ashwin@security:~ / about-me

I'm Ashwin.

A security engineer who still likes to build, debug, and understand how things work.

What I do

I lead a corporate security team and own the platforms behind identity, privileged access, secrets, and endpoint investigation. I came up through application and product security — static analysis, WAF, vulnerability triage with engineering teams — and moved into the identity and access layer underneath them. I still design the controls, write the tools, and run the incidents alongside the engineers who use them. I like work where the security problem is ambiguous and the solution has to survive real engineering constraints.

What I care about

  • Understand the failure mode before choosing the control.
  • Make the secure path easier than the exception.
  • Enforce important boundaries in systems, not documentation.
  • Use evidence and incidents to improve policy.
  • Stay close enough to implementation to know when the design is wrong.

What I work with

  • Security — application security, product security, corporate security, cloud security, identity and access management (IAM), identity governance and administration (IGA), privileged access management (PAM), zero trust network access (ZTNA), just-in-time access, least privilege, RBAC and ABAC, policy-as-code, secrets management, non-human identity, access certification and access reviews, vulnerability management, threat modeling, incident response, endpoint security and forensics, detection and response, security automation, DevSecOps, security architecture, risk management, governance risk and compliance (GRC), SOC 2, ISO 27001, audit readiness and compliance evidence.
  • Identity standards — SAML, OIDC, OAuth 2.0, SCIM, SSO, MFA, device posture and conditional access.
  • Cloud and infrastructure — AWS (IAM, S3, EKS, Secrets Manager, WAF, Organizations), GCP, Kubernetes, Terraform, infrastructure-as-code, GitOps, CI/CD pipelines, Docker, observability and monitoring.
  • Languages and tooling — Go, Rust, Python, TypeScript, JavaScript, SQL, Bash, osquery, SAST, WAF rule development, audit log pipelines, data-driven security metrics.

What I enjoy

Outside work, you'll usually find me working through a CTF, planning my next DEF CON trip, making cortados, working on my latte art, exploring new cafés across New York, playing pickleball, or watching football. Current beans: Stumptown. Current desk rabbit hole: mechanical keyboards and whatever terminal tooling I have just discovered.

04 / how I got here

How I ended up in security.

I studied computer science and systems through a Computer Engineering degree in Pune, then Cyber Security Engineering at USC. That path took me from software and embedded systems to failure modes, trust boundaries, and adversarial thinking.

University of Southern California Viterbi School of Engineering logo

University of Southern California ↗

M.S. Cyber Security Engineering

Focused on engineering and operating secure information systems: secure applications and networks, security policy, cryptography, key management, and system assurance.

University of Pune official emblem

University of Pune ↗

B.E. Computer Engineering

Built foundations in algorithms, programming, computer architecture, software design and testing, and practical systems engineering.

Command palette
Homeg hSelected workg wAboutg aContactg c