Platform Security Engineer focused on hardening Cloud infrastructure, multi-cluster Kubernetes, and containerized workloads. I build developer-friendly security guardrails, automate threat triage, and implement secure-by-default patterns across IaC and CI/CD pipelines.
- Cloud Security: AWS, Azure, GCP
- Kubernetes & Runtime: Multi-Cluster Isolation, RBAC, Admission Controllers, Seccomp, AppArmor, Cgroups, Falco, Tetragon
- DevSecOps & Tooling: Terraform, CrowdStrike (CSPM/CWPP), Snyk (SAST/SCA), OWASP ZAP, Trivy, GitGuardian, CI/CD (Jenkins, GitHub Actions)
- Automation & Scripting: Python, Go, Bash, GenAI Workflows (Claude)
- Compliance & Frameworks: SOC 2, NIST CSF, CIS Benchmarks
Software Engineer - Security @ Contentstack (2022 - Present)
- Engineered security baselines and secure-by-default controls across AWS and multi-cluster Kubernetes environments.
- Deployed Crowdstrike, GuardDuty, and AWS Config for continuous posture monitoring and threat detection.
- Embedded Snyk and OWASP ZAP into CI/CD pipelines to catch vulnerabilities prior to deployment.
- Built Python/Go automation and GenAI workflows to streamline security alert triage and incident response.
Contributor @ Google Summer of Code (OWASP Foundation) (2024 - 2025)
- Authored Kubernetes manifests and Terraform modules for the OWTF project.
- Refactored deployment architecture from a monolith to a 3-tier microservices model across AWS and Azure.
- AWS: Certified Security - Specialty (SCS-C02) | Solutions Architect - Associate (SAA-C03)
- Kubernetes: Certified Kubernetes Administrator (CKA) | Kubernetes & Cloud Native Associate (KCNA)
- Cloud & Network: Azure Administrator (AZ-104) | Cisco CyberOps & CCNA
- LinkedIn: linkedin.com/in/rahul-surwade
- Email: rtr.rahulsurwade@gmail.com



