Cybersecurity Professional · Identity & Access Management · PAM · Zero Trust
I design and operate the controls that decide who can touch what — and prove it. My focus is Privileged Access Management, Zero Trust architecture, and turning hard security problems into systems that hold up under real-world adversaries. I also publish independent, public-interest security research.
I'm a cybersecurity professional specialising in Identity & Access Management (IAM) and Privileged Access Management (PAM). Day to day, I work as a PAM Product Owner — building and running the platforms that govern privileged access, enforce least privilege, and make every sensitive action accountable.
My conviction is simple: security should be architectural, not procedural. Controls that depend on people remembering to do the right thing fail under pressure. Controls built into the system — zero standing privileges, just-in-time access, cryptographic enforcement, continuous monitoring — hold.
Beyond my day job, I'm passionate about applying security engineering to problems that matter at national scale. I research and publish independent, open, public-interest proposals — the kind of work I believe should exist whether or not anyone asks for it.
Lifecycle governance, authentication, authorization, and identity federation across enterprise systems.
PAM platform ownership — credential vaulting, session recording, just-in-time and zero standing privileges.
Architecting "never trust, always verify" — continuous verification, least privilege, micro-segmentation.
Key management, HSMs, certificate infrastructure, and encryption for data at rest and in transit.
Threat modelling, detection engineering, and security operations — UEBA, SIEM/SOAR, incident response.
Aligning controls to recognised frameworks and regulation, and making systems auditable by design.
Own the Privileged Access Management product: strategy, roadmap, and operations. Drive adoption of just-in-time access and zero standing privileges, credential vaulting and rotation, and full session accountability across the enterprise.
Design and deliver identity governance, authentication, and access-control capabilities — integrating IAM controls with the broader Zero Trust and security-operations stack.
Author and publish open, non-commercial security architecture proposals for problems of national importance — most recently a full zero-trust reference architecture to secure India's national examinations.
// Full role history & specifics available on LinkedIn
A complete, open zero-trust reference architecture to prevent examination paper leaks, protect merit, and rebuild public trust — covering every stage from AI-assisted paper creation to post-exam destruction. A 30-page government-grade proposal with a threat model, AI-security controls, a standards & legal compliance matrix, breach-response playbooks, budget, and KPIs.
Open to collaboration on identity security, zero-trust architecture, and public-interest research. Reach me on any of these — I read everything.