VK
Security Architect · Hyderabad, India

I design systems
attackers can't walk through.

10+ years in Application Security — VAPT, SAST/DAST, DevSecOps, Threat Modeling and Cloud Security, with 3 credited CVEs. I blend hands-on pentesting with secure-by-design architecture to drive measurable risk reduction across the SDLC.

CISSP CEH AZ-500 Azure Security AWS Cloud Practitioner CVE credited Currently @ Capgemini
10+
Years in Application Security
3
CVEs credited (Supabase, conda, wg-portal)
6
Global firms — EY, Capgemini, TechM, Accenture, TCS
7+
Industry certifications (CISSP, CEH, AZ-500…)
About

Secure design meets hands-on offense

I'm a Security Architect with 10+ years across the full application-security spectrum: VAPT (web, API, mobile), SAST/DAST/SCA, threat modeling (STRIDE, OWASP ASVS), and DevSecOps pipeline security — backed by cloud security on AWS and Azure and Kubernetes hardening.

What sets me apart is the blend: I don't just review architecture on paper — I attack it. That hands-on pentesting instinct feeds directly into the reference architectures, policy gates and secure-SDLC controls I design, so the defenses I recommend actually hold up against a real adversary.

I lead cross-functional engagements, embed automated security gates into CI/CD, mentor junior engineers, and drive remediation with measurable risk reduction — translating findings into design patterns and actionable user stories that teams ship.

Career journey

Where I've built security

Capgemini — Security Architect
Sep 2025 – Present · Hyderabad, India
  • Lead security architecture reviews for web, API and cloud-native workloads; define reference architectures (authN/Z, secrets, crypto, logging, telemetry).
  • Facilitate STRIDE/ASVS threat modeling; convert threats into design patterns and actionable user stories.
  • Embed DevSecOps controls (SAST/DAST/SCA/IaC/container) with policy gates and break-glass standards.
  • Establish API security standards (OWASP API Top 10 defenses, gateway/WAF policies, token lifecycles, mTLS) and drive Kubernetes hardening.
Tech Mahindra — Senior Security Consultant (Architect scope)
Oct 2023 – Sep 2025 · Hyderabad, India
  • AppSec SME for shared services; drove secure SDLC and architecture reviews across units and AWS-hosted solutions (IriusRisk).
  • Led threat-modeling workshops; produced secure-design and secure-coding guidance aligned to ASVS.
  • Built CI/CD quality gates (Jenkins, SonarQube), container security (Trivy) and governance dashboards.
  • Recognized with a "Pat on the Back" award (2025) for excellence in MSSP AppSec delivery.
Ernst & Young — Security Consultant
May 2021 – Oct 2023
  • Led the end-to-end VAPT lifecycle for a major banking client; managed a 5-member team and formal reporting.
  • Built DevSecOps pipelines (SAST, SCA, IaC) with Jenkins, Snyk, AquaSec and Jira; advised on Zero Trust and ASVS.
  • Hardened Kubernetes (RBAC, network/pod policies); executed manual pentests for web, thick clients and APIs.
Accenture — Security Analyst
May 2020 – Apr 2021
  • Ran DAST with Tenable.io; validated issues in Burp Suite Pro; scripted report extraction in Python.
  • Contributed to Jenkins/SonarQube DevSecOps workflows and stakeholder triage.
Tata Consultancy Services — Security Engineer
Oct 2016 – May 2020
  • Led vulnerability management across two programs — exception handling, false-positive validation, remediation tracking.
  • Performed DAST, tested REST APIs, and led infra scanning (Nessus, Qualys, Nexpose) with custom risk reporting.
Skills & expertise

The toolkit

Application Security

VAPT — Web/API/MobileSASTDASTSCAThreat Modeling (STRIDE)OWASP ASVSOWASP API Top 10

DevSecOps

JenkinsSonarQubeSnykTrivyIaC / Container securityPolicy gatesMTTR reduction

Cloud & Containers

AWSAzureKubernetes hardeningRBAC / CISMicroservices & API securitymTLS

Governance & Design

Zero TrustSecure SDLCReference architecturesSecure coding guidanceRemediation governance

Tooling

Burp SuiteTenable.io / NessusRapid7NmapPostmanIriusRiskQualys

Languages & Automation

PythonBashAPI scriptingCustom reporting
Open source & tooling

Things I build

Tools built from real engagement work — the parts that turned out to be reusable, packaged so other people can run them.

HuntKit

74 offensive-security playbooks for AI coding agents — vulnerability classes plus a discipline layer that makes an agent prove a finding instead of asserting one. Ships for Claude Code, Cursor, Copilot, Codex, Gemini, Zed and the AGENTS.md standard. Load-tested on four of them; the rest are format-verified and labelled as such. Open source, MIT.

MIT · open sourceMCPAGENTS.md10 platform formats8 publication gates

github.com/krishnextgencyber/hackz-huntkit ↗

hackz Scanner

An offline DAST scanner for air-gapped corporate networks — zero outbound connections, with a multi-identity engine for the access-control bugs generic scanners are structurally blind to.

DASTAir-gappedIDOR / BOLA / BFLA

corral

Fuzzing and confinement for LLM-agent tool loops — treat the model as untrusted, find where the tool-use boundary breaks, then enforce it fail-closed at runtime.

AI-agent securityTool-use fuzzingRuntime policy

Writeups and methodology at hackz.blog — most recently five ways my own secret scanner lied to me.

Education & credentials

Certifications

CISSP
(ISC)² CC
CEH
Microsoft AZ-500
Microsoft AZ-900
AWS Cloud Practitioner
AI Security & Governance
Qualys VM

B.Tech, Electronics & Communication Engineering — Lakireddy Bali Reddy College of Engineering (2012–2016).

Security research

Credited CVEs

Original vulnerability research responsibly disclosed to vendors and assigned public CVE identifiers via GitHub Security Advisories & MITRE.

CVE-2026-54551

Missing per-user authorization on the WireGuard-portal statistics WebSocket — any authenticated user could read every peer's live traffic stats.

h44z/wg-portalCWE-862CVSS 4.3GHSA published

CVE-2026-63348

Exec injection via unescaped newlines in package-controlled .desktop shortcut fields in conda/menuinst — code execution on install.

conda/menuinstCWE-94ModerateGHSA published

CVE-2026-31813

Authentication bypass in Supabase database.dev — a forged session JWT escalated an anonymous caller to an authenticated role.

Supabase / dbdevCWE-287CVSS 6.5CVE assigned
Ask about me

Meet my profile assistant

Profile Assistant answers from Vamsi's résumé
Hi 👋 I'm Vamsi's profile assistant. Ask me about his experience, skills, certifications, or how to reach him.
What's your experience? Cloud security skills? Any published CVEs? Which certifications? How do I contact you?
Runs 100% in your browser — no server, no tracking, no cost.
Contact

Let's talk security

Open to Security Architect & AppSec leadership roles.

Threat modeling, secure-SDLC, DevSecOps enablement, cloud & Kubernetes security, and hands-on VAPT. Reach out and I'll get back within a day.

Email me →