Security is a practice, not a checkbox.
I'm Yogendra Swaroop Srivastava, a Senior Security Engineer with 6+ years designing and scaling security architecture across product, cloud and DevSecOps domains in high-scale, cloud-native environments. OSCP certified, with a red-team background — I like taking systems apart to understand how they break, then turning that understanding into controls, tooling and detections that hold up against a real adversary.
I started out on the offensive side — red teaming, penetration testing and training others to break things — before moving into leading organization-wide security initiatives: secure SDLC, CI/CD security frameworks, supply chain security, authentication/access control, and container and cloud security across AWS/GCP. This blog is where I write that work down — deep-dives, series, and field notes from the trenches, aimed at practitioners rather than headlines. I care more about "does this hold up under a real attack" than "does this pass the audit".
Outside of breaking and building things, I'm a brown belt in Karate, I play percussion (drums, cajon, congo), and I'm a regular at security meetups like null and BSides — mostly because I like meeting people and learning from them.
Where I've worked
Senior Application Security Engineer
Leading security engineering across application, cloud and DevSecOps domains for a fintech platform serving 2M+ active users — defining the org-wide security roadmap and aligning priorities with CISO/CTO. Designed an org-wide URL security monitoring platform enforcing SSO across 100+ services (~80% reduction in unauthenticated surface area), architected container image security across CI/CD (hardening 1000+ repos), migrated SAST/SCA tooling to open-source (saving ~$70K/yr, 35% faster MTTR), built an internal SBOM/OSS vulnerability dashboard (40% better remediation SLAs), and reduced open vulnerabilities by 90% (300+ → ~30) in 6 months. Defined a Product Security Review framework adopted by 15+ engineering teams and mentors 2 junior security engineers.
Security Engineer II
Integrated CI/CD security with Semgrep SAST/SCA across 1500+ repositories, cutting critical findings by 40% in 3 months. Built Slack-based PR security approval automation, implemented org-wide attack surface monitoring with Nuclei, established automated secret-leakage detection (secret exposure incidents to zero), and configured Cloudflare WAF rules to strengthen perimeter security.
Security Engineer I, Mobile Premier League (MPL)
Led end-to-end product security for MPL's flagship gaming app with 90M+ registered users — security architecture, VAPT, threat modeling and secure SDLC. Managed AWS WAF and Cloud Armor, launched and ran the internal Bug Bounty Program (200+ researcher-reported vulnerabilities triaged), and performed red-team assessments simulating real-world attacks (supply chain, privilege escalation, SSRF).
Security Research Engineer, VirSec Systems
Researched runtime application self-protection (RASP) techniques — code injection, RCE and memory tampering — to inform detection logic, and evaluated evasion techniques against RASP controls.
Cyber Security Instructor, Red Team — ThriveDX (formerly HackerU)
Trained 200+ students in web/app security, Linux/Windows exploitation and penetration testing; designed custom vulnerable lab environments and red-team learning content used across multiple cohorts.
Where I spend my time
Security Architecture & Leadership
DevSecOps
Cloud Security
Application & API Security
Governance & Compliance
Automation & Tooling
AI Security
Certifications
Offensive Security Certified Professional
OSCP — September 2019
Security Engineering on AWS
Running Containers on Amazon EKS
DevOps Engineering on AWS
Education
B.Tech, Computer Science Engineering
Madhav University, Rajasthan — 2016 to 2020
HSC
Seth Anandram Jaipuria School, Kanpur — 2016
SSC
Seth Anandram Jaipuria School, Kanpur — 2014