I Lead Cloud, Infrastructure & AI Security at CRED — owning how we secure our cloud environments, core infrastructure, and the AI systems we build and ship. My roots are in offensive security and red teaming, and I still think like an attacker: the fastest way to secure something is to understand exactly how it breaks.
Along the way I’ve built and scaled red/purple team operations — mapping tactics to the MITRE ATT&CK framework, standing up red-team and C2 infrastructure, bypassing defenses, and turning offensive findings into metrics that move a security program — alongside hands-on application and mobile security work.
This blog is where I write up the technical side of all that: cloud attack paths, C2 tradecraft, AI/ML security, and the occasional deep dive into how real systems break.
- Cloud security — securing AWS & Azure environments, attack paths, and defense
- Infrastructure security — hardening core infrastructure at scale
- AI security — securing the AI/ML systems and pipelines we build and ship
- Offensive security & red teaming — adversary emulation, MITRE ATT&CK, covert C2
- Application & mobile security — iOS assessments, architecture/security reviews, and VAPT across web, API, network, and infrastructure
- CVE-2026-20686 — Apple iOS / iPadOS (Contacts): an app could access sensitive user data. Fixed in iOS 26.3 with improved input validation; credited to me in Apple’s advisory.
- CRED — Head of Cloud, Infrastructure & AI Security
- Meesho — Security Engineer III
- FICO — Cyber Security Engineer II
- Network Intelligence — Cyber Security Analyst → Senior Analyst → Specialist
Certifications: ISO/IEC 27001:2013 Lead Auditor
- GitHub — @thatpentesterguy
- LinkedIn — atulkishorjaiswal
- X / Twitter — @atulkjaiswal