Divyanshu S. — DevOps Engineer
Senior Security Engineer with over 8 years of experience, led the cloud security teams for AWS, GCP security & infrastructure threat modeling and along with managing cloud security including cloud-managed (EKS & GKE) and self-hosted Kubernetes security. I am an expert in cloud and application security including architecture review, threat modeling, DevSecOps automation, web pentesting, cloud pentest & audits. Additionally, skilled in implementing robust security for Infrastructure as Code (IAC), containers along with managing CSPM (Cloud Security Posture Management). I have extensive experience in training and have spoken at major conferences like Black Hat, Nullcon, BruCON, BSides, and c0c0n. Also AWS Community builder and was a crew member of Defcon Cloud Village 2020/2021/2022. Key Highlights: - Cloud Security & Compliance: Experienced in Application & Infra threat modeling & acrhitecture review for cloud infrastructure, along with that conducted EKS and GKE reviews. - Offensive Security: Performed red teaming and penetration testing across AWS and GCP, covering IAM, Lambda, Cognito, ECR and Workload Identity Federation. - Security Automation & DevSecOps: Implemented CI/CD pipelines, automated scans, and trained developers on secure coding. - Product Security & Vulnerability Management: Performed multiple web & API pentested and also reported vulnerabilities to Samsung, Airbnb, Google, Microsoft, AWS, and Apple, etc CVEs: - CVE-2019-8727 (Safari Browser) - CVE-2019-16918 (Samsung Browser) - CVE-2019-12278 (Opera Browser) - CVE-2019-14962 (Opera Mini Browser) Acknowledgments: - Cloud Security Champion at CSA Bangalore 2023 - Cybersecurity Samurai at BSides Bangalore 2023 - Star Team of the Quarter for AWS Security at Meesho - Recognized by Airbnb, Google, Microsoft, AWS, Apple, Mozilla, and others for reporting critical vulnerabilities - Secured 4th rank in TCS HackQuest'17 Open Source Projects: - OWASP EKS Goat - Very Vulnerable Serverless: AWS Lambda Security - Burp Suite Automation: Automated scanning with Python - GCP Inspector: Tool for enumerating publicly accessible GCP Buckets - Defcon Cloud Village (2020/2022/2025) CTF Contributions & Talks: - Workshops on "Defending & Attacking Kubernetes" at Nullcon Hyderabad 2024, c0c0n 2023, and BSides Bangalore 2023 - Presented arsenal tool Route53Secure Sweep at Black Hat Europe 2023 - Trainings at Nullcon 2021 & 2022 on Cloud Security - Talks at IIT Dharwad and Null Bangalore Meetup Contact & Socials: #Github Link : https://github.com/justmorpheus #Medium : justm0rph3u5.medium.com/
Stackforce AI infers this person is a Cloud Security and DevSecOps expert in the SaaS industry.
Location: Bengaluru, Karnataka, India
Experience: 8 yrs 11 mos
Skills
- Cloud Security
- Threat Modeling
- Devsecops
- Vulnerability Assessment
- Penetration Testing
- Threat Detection
- Log Management
Career Highlights
- Expert in cloud and application security.
- Led cloud security teams for AWS and GCP.
- Presented at major cybersecurity conferences.
Work Experience
Confluent
Senior Security Engineer (2 yrs 11 mos)
Meesho
Senior Security Engineer (1 yr 4 mos)
Sprinklr
Senior Security Engineer (1 yr 2 mos)
Security Engineer (10 mos)
Quotient Technology Inc.
Information Security Engineer (1 yr 5 mos)
Securonix
Security Engineer (1 yr 3 mos)
ServerGuy
Linux Administrator Intern (3 mos)
OpsTree Solutions
DevOps Engineer Intern (3 mos)
MTS - Sistema Shyam Teleservices Ltd
Network Engineer Intern (1 mo)
Intaglio Solutions
Linux Trainee (RHCSA and RHCE) (1 mo)
Gurgaon Cyber Crime Cell
Cyber Security Intern 2016 (0 mo)
Bytecode Cyber Security - India
Ethical Hacking Winter Trainee (1 mo)
Network Bulls
CCNA Security | Summer Trainee (1 mo)
CETPA Infotech Pvt. ltd.
Web Designing with PHP | Winter Trainee (1 mo)
Nettech Private Limited
Network Management Summer Trainee (0 mo)
Education
Bachelor’s Degree at Dr. A.P.J. Abdul Kalam Technical University