Ashish Kurmi

Co-Founder

Kirkland, Washington, United States16 yrs 6 mos experience
Highly Stable

Key Highlights

  • Led cloud security transformation at Uber.
  • Developed multi-cloud security monitoring platform.
  • Co-founded StepSecurity to enhance cybersecurity.
Stackforce AI infers this person is a Cloud Security Engineer with extensive experience in Information Security and Software Engineering.

Contact

Skills

Core Skills

Information SecurityCloud SecuritySoftware Engineering

Other Skills

AWSKubernetesSecurityGCPGSuiteThreat DetectionIncident ResponsePartnership ManagementSecurity EngineeringCloud Service LifecycleSoftware DevelopmentAzure FunctionsSecurity Design ReviewsPenetration TestingAzure Security

Experience

16 yrs 6 mos
Total Experience
4 yrs 5 mos
Average Tenure
4 yrs 3 mos
Current Experience

Stepsecurity

Founder & CTO

Feb 2022Present · 4 yrs 3 mos · Redmond, Washington, United States · Hybrid

Plaid

Lead Security Engineer

Jun 2021Feb 2023 · 1 yr 8 mos · Greater Seattle Area

  • All things AWS & Kubernetes security.
AWSKubernetesSecurityInformation Security

Uber

Lead Staff Security Engineer

Jul 2017Jun 2021 · 3 yrs 11 mos · Greater Seattle Area

  • Lead security engineer for cloud (AWS, GCP, and GSuite) security projects focused on directive, preventative, detective, and responsive controls.
  • Led the transformation of Uber Cloud Security from an operations-focused to an engineering-driven team. Envisioned and led projects to build multi-cloud security monitoring & response automation platform, identity & access management, threat detection, and provisioning.
  • Built and driving cross-industry partnership with Dow Jones for Hammer.
  • Helped the Vulnerability Management, Threat Detection, Incident Response, and Compliance teams to successfully adopt the cloud by authoring engineering solutions and consultation.
  • Performing security engineering reviews including threat models, architecture reviews, and providing security guidance for cloud initiatives.
AWSGCPGSuiteCloud SecurityThreat DetectionIncident Response+1

Microsoft

6 roles

Senior Software Development Engineer

Oct 2014Jun 2017 · 2 yrs 8 mos

  • In this role, I participated in all phases of the cloud service lifecycle which includes design, development, deployment, monitoring, and maintenance. I worked with third party vendors to integrate their services into the Microsoft cloud to ease customer pain points and provide seamless experiences. I owned ‘App Service Certificate’, ‘App Service Domain’ and components of ‘App Service’ Platform and Azure Server-less offering i.e. ‘Azure Functions’.
Cloud Service LifecycleSoftware DevelopmentAzure FunctionsSoftware Engineering

Security Software Development Engineer II

Promoted

Jul 2011Sep 2014 · 3 yrs 2 mos

  • As part of this role, I performed security design reviews, code reviews, threat modelling, penetration testing, security breach detection and reactive security engineering on various cloud services and products in Azure organization. It also included developing security features, proofs of concepts and security services for first party Azure services.
Security Design ReviewsPenetration TestingAzure SecurityInformation Security

Program Manager in Information security and risk management (ISRM)

Feb 2011Jul 2011 · 5 mos

  • Worked on a password security project under the Consumerization of IT (CoIT) initiative in collaboration with Microsoft Research. In this project, we analyzed the threat to corporate password security due to CoIT from both, theoretical and practical perspectives. In addition to managing it, I also developed all the tools required for this initiative.
Password SecurityRisk ManagementInformation Security

Research Software Development Engineer

Promoted

Jul 2010Jan 2011 · 6 mos

  • Worked in the Security and Privacy research group on their ServiceOS research project. My responsibility was to build the ServiceOS prototype for both, smartphone and desktop. This included implementing the ServiceOS policies in its browser kernel by modifying the Internet Explorer rendering engine and making ServiceOS runtime compatible with the core Windows kernel.
ServiceOSSecurity and PrivacySoftware Engineering

Security Analyst

Promoted

Feb 2010Jul 2010 · 5 mos

  • Performed security code review of multiple internal applications and deployment review of production servers. Also prepared a few internal security white papers and got them reviewed from security experts.
Security Code ReviewInternal SecurityInformation Security

Test Engineer

Aug 2009Feb 2010 · 6 mos

  • Prepared test plans and test cases for features in the Windows Activation stack and executed them during the system testing phase. Analysed pain points in our group’s performance testing methodologies, gave recommendations and built assistive tools. I evaluated VSTS 2010 and TFS 2010, presented my findings and gave recommendations to the team.
Test PlansPerformance TestingSoftware Engineering

Google summer of code 2009

Student Contract Developer

Apr 2009Jun 2009 · 2 mos

  • Worked as a student developer for Google during Google Summer of code 2009 to develop Freesite (websites hosted in Freenet) filters for Freenet which is a decentralized, censorship-resistant P2P network with a distributed dataset. I created white list based filters for HTML5, CSS2, SVG and BMP.
Web DevelopmentFreenet

Microsoft corporation

Intern

Jun 2008Aug 2008 · 2 mos · Greater Hyderabad Area

  • Developed automation software for routine on premise production server maintenance operations such as patch management, monitoring performance and uptime etc.
Automation SoftwareServer MaintenanceSoftware Engineering

Education

Mumbai University

Bachelor of Engineering — Computer Science

Jan 2005Jan 2009

Stackforce found 100+ more professionals with Information Security & Cloud Security

Explore similar profiles based on matching skills and experience