Skip to content

CN=Kunal Joshi · O=Cloud Security · L=Mumbai, IN

Kunal Joshi

Cloud & AI Security Architect

3F:A2:9C:D4:E7:1B:4F:8D:2A:6E:C5:B9:F1:3D:7A:E4:9B:2F:6C:D8:4E:A1:7F:3C:B5:E9:1D:8A:4F:C2:6B:9E
scroll ↓
Security engineer and AWS cloud security architect with 8 years designing, securing, and optimizing enterprise-grade systems. Deep specialist in identity & access management and applied cryptography (KMS / CloudHSM / PKCS#11), with hands-on delivery for regulated financial customers. Increasingly focused on security for AI agent systems — identity propagation, delegated authorization, and least-privilege for agentic / MCP architectures.

Cloud Security Architect

verified

Amazon Web Services · Mumbai · May 2024–Present

  • Translate customer security requirements into AWS architectures across IAM, KMS, CloudTrail, GuardDuty
  • Strengthen customer IAM posture: least privilege, MFA, credential rotation, SSO via Azure AD/Okta, Just-In-Time access
  • Deliver end-to-end security solutions for enterprise customers handling sensitive financial data under Indian regulatory standards
  • Architect defenses across AWS security pillars: identity, logging/monitoring, incident response, data protection, infrastructure security

Cloud Engineer II – Security

verified

Amazon Web Services · Bangalore · Dec 2017–May 2024

  • Resolved complex issues across AWS security services: IAM, Cognito, SSO, KMS, CloudHSM, GuardDuty, Inspector
  • Recognized SME for AWS IAM (federation, SAML, SSO) and for cryptography (KMS, CloudHSM)
  • Designed internal AWS security training on IAM, CloudHSM, SSO, Secrets Manager
  • Fixed SDK issues across Python/Java/C++/C#/JS/Ruby/Go/PHP for cross-language compatibility
  • Onboarded 60+ applications into AWS SSO application catalog
section: projects
verified

CloudHSM Management Dashboard

Web UI to manage AWS CloudHSM clusters without wrangling command-line tools. Create AES/RSA/EC keys, search, and delete keys through a clean UI; test HSM connection before saving.

CloudHSMPKCS#11FastAPIReactCryptography
section: client work

Cloud-Native SIEM & SOC

for a leading stock brokerage firm

  • Built cloud-native SIEM on AWS OpenSearch
  • Custom Java log processor handling 10M+ events/minute
  • Integrated public + privately subscribed threat intelligence
  • Near-real-time alerting at ~1TB/day log volume
section: client work

KMS Key-Policy Least-Privilege Orchestrator

for a leading multinational bank

  • Identify and remediate excessive cryptographic key privileges (PCI-DSS, SOC 2)
  • Analytics engine over high-volume CloudTrail logs
  • Automated GitHub integration with approval workflows
  • Track and audit policy changes across thousands of KMS keys
section: client work

IAM Least-Privilege Orchestrator

for a leading multinational bank

  • Full-stack IAM governance platform (SOC 2, ISO 27001)
  • Automated access reviews via org-wide CloudTrail analysis
  • SAML auth + two-person-review (2PR) approval workflow
  • AWS Cloudscape UI with RBAC and automated quarterly audit reports
keyUsage: proof
verified

Credentials

  • AWS Certified Security – Specialty
  • AWS Certified AI Practitioner
  • Claude Certified Architect - Foundations
  • Identity and Access Management (IAM) Subject Matter Expert
  • Key Management Service Subject Matter Expert
  • CloudHSM Subject Matter Expert
section: expertise

Areas of Expertise

  • Identity & Access Management (IAM, federation, SAML, OAuth, SSO, JIT)
  • Applied cryptography & key management (AWS KMS, CloudHSM, PKCS#11, JCE, OpenSSL engine)
  • AWS security architecture & governance (least privilege, logging/monitoring, incident response, data protection)
  • Cloud-native SIEM / SOC (OpenSearch)
  • Infrastructure as Code & security automation
  • (Emerging) AI / agent security — on-behalf-of token exchange (RFC 8693), A2A & MCP authorization
section: technical

Technical Skills

Languages

Python, Java, C/C++

IAM

OAuth, SAML, AWS IAM, Identity Center

Cryptography

AWS KMS, CloudHSM, PKCS#11, JCE, OpenSSL dynamic engine, Encryption SDK

Security Operations

Cloud SIEM/SOC, threat hunting

Cloud

AWS security architecture & automation, IaC

AI / Agent Security (emerging)

Agentic identity, delegated authorization, RFC 8693 token exchange, A2A, MCP, least-privilege for agentic tools

section: education

Education & Honors

B.Tech, Computer Science

College of Technology and Engineering, Udaipur (2017)

Competitive Programming
  • ACM ICPC 2016 — Kolkata regional finals, Rank 58
  • Google Code Jam 2017–18
  • Tata Codevita 2016 — AIR 98