Architecting Secure & Resilient Multi-Cloud Platforms at Scale.

Hi, I'm Rahul Surwade. DevSecOps & Cloud Security Engineer with 4+ years of experience building secure, scalable, and cost-efficient cloud-native platforms across AWS, Azure, and GCP. Expert in Terraform IaC, Kubernetes orchestration (CKA), and multi-tenant isolation.

Ecosystem: AWS • Azure • GCP Kubernetes (CKA & KCNA) CrowdStrike & Snyk Terraform SOC 2 & ISO 27001
defense-telemetry
$ crowdstrike-cspm --audit-multi-cloud
✓ AWS, Azure & GCP posture audited: 0 High CVEs ↳ Incident Response Time reduced by 30%
$ snyk test --all-projects && snyk iac test
✓ CI/CD Pipeline Gates: SAST, DAST & SCA passed ↳ Service Control Policies & Azure Guardrails: ACTIVE
$ echo $COMPLIANCE_STATUS
SOC2_AND_ISO27001_COMPLIANT
4+ Years
DevSecOps & Cloud Security
OWASP
Open Source Contributor
7+ Certs
AWS, Azure, Kubernetes, Cisco
SOC 2 / ISO
Enterprise Compliance Enforced

Core Engineering Pillars

Leading security initiatives, hardening CI/CD pipelines, and driving compliance efforts while maintaining high developer velocity.

Multi-Cloud Security & Governance

Implementing security improvements across AWS, Azure, and GCP. Developing Terraform modules for least-privilege IAM and Service Control Policies (SCPs).

  • Cloud misconfiguration remediation across AWS, Azure, GCP
  • SCP guardrails & Azure Policy enforcement
  • CrowdStrike CSPM / CWPP / SIEM monitoring & alerting

Kubernetes & Container Hardening

Certified Kubernetes Administrator (CKA & KCNA) architecting isolated container environments, multi-tier microservices, and runtime defense.

  • Production Kubernetes orchestration & manifests
  • Container image scanning & base image minimization
  • Multi-tenant isolation for enterprise SaaS

Shift-Left DevSecOps & Compliance

Integrating SAST, DAST, and SCA (Snyk, Burpsuit) into CI/CD workflows, aligning infrastructure blueprints with SOC2, ISO 27001, and CIS benchmarks.

  • Automated CI/CD security quality gates in GitHub Actions
  • Infrastructure alignment with SOC 2 & ISO 27001
  • Cost optimization alongside infrastructure hardening

Work Experience

Proven track record in enterprise SaaS security engineering, open-source cloud infrastructure, and network engineering.

JANUARY 2022 — PRESENT

Software Engineer I - Security

Contentstack • Remote
  • Implemented security improvements across AWS, Azure, and GCP environments in collaboration with platform and DevOps teams by remediating cloud misconfigurations.
  • Monitored, triaged, and remediated cloud security incidents; managed CVEs and reduced response time by 30%.
  • Developed infrastructure-as-code (Terraform) modules to enforce least-privilege IAM and secure networking.
  • Led initiatives on container hardening, CI/CD pipeline security, and policy-as-code.
  • Integrated SAST, DAST, and SCA tools (Burpsuit, Snyk) into CI/CD pipelines to automate secure development practices.
  • Built dashboards and alerting in CrowdStrike SIEM to monitor cloud resources and suspicious activity.
  • Reviewed and improved infrastructure blueprints to align with SOC 2 and CIS benchmark requirements along with cost saving initiatives.
  • Enabled security guardrails using Service Control Policies (SCPs) and Azure Policies to restrict non-compliant actions.
MAY 2024 — SEPTEMBER 2025

Contributor

Google Summer of Code – OWASP Foundation • Remote
  • Authored Kubernetes manifests and Terraform modules for production-ready deployment of the OWTF project.
  • Improved deployment architecture by migrating from a monolith to a 3-tier microservices model, enhancing scalability and maintainability.
  • Introduced support for AWS and Microsoft Azure cloud platforms alongside existing Kubernetes deployments.
MAY 2019 — JUNE 2019

Intern – Network Engineering

Indian Ordnance Factories – Ministry of Defence • Jalgaon, Maharashtra
  • Assisted in designing and configuring internal networking infrastructure and contributed to system documentation.
  • Supported senior engineers in troubleshooting and resolving routing/switching issues.

Verified Professional Credentials

Formal technical certifications across Cloud Architecture, Security Specialties, Kubernetes, and Networking.

AWS Certified Security – Specialty

Amazon Web Services (SCS-C02)
Specialty Level

AWS Certified Solutions Architect

Amazon Web Services (SAA-C03)
Associate Level

Certified Kubernetes Administrator (CKA)

Cloud Native Computing Foundation (CNCF)
Linux Foundation

Kubernetes & Cloud Native Associate (KCNA)

Cloud Native Computing Foundation (CNCF)
Linux Foundation

Microsoft Azure Administrator (AZ-104)

Microsoft Certified
Associate Level

Cisco CyberOps

Cisco Certified
Security Operations

Cisco CCNA

Cisco Certified
Networking & Routing

Technical Expertise

Languages, platforms, security tools, and compliance frameworks applied in production.

Cloud Platforms

AWS Microsoft Azure Google Cloud (GCP)

IaC & Orchestration

Terraform Kubernetes (CKA) Docker Ansible Jenkins GitHub Actions Python

Security & AppSec Tools

CrowdStrike CSPM/CWPP/SIEM Snyk SCA & SAST Burpsuit DAST Cloudflare Policy-as-Code SOC 2 Type II ISO 27001 CIS Benchmarks NIST 800-53

Key Projects & Implementations

Enterprise cloud hardening, Kubernetes microservices, and infrastructure automation.

PROJECT 01 Enterprise SaaS Multi-Cloud Security

Multi-Cloud Misconfiguration Remediation & SIEM Alerting

Engineered automated detection and remediation of cloud misconfigurations across AWS, Azure, and GCP. Integrated CrowdStrike CSPM and SIEM dashboards to monitor suspicious activity and reduced security incident response time by 30%.

Implementation

Developed Terraform modules for least-privilege IAM and enforced Service Control Policies (SCPs) and Azure Policies.

Impact

Reduced incident response time by 30% and aligned multi-tenant infrastructure with SOC 2 & CIS standards.

AWS Azure GCP CrowdStrike SIEM Terraform
AWS / Azure / GCP Stream Cloud Telemetry
↓ Real-Time Ingestion
CrowdStrike CSPM & SIEM Alert & Triage
↓ Automated Remediation
Least-Privilege Guardrails -30% MTTR
PROJECT 02 DevSecOps CI/CD Hardening

Automated Shift-Left Security Pipeline (SAST, DAST, SCA)

Embedded automated security gates into developer CI/CD workflows using Snyk (SAST & SCA) and Burpsuit (DAST) in GitHub Actions, preventing vulnerable dependencies and misconfigurations before reaching production.

Pipeline Automation

Automated vulnerability scanning on pull requests, blocking high/critical CVEs and enforcing policy-as-code.

Developer Velocity

Empowered engineering teams with instant feedback and remediation guidance directly within GitHub PRs.

Snyk Burpsuit GitHub Actions Docker
Developer Pull Request Code & IaC
↓ CI Automated Trigger
Snyk (SAST/SCA) + ZAP (DAST) Security Gate
↓ Policy Compliance Passed
Hardened Production Release DEPLOYED
PROJECT 03 Open Source Kubernetes & IaC

3-Tier Kubernetes Architecture & Multi-Cloud Terraform

Authored production-ready Kubernetes manifests and Terraform modules for the OWASP OWTF project. Migrated deployment architecture from a monolith into a decoupled three-tier microservice model with AWS and Azure support.

Microservices Architecture

Decoupled monolithic testing system into UI, API, and worker microservices with dedicated scaling policies.

Public Repository

Official infrastructure code: github.com/owtf/owtf/tree/develop/infra

Kubernetes (CKA) Terraform AWS & Azure Docker
Terraform IaC Entry AWS / Azure
↓ Automated Provisioning
3-Tier Kubernetes Pods Decoupled Services
↓ Health Check
Scalable Security Scanner ONLINE

Academic Background

University of Mumbai

Bachelor of Engineering in Computer Science
July 2017 — June 2021 • Mumbai, Maharashtra

Connect with Rahul Surwade

Let's collaborate on cloud security, DevSecOps architecture, and infrastructure hardening.

Direct Reach & Channels

Feel free to reach out directly via email, or connect on LinkedIn and GitHub.

Send a Direct Message