CONTACT

techsheriff

techsheriff

ABOUT

I am a cloud security architect who removes the security blockers that stall cloud adoption. I advise some of the largest cloud environments in the world, and I have built the automated guardrails that let developers move fast safely. My current focus is AI security: threat modeling agentic AI systems and securing LLM applications.

Outside of work, I enjoy woodworking, Miatas, US history, and BBQ.

SKILLS

Cloud Security Architecture, AI/LLM & Agentic Security, Threat Modeling, IAM & Data Perimeters, Network Security, Policy-as-Code (Python, CloudFormation Guard), DevSecOps, Pre-sales, Compliance, Security Strategy

CERTIFICATIONS

CISSP • CISSP-ISSAP • CSSLP • CISM • AWS Certified Security – Specialty

EDUCATION

Executive MBA

Southern Methodist University, Dallas, TX

Bachelor of Engineering in Electrical Engineering

Osmania University, India

RECENT WORK EXPERIENCE

Sr. Security Solutions Architect, Strategic Accounts

Amazon Web Services | 2023 - present

Security advisor to a portfolio of AWS's largest customers

  • Hyperscale cloud adoption: Removed the primary security blocker at one of AWS's largest strategic accounts. Showed how the AWS Nitro System's hardware-rooted security met their internal data-classification bar, which unlocked sensitive-data workloads on EC2 for the first time.
  • AI infrastructure security: Partnered with Meta on their end-to-end AWS security architecture (identity, network, and resource controls, plus secure AI clusters) and designed secure egress patterns for AI and HPC workloads; co-presented at re:Invent 2025 and re:Inforce 2025.
  • AI security practice: Presented "Novice to MAESTRO," a session on threat modeling agentic AI systems, at BSides DFW 2025. Earlier, created a hands-on workshop on securing LLM applications with custom data; it was picked for AWS's 300-level field-enablement curriculum and taught twice in 2024.
  • Adaptive edge protection: Architected Twilio's adaptive protection on AWS WAF: rules generated just-in-time and deployed through a no-touch CI/CD pipeline, protecting 1.7+ trillion interactions a year across 306,000+ customers. Co-presented at re:Inforce 2024.
  • Identity modernization: Cut long-lived IAM users by ~80% at a major social-media customer through migration to IAM Identity Center, and turned their feedback into service roadmap items.
  • Multi-account governance: Guided Pinterest's transformation from a monolithic AWS account to a multi-account AWS Organization (AWS blog).
  • DNS-first egress design: Designed Pinterest's layered egress controls: deny at the DNS resolver first, so blocked traffic never reaches Network Firewall inspection. Written up in two parts (part 1, part 2).

Security Engineer, AWS Control Tower

Amazon Web Services | 2022 - 2023

Product-side security engineering: proactive controls that validate infrastructure before it deploys

  • Policy-as-code at scale: Shipped 220+ production controls (preventive, proactive, detective) with a 3-engineer team, writing Python and extensive CloudFormation Guard DSL. Creator and security reviewer for the majority of the controls portfolio; carried production on-call.

Sr. Security Solutions Architect, FSI & Enterprise

Amazon Web Services | 2019 - 2022

Security advisor to major financial services and enterprise customers

  • Cloud perimeter protection: Reduced time to market by 3 months for an FSI customer's first app handling sensitive data in the cloud, through a layered perimeter control architecture based on threat modeling, using native and third-party security services.
  • Cloud security posture transformation: Led a major FSI to consolidate on a single CSPM tool, decreasing remediation time by 40%, and helped deploy a managed centralized CSPM deployment that cut costs by 20%.
  • Cloud-native vulnerability management: Cut a major financial exchange's patching time by 20-25% and tooling cost by 40% by replacing appliance-based scanning with cloud-native vulnerability management.
  • High-risk workload migration: Enabled 6x faster migration of a major manufacturer's workloads classified as high-risk, through threat modeling and managed-container security controls.
  • Product roadmap influence: Influenced the roadmaps of 18 AWS services by advocating strategic customers' security needs to service teams.
  • Platform evangelization: Wrote AWS's most-read security blog of 2021, co-authored the AWS Log4Shell response guidance, and co-created the FSI Service Spotlight blog series that helps customers accelerate AWS service approval through a standardized compliance and security framework.

Solution Architect

Slalom Consulting | 2017 - 2019

Cloud security architect responsible for client delivery, proposals, new business opportunities, knowledge management

  • DevSecOps transformation: Led a DevSecOps transformation for a global client: assessed the security needs of multiple DevOps teams, conducted POCs of pipeline security tools, and created roadmaps for deployment.
  • Cloud security assessments: Ensured cloud-native applications under development were compliant with regulatory and business requirements and resilient to attacks; accelerated an application migration with a threat-model-driven S3 data-protection strategy and layered controls.

Information Security Officer & Operational Risk Manager

Citigroup | 2013 - 2017

Technology & cyber risk advisor to supported business entities

  • Privileged access reduction: Managed a program that reduced persistent privileged access by 8x across 12,000 users in Citigroup's end-user computing organization.
  • Business unit security SME: Acted as cybersecurity partner for Citigroup's end-user computing engineering and operations groups, ensuring apps were developed to Secure SDLC principles and operated in alignment with company security policy.
  • Risk manager: Managed technology & operational risk for the consumer banking division by liaising with first-line and audit groups; ensured security control alignment with the firm's risk appetite and compliance needs (GDPR, SOX, FFIEC).

PRESENTATIONS & BLOGS