its origin until destination to make sure it is secured in all of its three states. After spending around 4 years in this company, I switched to PayPal, a similar company in the FinTech space. Here, I'm now a part of the cryptography engineering team developing and exposing cryptographic REST APIs that'd be consumed by other applications to protect their sensitive data elements. Areas of expertise: 1. [Cryptography and data protection/data security]: encryption/tokenization methodologies and implementation 2. [HSM and PKI]: key life cycle management, certificate management, and overall hands-on knowledge on the PKI ecosystem 3. [Application Security]: security architecture reviews, threat modeling (STRIDE), and the ability to use tools to perform in-depth SAST/DAST kind of scans to identify insecure code 4. [Programming]: ability to understand, debug and develop security components/utilities/frameworks using the following languages - Java, Python, Shell script 5. [Web Technologies/Micro Services]: hands-on knowledge developing web-applications that consumes/exposes REST APIs to perform various different crypto operations using some widely used frameworks 6. [Databases]: ability to perform CRUD operations on various flavors of DB such as Oracle, MySQL, MSSQL, DB2, and Mongo using their respective connectors

Experience

Apple

Senior Security Engineer

Dec 2023Present · 2 yrs 3 mos · Austin, Texas, United States

Paypal

Security Engineer (Member of Technical Staff 1), Cryptography Engineering

Mar 2021Dec 2023 · 2 yrs 9 mos · Austin, Texas, United States · Hybrid

  • Primary technical lead to build the next generation bootstrapping mechanism for PayPal’s centralized Key Management System by migrating from the legacy way of managing keys
  • Offered consultation to the architecture, design, and feature rollout of TLSv1.2 for both client and server sessions at scale
  • Developed and exposed REST APIs for PayPal’s centralized key management system for performing a variety of cryptographic operations
  • Engineered a component that fetches tokens from the key management system which would be used by the applications to authenticate with the KMS
  • Supervised and validated different certificate renewal and deployment for various internal entities
  • Participated in the re-architecture of the topology of internal cryptographic systems to support high availability and disaster recovery
  • Work closely with customers of the security engineering team in supporting and debugging encryption and key management products
  • Support and monitor operational activities and work on immediate fixes to ensure the end-to-end availability of the business-critical systems
CryptographyREST APIsTLSv1.2Key Management SystemCryptography and data protection/data securityApplication Security

Visa

2 roles

Senior Cybersecurity Engineer, Data Protection and Security Architecture

Promoted

Jan 2020Mar 2021 · 1 yr 2 mos · Austin, Texas Metropolitan Area

  • Serving as the primary architect and engineering owner of tokenization service that provides SST and FPE based encryption mechanisms to various internal applications
  • Designed, architected, and engineered a data security engagement process in an internal portal that’s used to file security assessments. Automated various internal workflows including like X509 Certificates automation, HSM configuration etc., using spring-boot, MySQL, and REST APIs thereby reducing the on-boarding time from 4-days to just 4 minutes
  • Technology owner for PKCS#11-based encryption services that’s used by COTS applications to protect their sensitive data-at-rest using application-level encryptions
  • Perform in-depth security architecture reviews and threat modeling for applications’ that process PII/PAN data to identify data-security gaps, and propose appropriate protections (different flavors of encryption, tokenization etc.)
  • Primary engineer responsible for building an automation utility, in python, that addressed bulk symmetric key creation problem faced by various clients
  • Participated in various internal audits like ITDR, AAA certification, PCI DSS representing as a technology owner for some business-critical tier-0 applications
TokenizationData SecuritySecurity ArchitectureThreat ModelingCryptography and data protection/data securityApplication Security

Cybersecurity Engineer, Data Protection and Security Architecture

May 2017Mar 2021 · 3 yrs 10 mos · Austin, Texas Metropolitan Area

  • Work closely with product development teams and other technology architects to ensure all sensitive data is secure and 100% protected at various levels
  • Technical expertise in data-protection methodologies, protocols, and technologies including an understanding of cryptographic algorithms such as AES, 3DES, RSA, HMAC, SHA etc.
  • Built an abstraction layer that uses REST and KMIP to integrate with the HSMs for crypto operations. This is consumed by the application teams, and greatly reduced the dependency and tight coupling with vendor solutions.
  • Architected, and developed a live monitoring dashboard, using Grafana and sCollector, that monitors around 30+ operational metrics of internal HSM, PKI, and data protection appliances
  • Participated in the vulnerability management program on a weekly basis to remediate security gaps/findings to harden our internal systems
  • Researched and developed POVs for Salesforce’s Shield platform evaluating their BYOK solution offering and helped some internal teams integrate with the same for their key management use-case
Data ProtectionCryptographic AlgorithmsRESTMonitoringCryptography and data protection/data securityApplication Security

Gns healthcare

Capstone Research Intern

Sep 2016Dec 2016 · 3 mos · Cambridge, MA

  • Conducted security architecture review of critical applications hosted inside AWS to identify potential security weakness
  • Identified external and internal risks to applications with the help of STRIDE Threat Modelling and a secure code review
  • Researched, designed, and delivered a high-level risk assessment framework that prioritizes top risks to the company along with some recommendations on industry best practices to tackle the same
Security Architecture ReviewThreat ModelingRisk AssessmentApplication Security

Nbcuniversal media, llc

Information Security Analyst Intern

Jan 2016Apr 2016 · 3 mos · New York City Metropolitan Area

  • Part of NBC’s Response Operations team to research and investigate the processes related to cybersecurity events alongside with monitoring security tools.
  • Analyzed trends, and metrics from social media to detect and identify threats to the company for a list of events hosted/sponsored by NBC.
  • Researched various types of malwares and attacks like virus, spam, phishing, unauthorized access, brute force, along with fake NBC domains from domestic and international proxies to take appropriate remediating actions.
  • Performed vulnerability scan for servers and applications to spot high vulnerabilities and communicated the results along with action items to business security leaders
  • Monitored and tracked down employees, third party vendors, and contractors trying to access restricted/unauthorized sites using company’s network
Cybersecurity EventsVulnerability ScanningMalware AnalysisInformation Security

Education

Northeastern University

Master's degree — Computer and Information Systems Security/Information Assurance

Jan 2014Jan 2016

SASTRA University

Bachelor of Technology (B.Tech.) — Information Technology

Jan 2010Jan 2014

Stackforce found 100+ more professionals with Cryptography And Data Protection/data Security & Application Security

Explore similar profiles based on matching skills and experience