RÉSUMÉ
Koushik Kotamraju
Sr. Technical Security Engineer · Yahoo!
CERTIFICATIONS
AWS Certified Security – Specialty
AWS Certified Solutions Architect – Associate
TECHNICAL STACK
EXPERIENCE
Yahoo Inc. · Paranoids (Cloud Security)CURRENT
Feb 2022 – PresentSenior Technical Security Engineer
- —Define and operate Yahoo's company-wide cloud security baselines, authoring and maintaining the Paranoids AWS Cloud Alerts Detection system of 200+ Python detection signatures on AWS Lambda that evaluate resource configurations across 1,400+ AWS accounts, producing per-resource findings and account/BU/org security-posture scores (CSPM) the company is measured against, each with CIS-style audit and remediation guidance.
- —Conducted 150+ cloud security reviews under Yahoo's Paranoid Security Review (PSR), partnering with the Product Security, Network, and Identity teams and submitting developers, leads, and managers to threat-model and approve new cloud services and architectures before launch across Mail, Sports, Finance, and Central Tech.
- —Primary point of contact for Yahoo's AWS security baselines, coordinating the v6.0 release (the program's largest control expansion, 50+ new baselines) by researching new AWS services, running Checkov parity analysis to close policy gaps, and re-scoring every control's severity on a risk × likelihood × impact matrix.
- —Built security Claude Code skills to harden AI-assisted development: a package-hallucination detector flagging AI-invented dependency names before slopsquatting supply-chain exploitation, and a live AWS IAM audit skill (AWS CLI + IAM Access Analyzer) returning findings with severity, source attribution, and escalation-path IDs.
- —Built a toxic-combination correlation engine over CIS-based alert data, chaining findings into privilege-escalation paths across three classes: misconfig+misconfig (public SSH/RDP without IMDSv2), misconfig+IAM (public Lambda with a privileged role, or an exposed host with an over-permissioned profile), and IAM+IAM (cross-account assume-role into a privileged role, or self-escalation via attach/put-policy), catching chains single-finding scanners miss.
CYR3CON (Cyber Reconnaissance, Inc.)
May 2019 – Jan 2022Cyber Security Architect
- —Designed and built the company's multi-account AWS foundation as code (reusable Prod, Dev, Staging, and Security account templates on a Transit Gateway hub-and-spoke with segmented IP ranges and centralized SSO), and hardened it to baseline hygiene with least-privilege IAM using reusable IAM role templates, VPN-gated cloud access, and AWS Systems Manager host access that removed public SSH and bastion hosts.
- —Owned and secured the startup's self-hosted infrastructure, administering on-premise GitLab, Mattermost, and Taiga behind a data-center firewall, provisioning isolated VMs for dark-web research, and running the company's security-awareness program with internal CTFs and phishing simulations.
- —Deployed a honeypot network (T-Pot, Cowrie, and others) that collected live attacker telemetry for the company's threat-intelligence product, and partnered with the data team to build the pipelines clients used to prioritize the vulnerabilities being actively exploited against their own assets.
Cyber Reconnaissance
Dec 2017 – May 2019Cyber Security Intern → Team Lead
- —Progressed from intern to team lead within the infrastructure and security function, leading the cloud migration, running security training, and configuring data-center network security (firewall policies, segmentation, and routing across Cisco and UniFi hardware).
Infosys Limited
Dec 2015 – May 2017Systems Engineer
- —Automated a US logistics client's B2B partner data exchange on Dell Boomi (iPaaS), re-architecting the EDI integration processes and tuning connector and runtime configuration to raise processing throughput about 80%.
- —Built reusable, fault-tolerant integration patterns (connectors, maps, and sub-processes) for partner onboarding, with retries, alerting, and health monitoring that caught and recovered failed transactions to meet enterprise SLAs.
EDUCATION
M.S. Software Engineering
Arizona State University
B.E. Computer Science
Birla Institute of Technology, Mesra
Ask AI
Ask an AI about me
Each button opens the AI tool with a pre-loaded prompt pointing to my machine-readable profile. The AI reads it and answers your questions.
profile · koushik.io/llms.txt
04. What's Next?
Get In Touch
I'm always open to talking security architecture, AI infrastructure, or new opportunities. Whether you want to collaborate or just say hi, my inbox is open.
Built with Next.js · Deployed on GitHub Pages · koushik.io