Experience
Three security roles spanning application, cloud, infrastructure, mobile, AI/ML, DevSecOps, and incident response. Open Methods & Controls for the supporting technical detail.
-
Apr 2022 – Present
◆ currentU.S. Bank
Security Engineer
Security engineering for internal and cloud-native applications in a regulated financial environment, working alongside product and engineering teams.
Security scope Applications, AWS infrastructure, containerized workloads, CI/CD pipelines, and fraud-detection models each carry distinct exposure.
Selected responsibilities Application security reviews and red team assessments; secure-by-default guidance through internal security libraries and threat-modeling templates; and hands-on assessment across cloud, container, mobile, and AI/ML systems.
Methods & controls
ApplicationApplication security reviews and red team assessments identifying OWASP Top 10 and business-logic vulnerabilities · manual and automated secure code review in Python, Java, JavaScript, and C# with developer remediation guidance
Mobile · MLAndroid and iOS application security testing with MobSF, Frida, Objection, and static analysis for insecure storage and runtime behavior · adversarial ML evaluation of fraud-detection models through evasion and poisoning simulations, with review of model APIs, training-data integrity, and access controls
Cloud · infraAWS controls with IAM, KMS, CloudTrail, and security-group hardening · Docker and Kubernetes RBAC, network policies, and policy-as-code with OPA, Kyverno, and Checkov
PipelineSAST and DAST (SonarQube, OWASP ZAP) and container scanning embedded in CI/CD · Python-based Semgrep policies and pre-commit hooks · Terraform infrastructure-as-code modules checked with Checkov and OPA
Detection · IRNetwork security assessments of segmentation, firewall rules, and NAC · Python and PowerShell automation for access-policy validation and log analysis · incident response with Splunk log analysis, SOC coordination, and containment and root-cause investigations · STRIDE threat models and risk assessments aligned to PCI DSS and HIPAA
Documented boundary Specific systems, findings, and outcome metrics are not published.
-
Oct 2020 – Jul 2021Netsurion
Security Engineer
Application security testing and DevSecOps support alongside development teams.
Security scope Web applications and container images needed consistent assessment for injection, cross-site scripting, access-control flaws, and misconfiguration, with remediation tracked against compliance goals.
Selected responsibilities Manual and automated AppSec testing, developer triage and secure-coding guidance, and infrastructure and container review.
Methods & controls
TestingManual and automated AppSec testing with Burp Suite, IBM AppScan, and OWASP ZAP for injection, XSS, and access-control issues
RemediationFinding triage with developers, secure-coding guidance, and validation of security patches · findings documented with CVSS scoring and remediation timelines aligned to PCI and ISO 27001 goals
InfrastructureDocker image scanning and infrastructure-as-code review for container misconfiguration
Documented boundary Specific systems, findings, and outcome metrics are not published.
-
Feb 2018 – Sep 2020LanceSoft
Security Analyst
Cloud vulnerability management and security-operations support across AWS and GCP environments.
Security scope Cloud environments needed repeatable scanning and compliance reporting, and the security operations team needed help tuning detection and practicing response.
Selected responsibilities Scanning and reporting automation, detection testing, and incident-response drill participation.
Methods & controls
ScanningAutomated vulnerability scanning and compliance reporting for AWS and GCP with Checkov and Trivy
DetectionAnomaly-detection testing with AI-based tools to evaluate behavioral deviations in system logs · Python scripts for API endpoint validation, IAM policy auditing, and log parsing for potential threats
ResponseIncident-response drills, log analysis, and alert tuning with the security operations team
Documented boundary Specific systems, findings, and outcome metrics are not published.
Selected security work
Three personal projects listed separately from employment on Mukesh's résumé.
-
Threat modeling for AI/ML models
Résumé summary Comprehensive threat modeling for AI/ML models, identifying adversarial input vectors and implementing countermeasures to mitigate emerging threats.
-
Security automation for CI/CD pipelines
Résumé summary Security automation scripts integrated with CI/CD pipelines for automated scanning, policy validation, and vulnerability reporting.
-
Open-source security tooling
Résumé summary Contributions to open-source security tools and documentation focused on enhancing automation.
Project names, repositories, dates, metrics, and screenshots are not published.