RAJ SRIVASTAVA

Software Engineer

Bengaluru, Karnataka, India4 yrs 9 mos experience
Highly Stable

Key Highlights

  • Expert in security-critical infrastructure development.
  • Led significant OpenSSL upgrade initiatives.
  • Specialized in passwordless authentication workflows.
Stackforce AI infers this person is a Security Engineer specializing in Infrastructure with a focus on authentication and compliance.

Contact

Skills

Core Skills

Network SecuritySecurity EngineeringInfrastructure Automation

Other Skills

TACACS+SSHOpenSSLCiscoSSLGDBmultithreadingprotocol tracingFIPSX.509PKICMockaPyATSProgramming LanguagesRoot Cause AnalysisSystems Analysis

About

Software Engineer with 4.9+ years of experience at Cisco building security-critical infrastructure for IOS-XR, Cisco's carrier-grade network operating system. Specialized in Linux systems programming, C/C++, OpenSSL/CiscoSSL, SSH/TLS, PKI, TACACS+ AAA, authentication systems, and security compliance. Experienced in designing and delivering large-scale security features, including passwordless SSH authentication, remote public-key authentication, X.509 certificate lifecycle automation, and CiscoSSL/OpenSSL upgrades. Strong background in production debugging and root-cause analysis using GDB, core dumps, protocol tracing, and multithreaded systems diagnostics. Delivered fixes for security vulnerabilities, authentication failures, authorization defects, memory safety issues, and OpenSSL/FIPS compatibility challenges. Technical interests include systems programming, security engineering, cryptography, Linux internals, distributed systems, and modern authentication technologies.

Experience

4 yrs 9 mos
Total Experience
4 yrs 9 mos
Average Tenure
4 yrs 9 mos
Current Experience

Cisco

2 roles

Software Engineer II

Promoted

Oct 2025Present · 8 mos

  • Authentication, Authorization & SSH Security
  • Architected TACACS+-based Remote SSH Public Key Authentication for IOS-XR, enabling centralized AAA policy enforcement and eliminating local-only public-key authentication limitations.
  • Extended IOS-XR SSH to support FIDO/U2F hardware security keys alongside X.509 certificates and OpenSSH keys, enabling modern passwordless authentication workflows aligned with zero-trust security models.
  • Implemented local-to-remote authentication failover mechanisms, improving authentication resilience across large-scale distributed network deployments.
  • Enhanced authorization workflows across SSH, NETCONF, SCP, and SFTP services by resolving authentication and policy-enforcement defects impacting production environments.
  • OpenSSL / CiscoSSL Engineering & Security Compliance
  • Led CiscoSSL/OpenSSL upgrade initiatives to remediate security vulnerabilities and integrate modern cryptographic capabilities across IOS-XR platforms.
  • Resolved OpenSSL FIPS provider compatibility issues, preserving compliance requirements while maintaining backward compatibility for non-FIPS applications.
  • Worked extensively with OpenSSL internals including providers, EVP APIs, TLS state machines, and cryptographic configuration management.
  • Maintained and validated CiscoSSL/OpenSSL builds across multiple architectures and toolchains, including LLVM/Clang-based cross-compilation environments.
  • Production Debugging & Root Cause Analysis
  • Investigated and resolved complex production issues involving authentication failures, authorization defects, protocol interoperability problems, OpenSSL regressions, and memory safety issues.
  • Performed root-cause analysis using GDB, core dump analysis, protocol tracing, stack inspection, and multithreaded systems debugging.
  • Resolved critical security vulnerabilities including authorization bypasses, privilege-escalation paths, host-key verification issues, and memory corruption defects.
TACACS+SSHOpenSSLCiscoSSLGDBmultithreading+3

Software Engineer

Sep 2021Oct 2025 · 4 yrs 1 mo

  • PKI & Certificate Lifecycle Automation
  • Designed and implemented automated X.509 certificate lifecycle management infrastructure for IOS-XR.
  • Developed certificate auto-renewal mechanisms that reduced manual operational effort and improved certificate management scalability.
  • Enhanced PKI architecture to support increasing certificate inventories and shorter certificate validity periods.
  • Test Automation & Validation
  • Developed automated validation frameworks using CMocka and PyATS covering SSH, PKI, AAA, authentication, and authorization workflows.
  • Executed platform-wide compatibility and regression testing across multiple IOS-XR software releases and hardware architectures.
  • Collaborated with development, QA, and security teams to ensure reliable delivery of security-critical infrastructure updates.
X.509PKICMockaPyATSSecurity EngineeringInfrastructure Automation

Ta digital

Java Software Developer

Jul 2021Sep 2021 · 2 mos · Hyderabad, Telangana, India

Education

SRM IST Chennai

Bachelor's degree — Information Technology

Jan 2017Jan 2021

SRM University

Bachelor of Technology — Information Technology

Stackforce found 100+ more professionals with Network Security & Security Engineering

Explore similar profiles based on matching skills and experience