Saurabh Pathak

DevOps Engineer

San Francisco, California, United States7 yrs 9 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Architected automated threat containment systems.
  • Reduced incident response time by 95%.
  • Mentored engineering talent and led security initiatives.
Stackforce AI infers this person is a Cybersecurity expert with a focus on network security and automated solutions.

Contact

Skills

Core Skills

Network SecurityAutomated Threat Containment

Other Skills

PythonScriptingEvent ManagementFirewallsLinuxCisco Systems ProductsSecrets ManagementSecurity Policy DevelopmentIncident ResponseAccess ControlCisco Security ProductsCVirtual Private Network (VPN)Internet Protocol Suite (TCP/IP)Domain Name System (DNS)

About

Senior Security Engineer with 7 years of experience architecting and automating security for large-scale distributed systems. A strategic leader with a proven record of architecting automated threat containment systems, hardening security for hundreds of thousands of devices, and eliminating entire classes of risk. Passionate about driving company-wide security initiatives, mentoring engineering talent, and building resilient, secure-by-design systems.

Experience

7 yrs 9 mos
Total Experience
2 yrs 7 mos
Average Tenure
4 yrs
Current Experience

Meta

2 roles

Production Security Engineer

Promoted

Oct 2022Present · 3 yrs 8 mos

  • Architected a secrets obfuscation framework and wrote the secret management policy, protecting 1Million+ internal secrets and
  • limiting visibility to privileged users, achieving zero inadvertent exposures in over 2+ years.
  • Enhanced security posture for 100k+ controllers by developing a vendor-agnostic rendering mechanism that compressed Access Control Lists by 99%, overcoming hardware limitations and achieving consistent policy enforcement across heterogeneous infrastructure.
  • Reduced incident response time by 95% (from 20+ minutes to <60 seconds) by designing an automated threat containment system
  • that immediately revokes network access for compromised identities, protecting critical infrastructure from lateral movement.
  • Decreased high-privilege grants by 70% and orchestrated an automated rotation framework of 120k+ fleetwide secrets, eliminating
  • static credential exposure risk and surface for forensic abuse analysis.
  • Scaled the secrets encryption service by 38x in request volume while maintaining 99.999% availability; optimized cross-region load
  • distribution (US/EMEA) to decommission 30+ T1 servers and save >$150k/year in infrastructure costs.
  • Worked with US government to enforce compliance for subsea cable infrastructure by automating secure onboarding of major cable
  • systems through dynamic prefix caching and regular auditing, while maintaining access to <30 engineers.
  • Led company-wide security initiatives and talent development, guiding multiple mentees through a long-term projects along with
  • leading training for 30+ Network Ambassadors to establish a first-tier support team, reducing escalations to senior engineers.
Network SecurityPythonScriptingEvent ManagementFirewallsLinux+2

Rotational Network Engineer

Jun 2022Oct 2022 · 4 mos

Carnegie mellon university

4 roles

Graduate Teaching Assistant

Jan 2022May 2022 · 4 mos · Pittsburgh, Pennsylvania, United States

  • 14736 - Distributed Systems

Graduate Teaching Assistant

Oct 2021Dec 2021 · 2 mos · Pittsburgh, Pennsylvania, United States

  • 14760 - Advanced Real World Networks

Graduate Research Assistant | PeeX Lab

Aug 2021Oct 2021 · 2 mos · Pittsburgh, Pennsylvania, United States

  • Security Behavior Observatory : AdBlocker Project
  • Understanding of the economic impact of privacy protection, and the impact of privacy technologies on consumer welfare and behavior.
  • Participants are divided into three between-subject conditions:
  • 1. Control: Participants are exposed to all, including behaviorally targeted, advertising as it naturally occurs online.
  • 2. Anti-tracking: Participants are opted out of targeted advertising using the online advertising industry’s self-regulatory approach for consumer control over targeted advertising (DAA 2009; FTC 2009).
  • 3. Ad-blocking: Online ads are blocked by our software, leveraging a prominent ad-blocking tool (AdBlockPlus, configured to block online ads at its maximum capacity) so that participants’ exposure to ads is minimal or none.

Graduate Research Assistant | CyLab

Feb 2021May 2021 · 3 mos · Pittsburgh, Pennsylvania, United States

  • ONR Malploy Project
  • Technology Stack: C++, Windows32 system APIs
  • Worked with DoD in to create a Dynamic Defense Orchestration System, which dynamically hooks various native Windows32 system API calls in order to change the system behavior to deceive an attacker and present different outputs based on the chosen defense strategy.
  • Defense Strategies Implemented:
  • 1. Passthrough the actual system output to the attacker.
  • 2. Present Invalid Access for legitimate system calls.
  • 3. Present Statically created altered data for various system calls.
  • 4. Connect to a "Honey Factory" over the network to dynamically create content on the fly according to the behavior analysis of the attacker and by predicting future actions based on different MITRE attack techniques.

Facebook

Backbone Network Engineer

May 2021Aug 2021 · 3 mos

  • Worked with engineers from the Optical, ENSOO, and OMS team on automating and improving fiber-cuts analysis through a CLI-based utility to quickly and efficiently find the precise geographic location of a fiber-cut across a span.
  • The analyzed data then can be forwarded to onsite vendors for a quicker fix, reducing downtime and saving revenue. In addition to providing the geographic location of the cut, the tool also can generate a KMZ file outlining the entire fiber layout on Google Earth, while highlighting the segment of the cut for a visual interpretation.

Cisco

4 roles

Network Consulting Engineer III

Aug 2019Dec 2020 · 1 yr 4 mos

  • 1. Handling customer’s escalation for backbone theatre
  • 2. Product development
  • 3. Delivering Cisco Services in the area of Security Solutions, which includes
  • a. Advisory: Best Practices and Proactive Software selection
  • b. Planning: Network LLD and HDD per Customer's requirements.
  • c. Designing and Implementing
  • d. Hardware and Software Release Management
  • e. Proactive Network and Capacity and Optimisation services
  • f. Catering to large Enterprise and Service Provider environments on Cisco Security Products - ASA, ISE, WSA-Web Security Appliance, FTD, FMC, VPN-IPSEC/DMVPN/GETVPN/SSL, AMP (Advanced Malware Protection) & ESA (Email Security Appliance).

Technical Consulting Engineer III

Jan 2019Aug 2019 · 7 mos

  • 1. Escalation engineer of the Cisco TAC backbone team.
  • 2. Mentoring engineers for technical Excellency and domain knowledge.
  • 3. Cisco program member for elite customers called TAC Advisor wherein
  • a. I make customer' s network more effective and secure by advising product and alternate solutions.
  • b. I am the POC for the sales team for any network clarifications regarding fresh deployments in Security domain.
  • 4. Lead the automation charge with building modules with a python framework to develop tools that automate log analysis, analyse and predict customer incidents and automate troubleshooting.
Network SecurityCisco Security Products

Technical Consulting Engineer II

Promoted

Jul 2017Jan 2019 · 1 yr 6 mos

  • 1. Build Python/Java based scripts to automate daily tasks for engineers and customers.
  • 2. Maintain Customer Satisfaction Survey (C-SAT) of the team.
  • 3. Provide technical support to sales/pre-sales team in fresh deployments or network enhancements.
  • 4. Work for EMEA & APAC customers and collaborate with other Cisco teams to solve high complex problems and file bugs to enhance products.
  • 5. Drive and solve highly escalated cases for network security under VPN, Firewall domain.
  • 6. Upgrade, configure and troubleshoot all Cisco Routers, Firewall, Catalyst Switches including ASA 55xx; FTD; ISR- GI, 62, 63; CSR -1k; ASR-1K,9K; CAT- 6500,4500.
  • 7. Build and lead teams for bug scrubbing on future product [NGFW : FTD].
PythonNetwork Security

Hardware Network Engineer

Jan 2017Jul 2017 · 6 mos

  • Built Cisco Proprietary tool GUI based tool called PlayWithPKI
  • 1. Capabilities:
  • a. PKI Server to help TAC engineers across the globe, generate certificates with user defined lifetime, Common name, or Extended attributes like EKU, KU, SAN, etc.
  • b. One click solution to read any X509 certificate, independent of the all available encoding formats (PEM or DER).
  • c. Ability to make an exact replica of a certificate, sign it with a dummy key and dummy CA certificate.
  • d. Hierarchical based representations of the certificates that are generated for any PKCS12 chain for a given certificate.
  • e. Easy GUI based edit form for any certificate, thus making editing or modifying any given field in a certificate very easy for the engineers.
  • f. File conversion and exportation for key pair associated with the certificate made easy.
  • 2. Convert a certificate hierarchy into a PKCS12 chain with user downloadable key pair. Application programming is done in Python with Big Data Broker as the background architecture.
  • 3. The GUI is a web-based model build using HTML and JavaScript, thus providing a platform independent solution to all the SSL related problems with user guided and easy process flow.
  • 4. Database management is done using Big Data Broker, where a separate unlimited storage is given to every user for a limited time. Also, User data secrecy is maintained and stagnant files are automatically deleted over a defined period of time.
  • 5. OpenSSL, Shell and Python scripting used for the backend.
PythonNetwork Security

Hewlett packard enterprise

Trainee

Nov 2016Dec 2016 · 1 mo · Greater Patna Area

  • Presented a complete method for designing a multitasking robot by making a 4 in 1 robot using RF module. The features added into this robot are:
  • i.Line following robot
  • ii.Never falling robot
  • iii.Human detection robot
  • iv.PC controlled robot
  • This prototype model is able to defend as well as attack and hence helps to reduce the human causality in areas such as war regions and country’s borders. The smaller robot unit makes it much more work effective since it can go to the places where further movement of bigger robot is not possible.

Education

Carnegie Mellon University

Master of Science - MS — Computer and Information Systems Security/Information Assurance

Jan 2020Jan 2022

Vellore Institute of Technology

Bachelor in technology(B. Tech.) — Electronics and Communication Engineering

Jan 2013Jan 2017

The Avadh School

Higher secondary school

Jan 2011Jan 2013

Nirmala Convent Senior Secondary School

High School

Jan 1999Jan 2011

Stackforce found 100+ more professionals with Network Security & Automated Threat Containment

Explore similar profiles based on matching skills and experience