Initializing Security Posture…
CVE-2024-21626 · runc · CVSS 9.1 · ✓ MITIGATED · CVE-2023-44487 · HTTP/2 Rapid Reset · ✓ PATCHED · CVE-2024-3094 · XZ Utils · CVSS 10.0 · ✓ NOT EXPOSED · K8s CLUSTER · CIS 100% · OWASP 93% · INCIDENTS: 0 · CVE-2025-30065 · Apache Parquet · CVSS 10.0 · ✓ NOT EXPOSED · CVE-2025-29927 · Next.js Auth Bypass · ✓ PATCHED · SBOM PIPELINE NOMINAL · ALL GATES ACTIVE · SUPPLY CHAIN SECURED · CVE-2024-6387 · OpenSSH regreSSHion · CVSS 8.1 · ✓ MONITORED ·
Actively exploring DevSecOps & Cloud Security roles

ANSHUMAAN
SINGH

Building Security from Code to Cloud —
|

DevSecOps Engineer at ZEE Entertainment securing 350+ microservices across CI/CD pipelines, Kubernetes runtime, and GCP cloud governance. KubeAstronaut · 6 professional certifications · 0 production incidents. Building security where the risky path is structurally impossible.

📍 Bengaluru, India 🏢 InfoSec @ ZEE Entertainment 🎓 M.Tech CS · BITS Pilani ✦ Open to opportunities
Anshumaan Singh
Anshumaan Singh
DevSecOps & Cloud Security Engineer
@ ZEE Entertainment · Bengaluru
KubeAstronaut CKS CKA GCP-SEC TF
🛡 Security Control Plane All Nominal
CI/CD Gate Coverage
350+ PASS
SBOM Coverage
100% PASS
CIS K8s Benchmark
100% PASS
OWASP Top 10
93% GOOD
Production Incidents
0 CLEAR
0+
Microservices
Secured
0+
Professional
Certifications
0
GitHub
Repositories
0
Production
Incidents
Security Dashboard

Live Security Posture

Real capabilities and production metrics — not years of experience. Engineering outcomes that actually matter.

🛡️
0+
Microservices Secured End-to-End
Code → CI/CD → Container → Kubernetes Runtime → GCP Cloud — full coverage with zero bypass paths
0%
CIS Kubernetes Benchmark
All production GKE clusters · Benchmark v1.5.1 · Automated drift detection
🔴
0
Production Security Incidents
Since security control plane deployed in Jun 2023 — deterministic gates eliminate surprises
🏆
6+
Professional Certifications
CKS · CKA · GCP-SEC · GCP-PCA · Terraform · ACE — all active
🔐
0+
Kyverno Admission Policies
No privileged containers. Zero policy exceptions in production environments
📦
0+
Repositories Scanned
200+ credentials rotated · 47 leaks prevented Q1 · Custom regex patterns for org secrets
0d
Mean Time To Remediate
Was 14 days. Automated triage pipeline reduced MTTR by 78% across the board
🌐
0+
Engineering Teams Onboarded
Reusable pipeline templates reduced per-team setup from 2 weeks to under 1 hour
My Journey

From PCM to Cloud-Native Security

A story of continuous growth — from school rank-holder to building enterprise security platforms at scale.

2015 — 2018
High School & Intermediate · PCM
Vashisth Vatsalya Public School
Built the analytical foundation — ranked 1st in school across both high school and intermediate. Strong science and maths fundamentals that now drive how I reason about systems and security controls.
MathematicsPhysics1st RankAcademic Consistency
2019 — 2023
B.Tech · Electronics & Communication Engineering
Vellore Institute of Technology (VIT), Chennai
Built the engineering foundation: systems thinking, communication networks, embedded systems, and structured problem-solving. Discovered cybersecurity through network security electives — it clicked immediately.
ECESystems EngineeringNetworkingSignal Processing
Jun 2023 — Present
Information Security Analyst (DevSecOps · AppSec)
ZEE Entertainment Enterprises Ltd · Bengaluru, India
Built the end-to-end DevSecOps security control plane for 350+ microservices. Achieved 100% CIS Kubernetes Benchmark compliance. Led supply chain security (SBOM + Cosign), runtime guardrails (Falco + Kyverno), GCP cloud governance, and application security. Zero production incidents since deployment.
DevSecOpsKubernetes SecuritySupply Chain SecuritySBOMAppSecGCP
🥇 ZeeOlympics 2× Winner ⭐ Rating 5-A 🏆 GitHub Quiz Champion
2023 — 2025
6 Professional Certifications Earned
CNCF · Google Cloud · HashiCorp
Systematically validated expertise across the full cloud-native security stack — from Kubernetes runtime security (CKS) to cloud governance (GCP-SEC, GCP-PCA) to infrastructure automation (Terraform).
CKS · Sep 2025GCP-SEC · May 2025GCP-PCA · Apr 2025CKA · Jan 2025TF · Sep 2024
Jan 2026 — Dec 2028 · In Progress
M.Tech · Software Systems (Cybersecurity)
BITS Pilani — Work Integrated Learning Programme
Advanced cybersecurity specialization while continuing full-time security engineering. Secure software systems, distributed architecture security, IAM, cryptography, and AI/ML for security — theory meeting production reality every day.
CybersecuritySecure SDLCCloud SecurityIAMCurrently Pursuing
Philosophy

How I Think About Security

Six operating principles shaped by production delivery across CI/CD, Kubernetes, and cloud security.

01
Shift Smart, Not Just Left
Security bolted to a sprint is a tax. Built into the platform it's invisible — and teams ship faster because of it. The paved road must be the secure road.
02
Identity is the Control Plane
Network perimeters trust the packet. I trust the identity. Short-lived, OIDC-federated, cryptographically verifiable — unforgeable by design.
03
Guardrails over Gates
Gates block. Guardrails guide. One kills velocity — the other multiplies it. Build systems where the safe path is also the easiest path.
04
Detection as Code
An alert no one acts on is just log noise. Every detection maps to a playbook and a decision — not a Slack ping that gets ignored.
05
Evidence over Assertions
Don't tell auditors you're secure — show them. SBOM linked to commit. Scan output signed. Promotion gate logged. Theater out. Evidence in.
06
Risk-based, Not Fear-based
Not every critical CVE is worth blocking. CVSS + EPSS + reachability = one clear decision: block, allow with evidence, or accept with expiry.
🚀 KubeAstronaut

Certified Across the
Kubernetes Universe

KubeAstronaut — the CNCF's recognition for engineers who have demonstrated mastery across the full Kubernetes certification spectrum. Hands-on expertise in cluster administration, security hardening, cloud-native architecture, and production troubleshooting at scale.

CKS
Certified Kubernetes Security Specialist
CKA
Certified Kubernetes Administrator
KCNA
Kubernetes & Cloud Native Associate
RBAC
Role-Based Access Control Expert
OPA
Policy as Code · Kyverno · Gatekeeper
eBPF
Runtime Security · Falco · Cilium
🔐
🚀
DevSecOps

Security Control Plane

Every commit flows through 7 hardened stages — no bypass path exists. Click any stage to explore the controls.

💻
Code
PR Governance
CODEOWNERS Branch Protect Secret Scan
🔍
Build
SAST + SCA
Semgrep CodeQL Snyk
🐳
Container Scan
CVE Triage
Trivy Prisma Cloud EPSS
🔐
Sign & SBOM
Supply Chain
Cosign Syft Sigstore
🚀
Promote
Gate Verified
Registry Gate Digest Verify
☸️
Deploy
Admission Control
Kyverno ArgoCD Helm
📡
Monitor
Runtime + DAST
Falco OWASP ZAP Slack
Click any pipeline stage above to see detailed controls, tooling, and rationale
7
Pipeline Stages
0
Bypass Paths
100%
Evidence Coverage
350+
Microservices Gated
47
Leaks Prevented Q1
SLSA L2
Provenance Level
Kubernetes Security

Runtime Guardrails

Every layer of the Kubernetes security model hardened and continuously validated. Hover each domain to see the threat, mitigation, and best practice.

🔑
RBAC & Workload Identity
Least-privilege RBAC with Workload Identity Federation. OIDC-bound, cryptographically verifiable service account tokens with automatic rotation.
Identity
Threat
Overpermissioned service accounts → privilege escalation → cluster admin takeover
✓ Mitigation: Workload Identity + short-lived OIDC tokens + RBAC minimal permissions
🌐
Network Policies
Default-deny ingress and egress for all namespaces. Explicit allowlists per service pair. Automated connectivity matrix validation prevents drift.
Network
Threat
Lateral movement between compromised pods → full cluster enumeration → data exfiltration
✓ Mitigation: NetworkPolicy default-deny + Cilium eBPF enforcement + connectivity tests
🔒
Admission Controllers
45+ Kyverno policies: no-root execution, read-only root FS, dropped ALL capabilities, registry allowlist, seccomp enforcement. Zero exceptions in prod.
Policy as Code
Threat
Privileged pods → container escape → node compromise → host filesystem access
✓ Mitigation: Kyverno PSS Restricted + OPA Gatekeeper constraints + admission webhooks
👁️
Runtime Security
Falco with custom rules detecting container escapes, crypto-mining, reverse shells, unexpected binary execution, and sensitive file access in real-time.
Detection
Threat
Post-compromise persistence via dropped binaries, cron jobs, or modified system files inside containers
✓ Mitigation: Falco + custom rules + SIEM integration + automated response playbooks
🏷️
Image Verification
Kyverno policies verify Cosign signatures at admission. Unsigned or unapproved images blocked before scheduling. SBOM attestations verified cryptographically.
Supply Chain
Threat
Supply chain compromise via image tampering — malicious code injected between build and deploy
✓ Mitigation: Cosign keyless signing + Kyverno signature verification + SBOM attestation
📊
Pod Security Standards
Restricted PSS profile enforced cluster-wide. Non-root, read-only FS, no privilege escalation, seccomp runtime/default. Automated CIS drift detection alerts.
Hardening
Threat
Workload misconfiguration as attack surface — privileged, root, or host-mounted containers
✓ Mitigation: PSS Restricted + kubeaudit scans + CIS Benchmark 100% compliance
🔗
Service Mesh & mTLS
Mutual TLS between all service-to-service communication. Istio/Cilium service mesh for transparent encryption. Zero-trust traffic model inside the cluster.
Zero Trust
Threat
Man-in-the-middle attacks on intra-cluster traffic — compromised pod eavesdropping on service calls
✓ Mitigation: mTLS with certificate rotation + Istio AuthorizationPolicy + traffic encryption
🏗️
Namespace Isolation
Multi-tenant namespace architecture with ResourceQuotas, LimitRanges, dedicated service accounts, and RBAC bindings per team. Cross-team resource interference eliminated.
Multi-Tenancy
Threat
Noisy neighbor attacks and resource starvation in multi-tenant clusters affecting other team workloads
✓ Mitigation: ResourceQuotas + LimitRanges + namespace-scoped RBAC + network isolation
Cloud Security

GCP Security Architecture

Cloud-native security controls across identity, network, secrets, and observability. Click each domain to explore the implementation.

🔑
IAM + Least Privilege
Workload Identity Federation eliminates static service account keys
🌐
VPC Service Controls + Network
Data exfiltration prevention with VPC-SC perimeters
🔐
Secret Manager + KMS
Automatic rotation, CMEK encryption, zero plaintext secrets
📊
Security Command Center + Monitoring
Threat detection, vulnerability findings, compliance posture
🛡️
Cloud Armor + DDoS
WAF rules against OWASP Top 10, ML-based adaptive protection
🏛️
Organization Policies + Compliance
Org-level constraints, CIS GCP Benchmark continuous monitoring
IAM + Least Privilege
Principle of least privilege enforced at every layer. Service accounts granted only what they need — nothing more. Workload Identity Federation eliminates static key files entirely. Conditional IAM bindings restrict access by time, IP, and resource tag. Regular access reviews automated with Cloud Asset Inventory. No service account key files exist in any environment.
IAM Workload Identity Service Accounts Conditional Bindings Access Reviews
Secure SDLC

Security at Every Phase

Security controls mapped to every phase of the software development lifecycle — not bolted on at the end.

📋
Requirements
Threat Modeling STRIDE ASVS L2
🎨
Design
Security Review Trust Boundaries Attack Trees
💻
Development
SAST SCA Secret Scan
🧪
Testing
DAST Pentest SBOM Audit
🚀
Deployment
Cosign Sign Kyverno GitOps Gate
📡
Monitoring
Falco SCC SIEM Alerts
✨ Emerging Domain

Exploring AI Security

The next frontier — securing the AI/ML pipeline, protecting LLM applications, and building guardrails for the age of intelligent systems.

💉
Prompt Injection
Adversarial inputs that hijack LLM behavior — input sanitization, output validation, and defense-in-depth for AI applications
🤖
LLM Security
Model security, data poisoning, training pipeline integrity, and secure deployment patterns for production LLM systems
🗄️
RAG Security
Securing retrieval-augmented generation systems — knowledge base access controls, context window poisoning, and data leakage prevention
🔑
Secrets Exposure
API keys, credentials, and sensitive data leaking through AI system prompts, training data, or model outputs
⚖️
AI Governance
Responsible AI frameworks, model audit trails, bias detection, and policy controls for enterprise AI deployment
🛡️
Secure AI Development
Applying DevSecOps principles to the AI/ML pipeline — secure training, model versioning, supply chain integrity for ML models
Engineering Case Studies

Open Source Projects

Real repositories. Real security engineering. Every project has commits, production patterns, and measurable outcomes.

★ Featured Production Pattern CKS-Aligned
k8s-security-lab
10 real Kubernetes misconfigurations — each exploited end-to-end and documented with a hardening guide. Used by 12+ engineers for CKS preparation.
⚠ Problem
Most engineers train in sanitized labs that never expose real Kubernetes attack paths — including CKS certification preparation. The gap between theory and actual exploit chains leaves production clusters vulnerable.
⚡ Built
10 exploit-to-hardening pairs covering RBAC escapes, host namespace abuse, privilege escalation via serviceAccount tokens, pod security bypasses, and container breakout — each attacked step-by-step then hardened.
✓ Outcome
Used as CKS preparation by 12+ engineers. Every module maps to a real CVE pattern found in production Kubernetes environments. Directly informed security controls at ZEE.
kubernetes-security misconfigurations RBAC privilege-escalation CKS hardening
🔐
★ Featured Used in ZEE Production Written on Medium
image-attestation-cosign
Container image signing and attestation using Sigstore Cosign. Full supply chain integrity — sign, SBOM, verify. No trusted image without a verified signature.
⚠ Problem
No cryptographic guarantee that the container built in CI is the same one running in Kubernetes production. Supply chain attack surface open from registry to deployment.
⚡ Built
Sigstore keyless signing pipeline: OIDC-bound signatures, SBOM attestation attached as OCI artifacts, Kyverno policy verification at admission. No long-lived private keys anywhere in the chain.
✓ Outcome
Deployed in ZEE production across 350+ microservices. Zero unsigned or unapproved images reach Kubernetes runtime. SLSA Level 2 provenance achieved.
cosign sigstore supply-chain SBOM SLSA OCI
📋
45+ Policies in Production Policy as Code
kyverno-policy-demo
Policy-as-code with Kyverno for Kubernetes admission control. Block privileged pods, enforce image registries, auto-mutate workloads — governance without manual review bottlenecks.
⚠ Problem
Manual security reviews don't scale to 350+ microservices. Teams deploy inconsistently and enforcement gaps accumulate silently until a security audit or incident exposes them.
⚡ Built
45+ Kyverno admission control policies: registry whitelisting, no-privilege enforcement, resource label compliance, auto-mutation of unsafe workloads, image signature verification.
✓ Outcome
Zero privileged containers in production. 100% policy-compliant workloads. Governance runs without a single manual review bottleneck across all 350+ services.
kyverno policy-as-code admission-control OPA kubernetes-governance
🔍
47 Leaks Prevented Q1 200+ Secrets Rotated
custom-secret-regex
Custom regex patterns detecting org-specific secrets in CI/CD pipelines. Azure storage keys, internal API tokens — beyond what default scanners catch.
⚠ Problem
Default secret scanners miss company-specific credential formats. Azure storage keys, internal OAuth tokens, custom API secrets were leaking undetected into git history across 500+ repositories.
⚡ Built
Custom Gitleaks + TruffleHog pattern library tuned to org-specific formats. Integrated as CI gates and pre-commit hooks with push protection. Historical repository audit covering 500+ repos.
✓ Outcome
47 credential leaks blocked in Q1 alone. 200+ stale secrets rotated. Zero secret-related production incidents since deployment. Led credential rotation for 12 services after Azure key discovery.
secret-scanning regex gitleaks trufflehog CI/CD-security
Tech Stack

Security Engineering Arsenal

Every tool earned through shipping real security solutions — not just study. Hover to see them come alive.

GitHub Actions
Expert
Kubernetes
Expert
☁️
GCP
Expert
🔍
Semgrep
Expert
🎯
Trivy
Expert
📋
Kyverno
Expert
✍️
Cosign
Expert
📦
Syft / SBOM
Expert
👁️
Falco
Expert
🚀
ArgoCD
Expert
🏗️
Terraform
Expert
Helm
Expert
🕷️
OWASP ZAP
Advanced
🐛
Burp Suite
Advanced
🔒
Snyk
Advanced
🔬
CodeQL
Advanced
☁️
AWS
Advanced
🔷
Azure
Advanced
🐳
Docker
Expert
☁️
Checkov
Advanced
🔐
Vault
Advanced
🛡️
Prisma Cloud
Advanced
🕵️
Gitleaks
Expert
🐍
TruffleHog
Expert
Cilium / eBPF
Proficient
🐍
Python
Advanced
💻
Bash / Shell
Expert
🔗
Sigstore
Expert
⚖️
OPA Gatekeeper
Advanced
🔍
SCC Premium
Advanced
Certifications

Verified Expertise

6 active professional certifications across Kubernetes, Google Cloud, and HashiCorp — all verified on Credly.

CNCF Expert
CKS
Certified Kubernetes Security Specialist
Cloud Native Computing Foundation · Sep 2025
K8s SecurityRuntime SecRBACAdmission ControlSupply Chain
Verify on Credly ↗
CNCF Professional
CKA
Certified Kubernetes Administrator
Cloud Native Computing Foundation · Jan 2025
Cluster AdminNetworkingStorageRBACTroubleshooting
Verify on Credly ↗
Google Cloud Professional
GCP-SEC
Google Cloud Professional Cloud Security Engineer
Google Cloud · May 2025
Cloud IAMVPC SecurityComplianceSCC
Verify on Credly ↗
Google Cloud Professional
GCP-PCA
Google Cloud Professional Cloud Architect
Google Cloud · Apr 2025
ArchitectureGCP DesignReliabilitySecurity
Verify on Credly ↗
HashiCorp Associate
TF-ASC
HashiCorp Certified Terraform Associate
HashiCorp · Sep 2024
TerraformIaCProvisioningState Management
Verify on Credly ↗
Google Cloud Associate
GCP-ACE
Associate Cloud Engineer
Google Cloud · Apr 2025
GCPOperationsDeploymentMonitoring
Verify on Credly ↗
6
Active Certifications
3
Cloud Platforms
2
K8s Specializations
View All on Credly ↗
Recognition

Awards & Impact

Real awards, peer recognition, and verified impact from two years of building security at scale at ZEE Entertainment.

🥇
ZeeOlympics Best Performer — 2× Winner
Awarded across two consecutive fiscal years — FY 2023–24 and FY 2024–25. The highest engineering recognition at ZEE Entertainment. Not a single-year fluke — sustained performance recognized at org level.
FY 2023–24 FY 2024–25 2× Winner
Top Performance Rating — 5-A
Highest performance tier in FY 2024–25. Reflects delivery of the enterprise DevSecOps control plane, 100% CIS Kubernetes compliance, 0 production incidents, and expanding security scope across the organization.
FY 2024–25 Top Rating
🏆
GitHub Tech After Dark — Quiz Champion
Won the technical quiz at GitHub's Tech After Dark event in Bengaluru. Topics covered DevOps pipelines, GitHub Advanced Security, cloud-native architecture, and security tooling — competed against engineers across the ecosystem.
GitHub Event Quiz Champion
📊
Production Impact — The Numbers
Two years at ZEE. The work speaks through metrics that don't lie — 350+ microservices secured, 100% CIS compliance, 0 incidents, MTTR reduced from 14 days to 3 days.
350+ Services 0 Incidents 100% CIS K8s
Technical Writing

Security Engineering Writing

Security explained through real-world examples and production experience — 225 followers, 750+ claps on Medium.

Command Center

Get in Touch

Open to Security Engineering, DevSecOps, and Cloud Security opportunities. Reach out through any channel below.

anshumaan@devsecopswithanshu ~ security-engineer
anshumaan@sec-engineer:~$ whoami
Anshumaan Singh — DevSecOps Engineer · Cloud Security · KubeAstronaut
anshumaan@sec-engineer:~$ cat contact.json
{
  "github": "github.com/anshumaan-10",
  "status": "open_to_opportunities",
  "roles": ["Security Engineering", "DevSecOps", "Cloud Security", "AppSec"]
}
anshumaan@sec-engineer:~$