Breaking things so they can be built securely.

I'm Yogendra. I started out breaking into systems for a living — red team, exploits, the whole "try harder" grind — before switching sides to defend a fintech platform used by millions. These days I spend more time reading pull requests than writing exploits, but the instinct is the same: find the flaw before someone with worse intentions does. This is where I write down what that actually looks like — the wins, the near-misses, and the things nobody puts in a case study.

hacker-terminal
yogendra@sec:~$ whoami.sh
> name: Yogendra Swaroop Srivastava
> role: Senior Security Engineer
> focus: AppSec, DevSecOps, Cloud Sec
> status: breaking prod (safely)
 
yogendra@sec:~$ cat mission.txt
Find it before they do.
What I write about

What I obsess over

Application Security

Secure design, threat modeling, and the gap between "secure on paper" and production.

Offensive Security

Exploitation, tooling and adversary tradecraft, explained from first principles.

Detection Engineering

Building and tuning detections that survive contact with a real attacker.

DevSecOps

CI/CD security, SAST/SCA, SBOM and supply chain security embedded into the pipeline.

Shift-Left Security

Catching risk in design and code review, before it ever reaches production.

Cloud Security

IAM, WAFs, CSPM and hardening AWS/GCP environments at scale.

Security Automation

Turning manual triage and reviews into fast, repeatable, in-workflow tooling.

Security Leadership

Prioritization, tradeoffs, and building security programs that scale with the business.

Latest writing

From the blog

View all posts

New posts, straight to your inbox.

No spam, no fluff — just deep-dives on security engineering when they're published.

Free forever. Unsubscribe anytime.