Cloud Security Architect
AWS Professional Services · Mumbai · May 2024–Present
- Lead cloud security assessments for pre-IPO firms, multinational banks, brokerages, and lenders — CTO/CISO steering sessions, readouts, prioritized remediation roadmaps
- Design and pilot security automation pipelines that run agentic workflows on every build: AI code review, penetration testing, threat modeling (AWS Security Agent)
- Secure GenAI and agentic workloads — model access control, secure RAG pipelines, identity and authorization patterns for agents (Amazon Bedrock, AgentCore)
- Design identity for agentic AI: on-behalf-of token exchange, agent-to-agent trust, least-privilege for autonomous agents and MCP-based tools
- Overhaul customer IAM posture — least privilege, MFA, SSO federation, Just-In-Time access — replacing standing admin permissions across AWS organizations
- Build cloud-native SIEM/SOC on OpenSearch from raw log ingestion to near-real-time alerting; largest handles ~1TB/day for a stock brokerage





