I find the way in,
so attackers don't.

11+ years across penetration testing, cloud security, and DevSecOps — now building the security tooling that watches over AI systems before they ship.

Chennai, India / manojsagadevan@gmail.com / LinkedIn
guest@saimanojkumar:~$ cat about.md

About

I break applications for a living, professionally and on purpose. Over the last 11 years I've worked through penetration testing, red-team operations, cloud security audits, and DevSecOps pipelines — most recently at IBM, where my focus has shifted toward a newer problem: securing the AI coding assistants and browser-based AI tools that engineering teams are adopting faster than anyone can review them.

I'd rather ship a working control than write another finding no one fixes. That's why alongside assessments, I design and build the tooling myself — DLP browser extensions, proxy-based interception tools, drift-detection platforms — treating security as software to maintain, not a report to file.

0Years in security
0Companies & teams
0Apps under drift monitoring
0Security tools shipped
guest@saimanojkumar:~$ ls -la ~/projects/

AI & product security tooling

The work I'm most known for internally: security controls built as shipped software, not slide decks.

Red-teaming

AI compliance assistant red-team

Adversarial testing of an internal AI compliance assistant — surfaced a fabricated-reference-ID technique that flipped risk ratings from HIGH to LOW, plus resistance testing against indirect prompt injection and authority-pressure social engineering.

Prompt InjectionLLM Red-teaming
guest@saimanojkumar:~$ cat skills.json

Skills

Offensive security

  • Burp Suite Professional
  • OWASP ZAP
  • Penetration testing
  • Red teaming & threat modeling

Cloud & DevSecOps

  • AWS (IAM, S3, EC2)
  • CI/CD security integration
  • Kubernetes & Docker
  • Jenkins, GoCD

AI / LLM security

  • watsonx, OpenAI APIs
  • MCP (Model Context Protocol)
  • Prompt injection testing
  • LLM governance & AI red-teaming

AppSec & governance

  • Checkmarx, Veracode, Snyk, SonarQube
  • Secure SDLC & SPbD reviews
  • Compliance & risk reporting
  • Python, Flask, REST APIs
guest@saimanojkumar:~$ curl -s credly.com/users/sai-manoj-kumar

Certifications & badges

21 verified credentials from IBM, AWS, Anthropic, and AttackIQ. The seven most relevant to security and AI are featured below — full wall underneath, every one links to its verified Credly record.

All 21 credentials

guest@saimanojkumar:~$ git log --oneline --reverse career

Experience

Jun 2022 — Present

Penetration Tester — AI & Security Innovation

IBM, Chennai

Lead AI & Innovation initiatives across IBM Consulting's security practice — designing watsonx/OpenAI and MCP-integrated tools for vulnerability triage, risk classification, and compliance reporting. Run black-box and grey-box testing and Security & Privacy by Design reviews across internal platforms.

Dec 2020 — Jun 2022

Senior Consultant — Application & Cloud Security

Cognizant Technology Solutions

Led penetration testing and risk analytics across web, mobile, and API platforms. Ran AWS security assessments covering IAM, network controls, S3, encryption posture, and Infrastructure-as-Code.

Apr 2019 — Dec 2020

Deputy Manager — Red Team & Security Operations

Axis Bank, Mumbai

Built a red-team capability from scratch for a major financial institution. Integrated SAST/DAST into CI/CD and built risk & compliance dashboards for leadership.

Nov 2017 — Mar 2019

Consultant — Application Security

Aujas Networks (Client: Axis Bank)

Application security testing across web, mobile, thick-client, and web-service platforms, with emphasis on payment gateways and transactional flows.

Nov 2016 — Nov 2017

Senior Security Engineer

Newt Global India (Client: Verizon)

Black-box and grey-box application security assessments; documented findings and verified fixes with engineering teams.

Apr 2014 — Oct 2016

Security Analyst / Junior Research Analyst

CSS Corp & Comodo Security Solutions

Monitored security logs, analyzed vulnerabilities, and performed static malware analysis for threat research and detection signatures.

AWS Certified Cloud Practitioner CCNA eWPTX B.E. Computer Science — GKM College of Engineering
guest@saimanojkumar:~$ ./contact.sh --secure

Let's talk

Open to security engineering roles and conversations about AI security, cloud security, or penetration testing. The fastest way to reach me is email.