About

Security, designed
into the system.

Defensive security engineer with 7+ years shaping resilient web, cloud, CI/CD, and AI systems. I work alongside developers, DevOps, and platform teams to turn architecture reviews, threat models, and security controls into production defaults.

How I work

I started as an engineer building the systems, not auditing them. That shapes how I do security work: the goal is not to hand a team a list of findings, it is to change what the default behaviour of their system is. A finding gets fixed once. A hardened base image, a pipeline that blocks an unreviewed dependency, or middleware that makes hostile input inert before a route handler sees it fixes the same class of problem for everything built afterwards.

In practice that means being in the design conversation early, running threat models with the people who own the system rather than at them, and reviewing code as a discussion about structure instead of a search for syntax. Where something has to be remembered by a person under deadline, it will eventually be forgotten — so the interesting question is always how to move it into the platform.

Background

Four years at uTest, part of Applause, as a software engineer on data platforms and security. I replaced manual data-collection workflows with a dedicated collection and labeling platform supporting AI data pipelines, added auto-labeling and human-in-the-loop reduction on a revenue-critical system, and built automation frameworks that improved test accuracy by 60% and delivery efficiency by 20% across more than 25 cross-functional projects. Alongside that I ran secure code reviews across 50+ web applications, designed JWT, OAuth, and SSO authentication flows, and led threat modeling and CI/CD security improvements.

That work is what pulled me toward security properly. I left in 2023 for the M.S. in Cybersecurity at Yeshiva University, returned to Applause as an application security intern in 2024 — running manual and automated assessments that surfaced 50+ vulnerabilities, and building the Flask and Vue middleware that became the Sanitize / Escape libraries — and moved into the application security team in 2025.

Focus right now

Securing AI and agentic systems, and the platforms they reach. I build Model Context Protocol workflows around internal platforms so teammates can extend systems with agentic tools while secure review, PII handling, and deployment controls stay in place. I review AI-generated code before merge for injection, insecure dependencies, authentication gaps, and prompt-injection-adjacent risk. I designed and shipped a self-serve platform for secure multi-type data collection and labeling, integrated PII detection and redaction to stop data leaking across AI pipelines, hardened containers and CI/CD, and cut critical vulnerabilities by 30% in a quarter. I also lead threat modeling and OWASP Top 10 remediation, and triage vulnerability disclosures from external security researchers.

Education and credentials

M.S. in Cybersecurity from Yeshiva University (Katz), New York, 2024. Advanced Certificate in Cybersecurity from IIIT Bangalore, 2023. B.E. in Information Technology from NDMVP's KBTCOE, Nashik, 2017.

ISC2 Certified in Cybersecurity (CC) and the Google Cybersecurity Specialization. I received the ISACA New York Metropolitan Chapter's Moisey Levin Memorial Scholarship, and placed 3rd in the 2024 ISACA NYM Cybersecurity Case Study Competition with an analysis of the SolarWinds supply-chain compromise.

Elsewhere

LinkedIn · GitHub · mayurdusane1@gmail.com