About me

Security is a practice, not a checkbox.

I'm Yogendra Swaroop Srivastava, a Senior Security Engineer with 6+ years designing and scaling security architecture across product, cloud and DevSecOps domains in high-scale, cloud-native environments. OSCP certified, with a red-team background — I like taking systems apart to understand how they break, then turning that understanding into controls, tooling and detections that hold up against a real adversary.

about_me.sh
yogendra@sec:~$ █
 
> name: Yogendra Swaroop Srivastava
> role: Senior Security Engineer
> status: still curious

I started out on the offensive side — red teaming, penetration testing and training others to break things — before moving into leading organization-wide security initiatives: secure SDLC, CI/CD security frameworks, supply chain security, authentication/access control, and container and cloud security across AWS/GCP. This blog is where I write that work down — deep-dives, series, and field notes from the trenches, aimed at practitioners rather than headlines. I care more about "does this hold up under a real attack" than "does this pass the audit".

Outside of breaking and building things, I'm a brown belt in Karate, I play percussion (drums, cajon, congo), and I'm a regular at security meetups like null and BSides — mostly because I like meeting people and learning from them.

Experience

Where I've worked

Apr 2025 — Present

Senior Application Security Engineer

Leading security engineering across application, cloud and DevSecOps domains for a fintech platform serving 2M+ active users — defining the org-wide security roadmap and aligning priorities with CISO/CTO. Designed an org-wide URL security monitoring platform enforcing SSO across 100+ services (~80% reduction in unauthenticated surface area), architected container image security across CI/CD (hardening 1000+ repos), migrated SAST/SCA tooling to open-source (saving ~$70K/yr, 35% faster MTTR), built an internal SBOM/OSS vulnerability dashboard (40% better remediation SLAs), and reduced open vulnerabilities by 90% (300+ → ~30) in 6 months. Defined a Product Security Review framework adopted by 15+ engineering teams and mentors 2 junior security engineers.

Oct 2023 — Mar 2025

Security Engineer II

Integrated CI/CD security with Semgrep SAST/SCA across 1500+ repositories, cutting critical findings by 40% in 3 months. Built Slack-based PR security approval automation, implemented org-wide attack surface monitoring with Nuclei, established automated secret-leakage detection (secret exposure incidents to zero), and configured Cloudflare WAF rules to strengthen perimeter security.

Jul 2021 — Oct 2023

Security Engineer I, Mobile Premier League (MPL)

Led end-to-end product security for MPL's flagship gaming app with 90M+ registered users — security architecture, VAPT, threat modeling and secure SDLC. Managed AWS WAF and Cloud Armor, launched and ran the internal Bug Bounty Program (200+ researcher-reported vulnerabilities triaged), and performed red-team assessments simulating real-world attacks (supply chain, privilege escalation, SSRF).

Mar 2021 — Jul 2021

Security Research Engineer, VirSec Systems

Researched runtime application self-protection (RASP) techniques — code injection, RCE and memory tampering — to inform detection logic, and evaluated evasion techniques against RASP controls.

Feb 2020 — Mar 2021

Cyber Security Instructor, Red Team — ThriveDX (formerly HackerU)

Trained 200+ students in web/app security, Linux/Windows exploitation and penetration testing; designed custom vulnerable lab environments and red-team learning content used across multiple cohorts.

Toolbox

Where I spend my time

Security Architecture & Leadership

Secure SDLC Threat Modeling Security Roadmap Product Security Review Risk Management Zero Trust Security Champions

DevSecOps

SAST/SCA CI/CD Security Policy as Code SBOM Supply Chain Security GitHub Security

Cloud Security

AWS GCP IAM / SCPs AWS WAF Cloudflare Cloud Armor Kubernetes CSPM

Application & API Security

OWASP Secure Coding Mobile/API Assessments Penetration Testing Red Teaming

Governance & Compliance

ISO 27001 PIMS BCMS SEBI CSCRF DPDPA SOC 2 Incident Response

Automation & Tooling

Python Shell Scripting Semgrep Nuclei Cortex Prisma Cloud CrowdStrike Orca Wiz

AI Security

Prompt Injection Mitigation Data Leakage Prevention Secure LLM Usage
Credentials

Certifications

Offensive Security Certified Professional

OSCP — September 2019

Security Engineering on AWS

Running Containers on Amazon EKS

DevOps Engineering on AWS

Background

Education

B.Tech, Computer Science Engineering

Madhav University, Rajasthan — 2016 to 2020

HSC

Seth Anandram Jaipuria School, Kanpur — 2016

SSC

Seth Anandram Jaipuria School, Kanpur — 2014

Let's talk.

Questions, corrections, collab ideas, or just want to say hi? My inbox is open.