Mukesh Chanambatla Email

Experience

Three security roles spanning application, cloud, infrastructure, mobile, AI/ML, DevSecOps, and incident response. Open Methods & Controls for the supporting technical detail.


  1. Apr 2022 – Present
    ◆ current

    U.S. Bank

    Security Engineer

    Security engineering for internal and cloud-native applications in a regulated financial environment, working alongside product and engineering teams.

    Security scope Applications, AWS infrastructure, containerized workloads, CI/CD pipelines, and fraud-detection models each carry distinct exposure.

    Selected responsibilities Application security reviews and red team assessments; secure-by-default guidance through internal security libraries and threat-modeling templates; and hands-on assessment across cloud, container, mobile, and AI/ML systems.

    Methods & controls

    ApplicationApplication security reviews and red team assessments identifying OWASP Top 10 and business-logic vulnerabilities · manual and automated secure code review in Python, Java, JavaScript, and C# with developer remediation guidance

    Mobile · MLAndroid and iOS application security testing with MobSF, Frida, Objection, and static analysis for insecure storage and runtime behavior · adversarial ML evaluation of fraud-detection models through evasion and poisoning simulations, with review of model APIs, training-data integrity, and access controls

    Cloud · infraAWS controls with IAM, KMS, CloudTrail, and security-group hardening · Docker and Kubernetes RBAC, network policies, and policy-as-code with OPA, Kyverno, and Checkov

    PipelineSAST and DAST (SonarQube, OWASP ZAP) and container scanning embedded in CI/CD · Python-based Semgrep policies and pre-commit hooks · Terraform infrastructure-as-code modules checked with Checkov and OPA

    Detection · IRNetwork security assessments of segmentation, firewall rules, and NAC · Python and PowerShell automation for access-policy validation and log analysis · incident response with Splunk log analysis, SOC coordination, and containment and root-cause investigations · STRIDE threat models and risk assessments aligned to PCI DSS and HIPAA

    Documented boundary Specific systems, findings, and outcome metrics are not published.


  2. Oct 2020 – Jul 2021

    Netsurion

    Security Engineer

    Application security testing and DevSecOps support alongside development teams.

    Security scope Web applications and container images needed consistent assessment for injection, cross-site scripting, access-control flaws, and misconfiguration, with remediation tracked against compliance goals.

    Selected responsibilities Manual and automated AppSec testing, developer triage and secure-coding guidance, and infrastructure and container review.

    Methods & controls

    TestingManual and automated AppSec testing with Burp Suite, IBM AppScan, and OWASP ZAP for injection, XSS, and access-control issues

    RemediationFinding triage with developers, secure-coding guidance, and validation of security patches · findings documented with CVSS scoring and remediation timelines aligned to PCI and ISO 27001 goals

    InfrastructureDocker image scanning and infrastructure-as-code review for container misconfiguration

    Documented boundary Specific systems, findings, and outcome metrics are not published.


  3. Feb 2018 – Sep 2020

    LanceSoft

    Security Analyst

    Cloud vulnerability management and security-operations support across AWS and GCP environments.

    Security scope Cloud environments needed repeatable scanning and compliance reporting, and the security operations team needed help tuning detection and practicing response.

    Selected responsibilities Scanning and reporting automation, detection testing, and incident-response drill participation.

    Methods & controls

    ScanningAutomated vulnerability scanning and compliance reporting for AWS and GCP with Checkov and Trivy

    DetectionAnomaly-detection testing with AI-based tools to evaluate behavioral deviations in system logs · Python scripts for API endpoint validation, IAM policy auditing, and log parsing for potential threats

    ResponseIncident-response drills, log analysis, and alert tuning with the security operations team

    Documented boundary Specific systems, findings, and outcome metrics are not published.

Selected security work

Three personal projects listed separately from employment on Mukesh's résumé.

  1. Threat modeling for AI/ML models

    Résumé summary Comprehensive threat modeling for AI/ML models, identifying adversarial input vectors and implementing countermeasures to mitigate emerging threats.

  2. Security automation for CI/CD pipelines

    Résumé summary Security automation scripts integrated with CI/CD pipelines for automated scanning, policy validation, and vulnerability reporting.

  3. Open-source security tooling

    Résumé summary Contributions to open-source security tools and documentation focused on enhancing automation.

Project names, repositories, dates, metrics, and screenshots are not published.