Home About Blog LinkedIn GitHub Contact Resume
Sunil Kumar

Sunil Kumar

Senior Security Engineer • CISSP


Professional Summary

A Senior Security Engineer with around 5 years of professional experience and CISSP (Certified Information Systems Security Professional), currently working at Porch Group. Demonstrates a strong background in Cloud Security, DevSecOps, Incident Response, Security Tool Implementation and Administration, SOC Implementation, and Security Automation. Holds a B.Tech in Computer Science and Engineering, along with additional certifications including CompTIA Security+, AWS Certified Security – Specialty, and Google Cloud Professional Cloud Security Engineer.

Work Experience

Porch Group, Remote

Jun 2024 – Present

Senior Security Engineer (Nov 2025 – Present)

Security Engineer (Jun 2024 – Nov 2025)

  • Developed and maintained DevSecOps pipelines integrating SAST, IaC scanning, secret scanning, container scanning, DAST, API fuzzing, and dependency scanning. Automated vulnerability reporting to Jira using custom scripts for 500+ repositories spanning diverse technologies, and implemented ASPM for comprehensive application security monitoring.
  • Implemented a SIEM solution integrating 50+ data sources, including custom integrations, parsers, correlation rules, and SOAR response workflows to enhance threat detection and automated incident response.
  • Onboarded 30+ AWS, GCP, and Azure accounts into the CSPM solution, managing misconfigurations and indicators of attack in collaboration with account owner teams.
  • Implemented Kubernetes runtime security across 15+ clusters via a KSPM platform, providing real-time workload monitoring, behavioral threat detection, and automated policy enforcement.
  • Conducted gap assessments and supported the implementation of CIS Critical Security Controls across all 18 domains, ensuring PCI-DSS compliance and control alignment.
  • Automated security workflows using Python, AWS Lambda, and Google Cloud Functions, embedding GenAI-driven alert enrichment and incident summarization to reduce manual investigation effort.
  • Collaborated with global business units, stakeholders, and leadership teams across subsidiaries to close vulnerabilities and enforce security policies enterprise-wide.
  • Led implementation of enterprise GenAI security by deploying Lakera for real-time LLM protection (prompt injection, jailbreak, and data leakage prevention) and securing LLM gateways via Portkey with policy enforcement, prompt filtering, and access controls, establishing end-to-end security for AI applications and usage across the organization.

ACKO General Insurance, Bengaluru

Aug 2021 – Jun 2024

Security Engineer

  • Developed an advanced security system utilizing AWS CloudTrail, Config, Inspector, Detective, Macie, GuardDuty, and Security Hub for detailed logging and real-time monitoring, ensuring continuous security assessment and compliance.
  • Integrated DevSecOps stages into DevOps pipelines, automating security measures such as secret scanning, SAST, IaC security, container security, SCA, and DAST.
  • Managed the triage of issues from bug bounty programs, DevSecOps, and cloud security tools, ensuring timely resolution.
  • Designed and implemented security policies for EDR, CASB, and MDM solutions, and enforced RBAC, SSO, and Conditional Access across Google Workspace, AWS, and GCP IAM.
  • Developed custom security tools, including TPRM, phishing simulations, DNS security tool, and reporting solutions to streamline processes.
  • Actively engaged in incident detection and response, enhancing defense mechanisms through deep log analysis and coordinated response.
  • Conducted risk assessments and penetration tests to identify and mitigate vulnerabilities.

Celebal Technologies, Jaipur

Feb 2021 – Jun 2021

Associate - Cloud Infra and Security Intern

  • Developed proof-of-concepts (PoCs) focused on M365 Security and related technologies, demonstrating early interest in cloud security.
  • Integrated Okta and Azure AD for centralized identity management and streamlined authentication.
  • Built Azure Monitor and Dynatrace dashboards for proactive threat monitoring and alerting.
  • Leveraged Microsoft Defender for Office 365 to enhance real-time email threat protection.

Academic Background

Government Engineering College, Ajmer

Bachelor of Technology — B.Tech (Computer Science & Engineering)

Jul 2018 – Jul 2022

7.94/10


Skills & Tools

Technologies

Cloud Security DevSecOps Security Automation SOC Incident Response Threat Detection SIEM Vuln Assessment Pentesting IAM SAST DAST IaC Security SCA ASPM CSPM SOAR DLP

Tools & Platforms

AWS GCP Azure Python Burp Suite Nmap Wireshark Metasploit Docker Jenkins Git Kubernetes OWASP ZAP CrowdStrike NetSkope Cloudflare CheckPoint Coralogix Qualys Rapid7 Google Chronicle Okta Azure AD

Frameworks / Standards

CIS Critical Security Controls PCI-DSS ISO/IEC 27001

Languages

English Hindi

Personal Learning Projects

GenAI + Security

GenAI-Based Security Alert Triage

Developed a GenAI-powered triage engine using Claude with MCP-based integrations to fetch context from SIEM, XDR, ticketing systems, historical incidents, and SOPs, enabling intelligent alert analysis across EDR, Cloud, and Application Security domains with automated TP/FP classification, enrichment, and actionable response recommendations.

ClaudeMCPSIEMXDRGenAI
Automation

Enterprise SOAR Workflow Automation

Built an enterprise SOAR workflow integrating CheckPoint, Entra ID, Okta, Mimecast, Jira, ServiceDesk, PagerDuty, CrowdStrike XDR, Exchange Online, Google Workspace, AWS, and GenAI-based analysis and enrichment to automate incident response actions triggered from SIEM detections across multiple subsidiaries, reducing MTTR.

SOARCrowdStrikeOktaJiraPagerDuty
DevSecOps

DevSecOps Pipeline with Open-Source Tools

Implemented an open-source DevSecOps pipeline using Jenkins, integrating tools like Semgrep, Checkov, Trivy, Gitleaks, OWASP ZAP, and AWS ECR scanning with automated parsing and reporting to Jira and DefectDojo for streamlined security management.

JenkinsSemgrepCheckovTrivyDefectDojo
SIEM

SIEM with 100+ Data Sources

Implemented a comprehensive SIEM solution integrating 100+ data sources with custom integrations, parsers, correlation rules, and SOAR response workflows to enhance enterprise-wide threat detection and automated incident response.

SIEMSOARCoralogixThreat DetectionAutomation
Cloud Security

KSPM & ASPM Implementation

Deployed KSPM across 15+ Kubernetes clusters for real-time workload monitoring, behavioral threat detection, and automated policy enforcement. Implemented ASPM for comprehensive application security posture management across 500+ repositories.

KSPMASPMKubernetesRuntime SecurityDevSecOps
Awareness

Phishing Awareness Platform with Gophish

Developed a phishing awareness platform using Gophish, hosted securely on AWS EC2 with Amazon SES integration to run large-scale phishing simulations and improve employee security awareness.

GophishAWS EC2Amazon SES

Certifications

CISSP (Certified Information Systems Security Professional)
CompTIA Security+
AWS Certified Security - Specialty
Google Cloud Professional Cloud Security Engineer
Docker Foundations Professional Certificate
AWS Certified Cloud Practitioner
Microsoft Certified: Azure Security Engineer Associate