Anmol Singh Yadav

Platform Security Engineer · Mumbai, India

Download PDF

Security-focused Platform Engineer operating at the intersection of Platform Security and Security Architecture, specializing in securing cloud-native, containerized, and AI-driven systems. I translate real-world attack paths into scalable security architectures, with an emphasis on isolation-first design, attack-surface reduction, and trust-boundary enforcement — across both traditional infrastructure and emerging LLM-based workloads.

Experience

Jan 2023 — Present

Platform Security Engineer

ISS STOXX — Innovation Labs · Mumbai, India

  • Designed and led the adoption of a hardened container runtime architecture, closing a validated container-escape path across production Kubernetes clusters and Linux hosts without operational disruption.
  • Architected an SBOM-driven vulnerability intelligence system, using contextual validation and LLM-assisted prioritization to turn high-volume raw findings into a small, actionable set of real risks.
  • Designed a Kubernetes security assessment framework enabling cluster owners to identify and remediate misconfigurations such as privileged workloads, default root users, and unsafe capabilities.
  • Engineered an eBPF-based detection system providing real-time visibility into kernel-level activity across production hosts — privilege escalation, OOM events, network traffic, and sensitive file access.
  • Applied Kata Containers and runcvm for runtime isolation, implementing microVM-based security controls for containerized workloads in production.
  • Secured LLM-based systems by isolating execution, enforcing tool-access boundaries, and implementing guardrails to mitigate prompt injection and unsafe outputs.

Selected Projects

pwnspectrum

A cybersecurity intelligence and prioritization system. It aggregates public threat feeds, ranks disclosures by real-world impact, and generates contextual summaries so the signal doesn’t drown in volume.

Nautilus

A default-deny network firewall for containerized workloads, enforced at the kernel via eBPF. Every container starts with no network access; policy is what grants it, not what restricts it.

FaviCreep

A reconnaissance utility that maps attack surface by fingerprinting favicons across the internet — surfacing shadow assets, forgotten subdomains, and infrastructure an organization didn’t know was still exposed.

AWS Key Hunter

A detection tool that continuously scans public code for exposed, valid AWS credentials — built to surface real exposure, not just pattern matches, and to alert before keys are abused.

Skills

Offensive & Defensive Security

Purple teaming, container escape, privilege escalation, runtime detection & mitigation.

Security Architecture

Runtime isolation, threat modeling, secure system design.

Container & Kubernetes

Docker, containerd, runc, runcvm, Kata Containers, RBAC, CIS benchmarks.

Linux & Kernel

eBPF, syscall tracing, process monitoring, privilege-escalation analysis.

Programming

Go, Python, Bash, C/C++.

Systems & Data Pipelines

Kafka, Grafana, NiFi, Memgraph, OpenSearch.

AI Security

Prompt injection, guardrails, secure execution models, agent isolation.

Education

2019 — 2023

Vellore Institute of Technology

B.Tech in Computer Science Engineering

Specialization in Cyber Security & Digital Forensics · CGPA 9.0 / 10

Recognition

Conference Speaker

Presented API Security at GRIMMCon, covering real-world vulnerabilities in API-driven systems.

Technical Writing

Published 15+ articles on platform security, with individual articles reaching 30K+ readers. Link

Offensive Security

Ranked Top 1% (0xD — God Level) on TryHackMe through hands-on exploitation and CTF challenges. Link

Community

Volunteer at DEF CON 9111 Safe Mode.