Application & AI security engineer

Application security systems, built for scale.

I work on application security at Finastra, where security decisions have to hold across roughly 5,000 engineers. My background is offensive security; my current focus is AI security in both directions — AI for security, and security for AI. I build practical tools that turn security decisions into repeatable engineering workflows.

01 / Work

Selected security systems

Tools designed around a concrete security bottleneck, an explicit architectural choice, and evidence that is measured honestly — pending metrics are marked as pending.

ASPM Dashboard

Internal platform / Security posture management

Security findings at Finastra lived in disconnected tools — GitHub CodeQL, SCA, container scanning — so there was no single view of application security posture, and maturity conversations ran on anecdotes.

A single pane of glass — Go backend, React frontend — that aggregates CodeQL, SCA, and container-scanning results, computes a maturity score enriched with SAMM assessments, API security posture, WAF coverage, and other static signals, and answers teams' posture questions through a RAG assistant grounded in platform data and documentation.

Built with / Go / React / RAG / Vector DB

Signals / GitHub CodeQL / SCA / Container scanning / SAMM / API security posture / WAF coverage

Impact evidence pending Internal Finastra platform; shareable adoption and coverage figures pending approval.

CodeQL Reporting

Internal platform / SAST migration & triage

Finastra's move from Checkmarx to GitHub CodeQL exposed two operational gaps — CodeQL produces no detailed report equivalent, and GitHub's alert view cannot filter findings product teams have asked to dismiss — while high false-positive volume eroded trust in the new scanner.

A Go and React platform, in Finastra's design language, that adds the missing reporting and dismissal-review workflows on top of GitHub code scanning, plus an AI triage layer that reconstructs each finding's source-to-sink path from SARIF and has an LLM judge it on evidence.

Built with / Go / React

Signals / GitHub CodeQL / SARIF / GitHub code scanning API / LLM triage

Impact evidence pending Internal Finastra platform; false-positive reduction and adoption figures pending approval for public use.

Vektor

Active / AI-native SAST

Static analysis at enterprise scale produces more findings than any AppSec team can triage, and single-engine coverage leaves systematic gaps.

Orchestrates CodeQL, OpenGrep, and Joern as complementary engines, then applies an LLM false-positive filter layer so humans review a ranked, deduplicated queue instead of raw scanner output.

Built with / CodeQL / OpenGrep / Joern / LLM filter layer / Python

Impact evidence pending False-positive reduction rate and triage-time comparison pending publication of the evaluation set.

burpai

Open source / Offensive tooling

Moving between intercepted HTTP traffic and AI-assisted analysis usually means pasting sensitive request data into external chat tools.

A Java extension on Burp's Montoya API with provider choice: local Ollama for confidentiality-sensitive work, plus optional cloud models when engagement data-handling controls permit them.

Built with / Java / Burp Montoya API / Ollama / Cloud LLM providers

Verified artifact Public MIT-licensed repository and v1.9.0 release verified; usage and assessment-impact metrics are not yet published.

ThreatCanvas

Prototype / Threat modeling

Threat models rot: they live in documents nobody updates when architecture and trust boundaries change.

Treats the threat model as structured system data with an interactive diagram editor (AntV X6), a Go/chi backend, Azure AD SSO for enterprise use, and Azure OpenAI GPT-4o assisting threat identification against the modeled architecture.

Built with / React / TypeScript / Vite / AntV X6 / Go / chi / Azure AD SSO / Azure OpenAI GPT-4o

Impact evidence pending Pilot completion-time and model-coverage baselines not yet published.

reconx

Research tool / Reconnaissance

Recon toolchains are fragile: a dozen tools with conflicting runtimes, dependencies, and install steps, rebuilt by hand on every new machine or engagement.

A zero-dependency Go static binary that bundles 12 pre-compiled reconnaissance tools, so a single artifact drop gives a complete, consistent recon capability anywhere Go binaries run.

Built with / Go / static linking / embedded tooling

Verified artifact Public source is available as trace; coverage, runtime, and false-positive benchmarks are still pending.

02 / About

Security engineering with operational memory.

I build security capabilities that teams can run repeatedly: clear models, useful automation, testable controls, and feedback that improves the system. My experience spans application security and offensive practice in BFSI and fintech environments, and my current work covers both directions of AI security — using AI to do security work better, and securing systems that contain AI. My roots are offensive security, and everything I build carries that: secure by design, never security as an afterthought.

Certification CISSP
Community null — The Open Security Community
Current base Bangalore, India
Open to relocation Singapore / UAE / UK / Germany