DevSecOps Engineer | Application Security | Offensive Security Background
OSCP & AWS Security Specialty certified security engineer specializing in embedding real-world attacker knowledge into cloud-native DevSecOps pipelines. I've exploited the vulnerabilities these tools are meant to catch β which means I build security gates tuned for signal, not noise.
- DevSecOps Pipeline Security β SAST, SCA, DAST, SBOM, Secret Scanning, Image Signing integrated into CI/CD
- Cloud-Native Security β AWS EKS governance, IRSA, OIDC-based identity, zero static credentials
- Infrastructure as Code Security β Terraform with partitioned state, Kyverno policy-as-code, PSA
- Application Security β Threat modeling (STRIDE), secure code review, Web/API/Mobile VAPT
- Offensive Security β OSCP certified; VAPT across banking and enterprise environments
| Area | Tools |
|---|---|
| CI/CD Security | GitHub Actions, OIDC, Semgrep, SonarQube, Trivy, OWASP ZAP, Gitleaks, Cosign |
| Cloud & IaC | AWS EKS, IAM, ECR, CloudTrail, Terraform, Kyverno, IRSA |
| AppSec / VAPT | Burp Suite, Metasploit, Nessus, Qualys, NMAP, Tenable SC |
| Languages | Bash, Python (security automation) |
Production-grade EKS governance platform built as a reference baseline β not a demo.
Enforces security at four deliberate layers:
Cloud Identity (AWS IAM)
β
Cluster Admission (Kyverno + PSA)
β
Workload Identity (IRSA)
β
Infrastructure Lifecycle (Terraform + OIDC)
Key controls:
- 3 isolated identity planes β CI (GitHub Actions OIDC), workload (IRSA), break-glass β zero static credentials
- Kyverno policies: ECR-only images, digest references, no mutable tags, PSA restricted cluster-wide
- Terraform state partitioned by responsibility boundary (network / platform / workload)
- All controls validated against live EKS cluster with captured deny/allow evidence
- Break-glass access audited via CloudTrail + CloudWatch alerting
Stack: AWS EKS Β· Terraform Β· GitHub Actions Β· Kyverno Β· IRSA Β· OIDC Β· IAM Β· ECR Β· Cosign Β· Trivy Β· Semgrep Β· Gitleaks Β· OWASP ZAP Β· CycloneDX SBOM
- π΄ OSCP β Offensive Security Certified Professional (OffSec) β Does not expire
- βοΈ AWS Certified Security Specialty β Valid till 2028
- π‘οΈ Certified Ethical Hacker (CEH) β EC-Council
- 6 years in security β progressing from network/VAPT to cloud-native DevSecOps
- 25+ VAPT engagements across Web, API, and Mobile (banking & enterprise)
- 35% reduction in critical production vulnerabilities at Mahindra Defence Systems
- PCI DSS compliance assessments across banking clients
π§ akash.oistec@gmail.com | π Mumbai, India
"Security is not a feature you add at the end β it's a property you design in from the start."