MAYURDUSANE

Security Architecture, Platform Engineering & Applied AI

I design secure systems, platforms, and delivery paths with the teams that build them.

01

Security,
designed into
the system.

Defensive security engineer with 7+ years shaping resilient web, cloud, CI/CD, and AI systems. I work alongside developers, DevOps, and platform teams to turn architecture reviews, threat models, and security controls into production defaults.

The through-line is simple: understand how a system is designed, delivered, and operated, then make its safest behavior the natural path for every team involved.

017+

years securing systems

0225+

cross-functional projects

0330%

critical risk reduced

04E2E

design through deployment

02

Security in production

2025 — NOW

Application Security Analyst

Applause / Jersey City, NJ

Partnering with developers, DevOps, and platform teams to design secure data platforms and MCP workflows, embedding threat modeling, PII controls, container hardening, and CI/CD security from design through deployment.

2024

Application Security Intern

Applause / New York, NY

Strengthened internal platforms through architecture review, threat modeling, secure coding guidance, and reusable Flask and Vue middleware that made defensive controls easier for developers to adopt.

2019 — 2023

Software Engineer, Data Platforms & Security

uTest / Applause / India

Designed and operated production data platforms, secure identity flows, and delivery automation while coordinating security and engineering improvements across 25+ cross-functional projects.

03

Security Architecture

Shape systems so identity, data protection, and trust boundaries are intentional before implementation begins.

Most of what goes wrong in production was settled earlier, in a design decision nobody revisited. A secure design review is the cheapest place to catch it — before the authentication flow is written, before a service boundary hardens into something nobody wants to move.

The work starts as a conversation with the people who own the system. Where the trust boundaries sit. Which data crosses them, and what an attacker reaches if one component falls. Threat modeling turns that into a list you can argue with, then into decisions you can point at later: where tokens are issued and validated, how JWT, OAuth, and SSO flows behave when something is replayed or expired, which failures stay contained and which cascade.

OWASP Top 10 and CWE keep the review in shared vocabulary. Risk-based remediation decides what gets fixed first.

Secure design reviews / Threat modeling / Identity and access architecture / JWT, OAuth and SSO / Cloud and container security / OWASP Top 10 / CWE / Risk-based remediation

Platform & DevSecOps

Build security into developer workflows and delivery platforms so the secure path becomes the normal path.

Security that depends on people remembering it does not survive contact with a deadline. The version that lasts is built into the platform: a pipeline that refuses an unreviewed dependency, a base image that ships hardened, middleware that makes hostile input inert before a route handler ever sees it.

That is why CI/CD hardening matters more than any single finding. SAST and DAST are worth running where they block a merge, not fill a backlog nobody reads. Container hardening belongs in the image, not in a runbook. Secure code review stays a conversation about design instead of a search for syntax.

The measure is whether a developer can do the obvious thing and land somewhere safe. When the secure path is the shortest one, vulnerability management stops being a queue and turns back into maintenance.

Secure SDLC / CI/CD hardening / SAST / DAST / Secure code review / Container hardening / Vulnerability management / Developer enablement

AI & Platform Security

Protect the reasoning loop, the data around it, and every platform or tool an intelligent system can reach.

An agent is a system that takes untrusted input and acts on it holding real credentials. That framing does most of the work. Prompt injection defense becomes an input-trust problem. Secure MCP tool calling becomes an authorization problem: which tools a model may reach, at what scope, and what it may do with whatever comes back.

The data path needs the same attention. PII detection and redaction belong in the pipeline, before context reaches a model or a log, because a leak into a prompt and a leak into a database are the same incident. AI-generated code gets reviewed before merge like any other contribution — fluent code is not reviewed code.

MITRE ATLAS and the NIST AI RMF anchor this to named adversary behaviour and a risk framework, not intuition about what feels unsafe.

Secure MCP tool calling / AI-generated code review / PII detection and redaction / Prompt injection defense / Python and TypeScript / MITRE ATLAS / NIST AI RMF

04

Defensive ideas,
made tangible.

05

Still learning.
Still shipping.

  • M.S. Cybersecurity, Yeshiva University
  • ISC2 Certified in Cybersecurity
  • ISACA NYM Moisey Levin Memorial Scholarship
  • 3rd Place, 2024 ISACA NYM Cybersecurity Case Study Competition