Skip to content
S Swetha.
Security Engineer
Portrait of Swetha B

Offensive research · Cloud & AI defense

Swetha B.

Security Engineer

Open to new roles San Francisco ·

I started on the offensive side of security. Now I build the defense: detection and response, hardened cloud and identity, and protection for the AI infrastructure that teams ship faster than they can secure.

The short version

I took the scenic route through security, mostly the wrong way on purpose. I started by prying web applications open, moved on to hardening the cloud they run on, and now I design the automation and zero-trust guardrails that make an attacker's day genuinely annoying. A Master's in Cybersecurity from the University of Maryland gave the theory a home, and Wipro and the UMD Security Operations Center gave it teeth.

What I keep chasing is signal. Detection that fires on the things that actually matter, response that runs without a human babysitting it, and controls that engineers can live with instead of quietly routing around. Lately my off-hours belong to AI infrastructure security, where I built and open-sourced AASRT to go find the exposed agents nobody remembered to lock down. Away from the terminal there is usually a coffee within reach, and a plate of biryani on standby for whenever a stubborn bug finally gives up.

What I bring

Product Security

Offense-informed application security: scoped pentests, secure SDLC, and DevSecOps checks (SAST, DAST, CI/CD scanning) that catch flaws before they ship.

Cloud Security & IAM

AWS hardening across EC2, IAM, and S3, least-privilege policy design, and automated guardrails built with Lambda and policy-as-code.

Detection & Response

SIEM tuning that cut false positives around 30%, IR playbooks, and Tines automation that shrank time-to-containment by 25%.

Identity & Endpoint

Okta SSO, Workflows, and access reviews, plus CrowdStrike and Jamf endpoint hardening that keeps a distributed fleet locked down.

GRC & Compliance

SOC 2 and ISO 27001 evidence, threat modeling, and configuration reviews that turn audit requirements into controls people actually use.

Security from Zero

Comfortable in early-stage startups, standing up a security program from scratch and prioritizing the work that reduces the most risk first.

Tools I work with

Burp Suite Nmap Wireshark ELK / SIEM Tines Okta CrowdStrike Jamf AWS Kali Linux Python Bash

The track record

Experience

The roles where I've built, tested, and automated security.

Work

Security Engineer

YSecurity.io

Feb 2026 to Present
  • Built and managed identity and access management (IAM) on Okta SSO, automating user provisioning, access reviews, and policy enforcement with Okta Workflows across multi-client SaaS environments.
  • Managed endpoint security and device compliance across the macOS fleet using CrowdStrike Falcon (EDR), Jamf and Addigy (MDM), and Traceforce.
  • Conducted security testing across client environments, including network and Active Directory assessments and threat hunting, and supported SOC 2 and ISO 27001 readiness.
  • Integrated security into CI/CD pipelines (DevSecOps) with SAST and DAST scanning, and prioritized findings by risk using CVSS and threat intelligence.

Cybersecurity Analyst

Community Dreams Foundation

Sep 2025 to Apr 2026
  • Performed web application penetration testing with Burp Suite and OWASP ZAP, identifying and documenting SQL injection, cross-site scripting (XSS), IDOR, and authentication bypass findings with reproducible steps.
  • Conducted post-incident analysis to reconstruct attacker tactics, techniques, and procedures (TTPs), identify control gaps, and document WAF and IDS evasion.
  • Aligned security testing with PCI DSS and ISO 27001 control requirements.

SOC Analyst

University of Maryland

Dec 2024 to May 2025
  • Triaged and investigated security alerts in an ELK-based SIEM, tuning detection rules to reduce false positives and improve detection accuracy by roughly 30%.
  • Authored incident response (IR) playbooks and built Tines SOAR workflows to automate containment, reducing time-to-containment by about 25%.
  • Performed threat modeling and configuration reviews that identified misconfigurations and informed remediation priorities.

Project Engineer, Security

Wipro Technologies

Sep 2022 to Aug 2023
  • Ran vulnerability management across AWS, remediating 10+ critical findings in EC2, IAM, and S3.
  • Implemented and automated IAM guardrails using AWS Lambda and policy-as-code to reduce unauthorized-access risk.
  • Performed targeted penetration testing on internet-facing assets and partnered with product teams to improve secure defaults.

Security Engineer

Ignited Sparks

Sep 2020 to Dec 2021
  • Performed web application security testing on 8+ client projects with Burp Suite and OWASP ZAP, identifying 25+ findings including injection and authentication bypass vulnerabilities.
  • Wrote remediation guides for development teams that helped reduce vulnerability recurrence by about 20%.
  • Monitored intrusion detection systems (IDS) and analyzed security logs to support early threat detection.

Education

Master of Engineering, Cybersecurity

University of Maryland, College Park · Graduate Certificate in Cloud Engineering

Aug 2023 to May 2025

Proof of work

Projects

Things I've shipped, and the credentials behind them.

Certifications

OSCP OSCP+ CompTIA Security+ eLearnSecurity eJPT AWS Cloud Practitioner AWS Solutions Architect Associate

Say hello

Let's talk

Roles, collaborations, or a security problem worth chasing. I usually reply faster than an incident SLA.

swetha@sf: ~/contact

swetha@sf:~/contact$ ./say-hello.sh

Prefer email? Reach me directly:

swethab@terpmail.umd.edu