Senior Cloud Engineer &
AI Security Architect
Bridging 25+ years of core engineering foundations with production-grade Generative AI, Model Context Protocol (MCP) integrations, and enterprise Cloud-Native architectures.
Areas of Expertise
Production AI & Security
Securing stateful agentic workflows (Model Context Protocol). Developing advanced RAG architectures, prompt injection defenses, and mitigating OWASP Top 10 for LLMs.
Cloud Platform Engineering
Hands-on engineering across GCP and AWS environments. Managing containerized runtimes (GKE), secure VPC structures, and zero-trust API boundaries (Apigee X/Hybrid).
DevSecOps Automation
Enforcing Policy-as-Code pipelines via HashiCorp Terraform and Rego (OPA). Automating compliance checks directly into GitHub Actions, Harness, and Jenkins pipelines.
Career History
A 25+ year trajectory from deep-dive software development to leading cloud security posture, system virtualization, and high-impact AI/ML platform integrations.
Leading the API security architecture, threat modeling, and platform engineering for the enterprise integration of Google’s native Apigee Model Context Protocol (MCP) server.
- Stateful AI Boundaries: Designing proxy archetypes to secure the transition from stateless REST endpoints to stateful, context-retaining LLM/agentic patterns, mitigating prompt injection and leakage risks.
- Agentic Knowledge Base: Conceived and built an automated RAG-based agentic pipeline in Python (LangChain/LangGraph) to ingest unstructured telemetry data, using abstract adapters to update Confluence/Backstage dynamically.
- JIT Access Breakthrough: Proved interactive browser-based JIT console sessions break stateless pipelines (Terraform), winning team-wide consensus to deploy headless programmatic JIT endpoints.
Led the global engineering strategy for Application and API Security enablement across the bank's multi-cloud footprint.
- Decoupled DAST Broker: Ideated and coded a custom DAST-as-a-Service broker platform in Python and Java, abstracting internal microservices and CI/CD pipelines from scanning vendors using an asynchronous model.
- Policy as Code: Integrated custom apigeelint rules and Rego/Open Policy Agent (OPA) validation policies into build pipelines to enforce automated API security compliance gating.
- AI Triage: Built a prototype RAG and Agentic AI framework running on Google Vertex AI to automate vulnerability log ingestion and prioritization, reducing triage backlogs by 35%.
Led platform engineering for the 'Smart-Hub' system consolidation, operating heavily in AWS Cloud Native ecosystems.
- Legacy Modernization: Applied Domain-Driven Design (DDD) to decompose legacy betting engines into high-throughput Java Spring Boot microservices integrated with Kafka and AWS.
- Virtualization Bridge: Built a secure containerized bridge using layered Docker images and nested virtualization to interface 16-bit legacy retail till systems with modern cloud backends.
Served as technical lead and architect bridging legacy transaction systems with modern GCP Apigee API gateways.
- HSM Virtualization Stub: Coded a Java-based, containerized Hardware Security Module (HSM) software stub (JCA/JCE) to simulate transaction signing pipelines, completely unblocking squad testing cycles.
- Perimeter Hardening: Configured Google Apigee entry points enforcing strict mutual TLS (mTLS) and OAuth 2.0 access patterns to protect core banking channels.
Acted as principal architect and SME for the Java-based FICO Blaze Advisor rules engine platform.
- Engineered highly decoupled asynchronous RabbitMQ pathways to bridge core Java decision models with C#/.NET enterprise consumers.
- Built a custom Java Swing UI wrapper around the Blaze Rules Maintenance Application (RMA), enabling non-technical analysts to safely edit business rules.
Agile engineering lead delivering high-throughput customer-critical core systems.
- Designed and optimized core banking transaction interfaces using Oracle SOA Suite, Java EE, and complex PL/SQL.
- Automated manual deployment streams into Jenkins pipelines, initiating the team's early shift towards modern DevSecOps.
Insights & Diary
Technical writing on securing next-generation AI pipelines, static analysis in API gateways, and cloud architecture boundaries.
Published on Medium • Dec 2025
Beyond Configuration: Building an Intent-Based DAST Scanner with GenAI
Exploring how to design declarative intent frameworks that abstract OWASP ZAP using structured LLM outputs to bypass complex scanner configuration, boosting developer security adoption...
Read Full Article
Published on Medium • Oct 2025
Beyond Conventional SAST: A New Approach to Securing Apigee
In high-throughput API gateways, security verification must happen before deployment. Discussing automated static application security testing (SAST) customized for native XML-based Apigee configuration bundles...
Read Full Article