|
AI Security & Governance Engineer securing enterprise-scale LLM, GenAI, MCP, and agentic AI systems — and a solo founder shipping AI products end-to-end (HireEase, WarmNode). 9+ years of hands-on software development across self-directed projects, freelance work, startups, internships, research, and enterprise roles. I work across AI threat modeling, adversarial testing, red teaming, secure AI SDLC, AI governance, and runtime security controls — turning ad-hoc AI risk work into repeatable, measurable, auditable engineering. Risk focus: prompt injection · jailbreaks · tool poisoning · sensitive data leakage · excessive agency · insecure MCP servers · unsafe RAG · missing runtime controls |
|
| Metric | Result | Where |
|---|---|---|
| AI use-case review & permit-to-operate | 10–12 days → under 6 min (automated agentic review pipeline) | AT&T |
| LangGraph governance pipeline audit | 29 issues / 7 runs — incl. critical fail-open ("APPROVED" regardless of logic) | AT&T |
| LLM red-team harness | 415 adversarial prompts, full OWASP LLM Top 10, MITRE ATT&CK, CI regression gate | AT&T |
| Enterprise AI security controls authored | 42 controls / 9 categories (incl. voice-agent controls) | AT&T |
| "Contact Us" GenAI automation | 20+ hrs/week saved, 0 critical vulns, 50+ emails/day @ 95% accuracy | NOV |
| Self-improving MUD report parsing | 360× faster (8 min vs 2 days), 89–100% accuracy, 0 incidents | NOV (SPE 2026) |
| LIMA pentest framework | 95% success rate, 8+ hrs → 15 min | UH (IEEE FMLDS 2025) |
| PentestThinkingMCP | 90% accuracy / 50+ scenarios, HTB "Lame" in 3 min @ ~$0.03/run | UH |
| PentestThinkingMCP in production | ~10,000 monthly tool calls @ 99.99% reliability on Smithery · Claude / Cursor / VS Code | OSS |
| SwitchLane cost-aware routing | 40.5% cost reduction @ 100% pass rate (1,500-prompt benchmark) · 74.6% in live chat · ~1 ms routing | OSS |
| LLM vs. expert pentesters benchmark | 12/15 HTB boxes, ~95% cost reduction | UH |
| HireEase / AplyEase (founder) | 40,000+ applications processed · 300+ clients · applied to YC | Founder |
| WarmNode (founder) | Solo-built AI networking PWA · YC Fall 2026 application submitted | Founder |
🛡️ AI Security & Governance Engineer — AT&T · Plano, TX (Hybrid) · Jan 2026 – Present
- Designed and secured enterprise AI governance / permit-to-operate workflows for GenAI and agentic systems on Azure (Key Vault, Managed Identities, Defender for Cloud, Azure OpenAI).
- Led a manual security audit of a 15-node LangGraph governance pipeline — uncovered 29 issues incl. a critical fail-open defect; delivered a peer-validated remediation plan.
- Built a provider-agnostic LLM red-team harness — 415 adversarial prompts, OWASP LLM Top 10, MITRE ATT&CK scenarios, LLM-as-judge + canary detection, MAP-Elites landscape, CI regression gate; authored Sigma rules and monitored runs in Splunk ES.
- Ran multi-phase adversarial testing / red teaming (250+ prompts) on advanced enterprise LLM & agentic systems pre-deployment.
- Built privacy-preserving tokenization & masking for enterprise networking data (IPs, VLANs, infra metadata) preserving topology + semantics.
- Authored 42 AI security controls / 9 categories feeding the supplier AI requirements framework; contributed to an enterprise agentic-security control plane (AI observability/telemetry, LangGraph workflow design) aligned with zero-trust, NIST AI-RMF, secure AI SDLC.
🤖 GenAI Data Scientist — NOV Inc. (National Oilwell Varco) · Houston, TX · Jun 2025 – Jan 2026
- Contact Us AI Automation & Email Responder — AWS-hosted (Bedrock) routing engine grounded in indexed company content; threat-modeled against direct/indirect prompt injection & jailbreak per OWASP LLM Top 10 + Agentic AI Threat Modeling. 0 critical vulns, 100% compliance, 20+ hrs/week saved, 50+ emails/day @ 95% accuracy.
- Self-Improving MUD Report Automation — 3-agent GenAI system (vendor detection → prompt optimization → extraction), Azure Document Intelligence OCR + Azure OpenAI GPT-4o/5, eval DB + job pipeline on Databricks. 89–100% accuracy, 360× speedup (8 min vs 2 days), 0 incidents. Published as "Self-Improving Generative AI Agents for Automated Daily Mud Report Parsing", IADC/SPE 2026 (DOI).
- Secured MCP Server for Expression Language conversion — mitigated command injection (RCE), weak auth, missing rate limits, tool poisoning; fine-tuned a Code-Llama 8B model; enabled secure EL conversion for 5+ internal tools.
- Consulted data scientists / automation engineers on secure agentic coding and tested their AI solutions.
🔬 Research Assistant – AI & Cybersecurity — University of Houston · Houston, TX · Sep 2024 – May 2025
- Pioneered LIMA (first author) — LLM-driven, MCP-based penetration-testing framework; 95% success rate, 8+ hrs → 15 min.
- Engineered PentestThinkingMCP — reasoning agents + Nmap / Metasploit / Burp Suite across 50+ scenarios (90% accuracy); secured with prompt-injection defenses, I/O validation, rate limiting. Live
- Established a quantitative benchmark: Claude 3.5 outperformed expert pentesters on 12/15 HTB boxes (~$0.05/run). Authored IEEE FMLDS 2025 paper.
🌐 Software Engineer — Conceptech Solutions · Dubai, UAE (Remote) · Mar 2024 – Aug 2024
- Led a small engineering team delivering secure, customized web solutions for clients with React.js, Angular.js, and vanilla JavaScript.
- Worked directly with clients to translate requirements into resilient, performant applications — secure coding practices and threat modeling, owning delivery timelines end-to-end.
💻 Associate Software Engineer — Nagarro Software Pvt. Ltd. · Mar 2023 – Feb 2024
- Built secure .NET Core (C#) / SQL Server backend + React frontend for a banking client — secure coding, input validation, SQLi prevention, query optimization (30%) across 25+ APIs.
- Delivered secure REST APIs with JWT, RBAC, OWASP compliance — 1000+ daily requests, 99.9% uptime across 6+ apps.
Two AI products I founded and build end-to-end — product strategy, AI architecture, full-stack delivery, and security.
AI-powered "done-for-you" job-application platform — automated résumé tailoring + ATS optimization + job matching, paired with trained human specialists who apply on the client's behalf through a real-time tracking dashboard.
- 40,000+ job applications processed for 300+ clients. Applied to Y Combinator.
- Full-stack TypeScript: React 18 / Vite / Tailwind / Radix + Express / Drizzle ORM / PostgreSQL, Passport + JWT + bcrypt, Zod schema shared across client & server.
- Built the AI résumé-tailoring engine, a LaTeX → PDF pipeline, and a role-based (Client / Employee / Admin) employee-operations portal for application and payment tracking.
- Public components:
aplyease-backend·aplyease-frontend·aplyeasedash·hireeaseemployee
WarmNode (WarmNodeAI) — Founder & AI Engineer · Apr 2026 – Present
Privacy-focused AI relationship assistant — helps you find who in your network can help, why they matter, and what message to send. Own product strategy, AI architecture, and full-stack delivery.
- Solo founder · YC Fall 2026 application submitted · pre-seed.
- Mobile-first PWA: React / TypeScript / Vite + Node / Express / TypeScript, PostgreSQL (Supabase) / Drizzle ORM, custom secure JWT auth (no third-party provider).
- Google Gemini for semantic contact categorization and natural-language network queries (graceful local-keyword fallback); CSV contact import and Apple Wallet pass (
.pkpass) generation for shareable, privacy-conscious professional profiles.
Freelance / Conceptech Solutions — Client web delivery · 2024
Led a small team building secure customized web apps for clients (React / Angular), owning delivery end-to-end — see Experience above.
📖 Full catalogue of all 62 repositories, categorised with context for each → PROJECTS.md
| Project | What it does | Focus / Stack |
|---|---|---|
| PentestThinkingMCP 📌 | AI-powered pentest reasoning engine (MCP server) for attack-path planning, CTF/HTB solving, automated workflows — ~10,000 monthly tool calls @ 99.99% reliability on Smithery, integrated across Claude, Cursor & VS Code | MCP · Beam Search · MCTS · Metasploit/Nmap/Burp — IEEE paper |
| ClawProtect 📌 · paper | Content-aware security proxy for AI agent gateways (prompt injection / PII / secrets detection), unified with an eBPF kernel monitor and egress firewall by a cross-layer event bus for adaptive response across app / network / kernel layers | Go · Python · eBPF · Prometheus |
| SwitchLane · demo | Cost-aware LLM request routing — a single classifier call (~1 ms, no dual model calls) picks one model per request. Benchmarked: 40.5% cost reduction at 100% task pass rate (3 configs, same 1,500 prompts, real token usage & API pricing); 74.6% savings in a live chat session | Python · FastAPI · RouteLLM · llm-cost-aware-routing (validation) |
| Saleem Harness | Actively-developed personal coding-agent CLI (saleem), plugin-based on the Cordis composability framework, with a default-on preventive tool-call safety guard that blocks unsafe tool executions before they run (not logging after the fact) |
TypeScript · pnpm workspace · plugin architecture |
| EncoderThinkingMCP 📌 | MCP server guiding LLMs through encoder-decoder ML training via Beam Search + MCTS | MCP · PyTorch/TensorFlow/Keras — IEEE Southwest 2026 |
| TokenLess / TokenWatch 📌 | Token-optimization hub + dependency-free local LLM cost-tracking library; packages reusable AI skill packs (token/cost tracking, context optimization, enterprise efficiency guidelines) that plug directly into Claude Code, Windsurf, MCP agents & Copilot | Python · LiteLLM gateway · guardrails · prompt compression |
| UltraSearch 📌 | Lightning-fast laptop-wide RAG search built on LEANN vector DB | Python · Streamlit · Sentence Transformers · FAISS/HNSW |
| LLM Red-Team Library | Provider-agnostic red-team harness — 415 adversarial/bias/hallucination prompts, MAP-Elites landscape, CI regression suite | Python · OWASP LLM Top 10 · LLM-as-Judge |
| LocalRAGAgent | Offline, privacy-preserving RAG pipeline | Python · on-prem LLM |
| ML DDoS Detection | ML-based network monitoring & DDoS detection | Python · ML |
Active building threads — agent-security tooling, guardrails, and LLM cost control.
| Work Stream | What I'm building | Stack |
|---|---|---|
| Compass (contributor) | Team-built multiplayer AI agent platform with the Ward guardrail layer (screens external data / tool results, command policy, human-approval gates); I contribute on the guardrail / security side | TypeScript · Fastify · Postgres · Slack Bolt · Lit |
| dsh-dashboard | Local real-time observability dashboard for agent harnesses — token usage, cost, live tool calls, security-risk signals, straight from session logs | Node.js · Express · SSE |
| mcp-security-lab | Runnable lab with 7 intentional MCP-server vulnerabilities + fixed versions + working exploits, with a live WebSocket exploit dashboard | Python · FastMCP · Uvicorn |
| Paper | Venue | Status |
|---|---|---|
| LIMA: Leveraging Large Language Models and MCP Servers for Initial Machine Access — first author · Paper | IEEE FMLDS 2025 | ✅ Published |
| Self-Improving Generative AI Agents for Automated Daily Mud Report Parsing — second author · DOI: 10.2118/230772-MS | IADC/SPE International Drilling Conference & Exhibition, 2026 | ✅ Published |
| EncoderThinkingMCP: Guided Encoder-Decoder Model Development via MCP — w/ T. Banerjee | IEEE Southwest 2026 | 🧪 Experiment phase |
| Agentic Lean Embedding System for Vulnerability Discovery — lead researcher | — | 🔬 Active research |
| Auto ARC: AI-Powered Floor Plan Generation for Architectural Workflow Optimization — w/ M. Raza | IEEE SoutheastCon 2026 | 📝 To be submitted |
| Institution | Degree | Detail |
|---|---|---|
| University of Houston | M.S. Cybersecurity · Expected May 2026 | GPA 3.98/4.0 · $16K scholarship |
| Rajiv Gandhi Proudyogiki Vishwavidyalaya | B.Tech, Computer Science Engineering | July 2023 |
Coursework: Network Security · Secure Enterprise Computing · Cryptography · Data Analysis for Cybersecurity · Cybersecurity Risk Management · Secure Software Design
|
AI Security & Testing
Governance & Frameworks
|
Security Tooling
AI / LLM Stack
Cloud & Full-Stack
|
Certifications: OWASP Top 10 for LLMs · Microsoft Certified: Azure AI Engineer Associate · Azure AZ-900 · Azure AI-900 · ISC2 CC · Fortinet NSE 1–3 · Security+ (in progress)
flowchart LR
U[Untrusted Prompt] --> G{Guardrail Layer}
R[Retrieved Context<br/>assume poisoned] --> G
G -->|filtered| A[Agent<br/>least privilege]
A --> T{Tool Broker}
T -->|scoped + rate-limited| X[Tools / MCP Servers]
A --> O[Observability<br/>telemetry + canaries]
T --> O
O --> P[Permit-to-Operate<br/>audit + evidence]
Building secure AI systems means controlling what the model can see, what the agent can do,
what the tools can access, and what the enterprise can prove afterward.




