Mukesh Chanambatla Email

Identity

Mukesh Chanambatla

Security Engineer Bellevue, Washington

Security Engineer with 5+ years of experience across application, cloud, network, container, mobile, and AI/ML security. Experienced in red-team assessments, secure code review, DevSecOps, threat modeling, and incident response.

Résumé available on request by email.

Portrait of Mukesh Chanambatla

Attack surface

The systems and workflows Mukesh secures across applications, infrastructure, software delivery, incident response, and emerging technology.

  1. Applications and product surfaces

    Web and cloud-native apps, APIs, and mobile clients — where injection, broken access control, business-logic flaws, and insecure data handling appear.

  2. Cloud, network, and container infrastructure

    AWS identity and key management, network segmentation, firewall and NAC configuration, and Docker and Kubernetes workloads — where misconfiguration and excess privilege accumulate.

  3. Build and delivery pipelines

    CI/CD workflows and infrastructure-as-code, where unscanned code, weak policy enforcement, and artifact-integrity gaps let issues reach production.

  4. Detection and response gaps

    Logging, alerting, and incident-handling paths — where slow detection, unclear ownership, or missing root-cause analysis extend an incident.

  5. Mobile and AI/ML systems

    Android and iOS app behavior, and machine-learning models and pipelines exposed to evasion, poisoning, and training-data integrity risks.

Defensive engineering

Five connected capability domains show how Mukesh applies security across applications, infrastructure, delivery, response, and emerging technology. Select a domain to explore its methods and supporting experience.

Tools are representative of the résumé-supported work; they are not proficiency ratings.

Application and product security

Application security reviews and red team assessments on internal and cloud-native applications, secure code review across Python, Java, JavaScript, and C#, Android and iOS application testing, and security controls designed into feature planning and architecture reviews.

Representative methods & tools OWASP Top 10 · API security (OAuth2, JWT) · Burp Suite · OWASP ZAP · IBM AppScan · Acunetix · MobSF · Frida · Objection

Evidenced in U.S. Bank, Netsurion, and open-source security contributions.

Cloud, infrastructure, and container security

AWS security controls for least privilege and activity monitoring, network segmentation and firewall and NAC reviews, and hardening of Docker and Kubernetes workloads with policy-as-code.

Representative methods & tools AWS IAM · AWS KMS · AWS CloudTrail · Docker · Kubernetes RBAC and network policies · Checkov · OPA · Kyverno · Trivy

Evidenced in U.S. Bank, Netsurion, and LanceSoft.

Security automation and DevSecOps

SAST, DAST, and container scanning embedded into CI/CD, Semgrep policies and pre-commit hooks for developers, Terraform infrastructure-as-code checked with policy tools, and task automation in Python and PowerShell.

Representative methods & tools Semgrep · SonarQube · OWASP ZAP · GitHub Actions · Jenkins · Terraform · pre-commit hooks · Python · PowerShell · Bash

Evidenced in U.S. Bank, LanceSoft, and CI/CD security automation work.

Incident response, threat modeling, and compliance

Log analysis, incident containment, and root-cause investigation with Splunk, STRIDE threat models and risk assessments, and alignment to PCI DSS, HIPAA, NIST, and ISO 27001.

Representative methods & tools Splunk · ELK · STRIDE · MITRE ATT&CK · digital forensics · PCI DSS · HIPAA · NIST · ISO 27001

Evidenced in U.S. Bank and LanceSoft.

Mobile and AI/ML security evaluation

Adversarial evaluation of AI/ML models through evasion and poisoning simulations, model robustness review, ML pipeline threat modeling, and review of model APIs, training-data integrity, and access controls, alongside mobile application security testing.

Representative methods & tools Adversarial ML (evasion, poisoning) · model robustness evaluation · ML pipeline threat modeling · MobSF · Frida · APKTool · Ghidra

Evidenced in U.S. Bank, LanceSoft, and the featured AI/ML threat-modeling work below.

Selected security work

Résumé-backed personal security projects across AI/ML threat modeling, CI/CD automation, and open-source tooling.

  1. Threat modeling for AI/ML models

    Comprehensive threat modeling for AI/ML models, identifying adversarial input vectors and implementing countermeasures to mitigate emerging threats.