Independent Cloud Security Consultant

Hi, I'm Shashank Dubey|

I help organizations secure their cloud infrastructure on AWS, Azure, and GCP, covering architecture review, threat modeling, Pre-sales, compliance, and offensive security assessments.

BlackHat MEA Arsenal '24 DEF CON 9111 Speaker AWS Solutions Architect
Scroll

Cloud Attack Path Analysis

Real-world web-to-cloud attack paths mapped across AWS, Azure, and GCP, tracing every step from initial access to full compromise.

AWS API Timing Abuse for Denial of Service

Presented at BlackHat MEA Arsenal 2024. A post-exploitation utility that weaponizes the timing discrepancy between AWS Create and Delete APIs.

BlackHat MEA Arsenal 2024
Denial of Service

The Discovery

AWS Create* API calls consistently complete faster than their corresponding Delete* API calls across multiple services. This timing asymmetry means resource creation outpaces cleanup, creating a window for quota abuse.

Create API
~120ms
Delete API
~800ms
~6x timing gap exploitable at scale
01

Rapid Create Flood

AWS Bomber sends parallel Create calls for Security Groups, IAM Roles, VPCs, and other quota-bound resources.

02

Quota Saturation

Because creations outpace deletions, the target account rapidly hits its maximum service quota limits.

03

Automation Disruption

Terraform, CloudFormation, CI/CD pipelines, and any IaC relying on resource provisioning fail with quota exceeded errors.

Affected Resources

Security Groups IAM Roles VPCs Subnets EBS Volumes Lambda Functions S3 Buckets CloudFormation Stacks

Cloud security researcher with 5+ years of hands-on experience.

I've built CSPM and ASM products at security startups, performed threat modeling for enterprises, and implemented compliance frameworks in production. My background spans offensive security research, DevSecOps, and cloud-native architecture on AWS, Azure, and GCP.

As an independent consultant, I think like an attacker and build like an engineer. I've shipped production security tooling and presented original research at Black Hat MEA, DEF CON 9111, and India's Ministry of Electronics & IT.

0 Years in Cloud Security
0 Cloud Attack Paths Mapped
0 Cloud Platforms
0 Conference Presentations

What I Can Help With

Cloud security services covering pre-sales advisory, architecture design, offensive testing, and AI-powered threat detection.

Cloud Security Assessment & Configuration Review

Deep-dive reviews of AWS, Azure, and GCP environments. Misconfiguration detection, policy audits, IAM analysis, and attack surface mapping across CSPM, CWPP, CIEM, and KSPM.

  • CSPM
  • CWPP
  • CIEM
  • KSPM
  • Config Review

Cloud Pentesting & Red Teaming

Offensive security engagements focused on privilege escalation, lateral movement, IAM exploitation, container breakouts, and attack path simulation in live cloud environments.

  • Pentesting
  • Red Team
  • IAM Exploit
  • Container Escape

Cloud Security Architecture

Secure-by-default cloud architecture design. Landing zone blueprints, zero-trust networking, multi-account strategy, and reference architectures for multi-cloud setups.

  • Architecture
  • Zero Trust
  • Landing Zone
  • Multi-Cloud

Cloud Security Pre-Sales

Technical pre-sales for cloud security products. PoC demonstrations, competitive analysis, customer threat modeling, RFP responses, and solution architecture for CSPM/CNAPP/CWPP platforms.

  • Pre-Sales
  • PoC
  • RFP
  • CNAPP

Compliance & Governance

Audit and implement CIS Benchmarks, NIST, ISO 27001, HIPAA, and GDPR. Build guardrails and policy-as-code that keep teams compliant without slowing them down.

  • CIS
  • NIST
  • HIPAA
  • GDPR
  • ISO 27001

DevSecOps & Pipeline Security

Bake security into CI/CD pipelines and SDLC. Automated scanning, policy-as-code, and secure container orchestration on EKS, AKS, and GKE.

  • CI/CD
  • Kubernetes
  • Terraform
  • IaC Scan

AI + Cloud Security

Securing AI/ML workloads on cloud platforms. LLM deployment security, model endpoint hardening, AI pipeline protection, and ML-driven threat detection on cloud-native data.

  • AI Security
  • LLM
  • ML Pipelines
  • SageMaker
  • Vertex AI

Cloud Monitoring & Detection

Real-time monitoring and anomaly detection with automated alerting and self-healing remediation. Built on CloudTrail, EventBridge, Lambda, and SIEM integrations.

  • SIEM
  • CloudTrail
  • AI Detection
  • Auto-Remediate

Security Training & Workshops

Cloud attack labs, security awareness workshops, and team upskilling. Red team exercises, CTF challenges, and AI-assisted threat hunting sessions.

  • Labs
  • Workshops
  • CTF
  • AI Training

Professional Journey

Jul 2025 — Feb 2026

Cloud Security Researcher

Cyble

Enhanced CSPM and ASM capabilities across AWS, Azure, and GCP by expanding scanner coverage, strengthening findings, and validating KSPM and multi-cloud attack surface visibility.

  • Expanded scanner coverage and strengthened CSPM findings across multi-cloud
  • Executed multi-cloud black-box PoCs for ASM findings and attack surface detection
Jan 2025 — May 2025

Sr. AWS Cyber Security Engineer

TryHackMe Contract

Built defensive AWS security tools, designed cloud attack labs, and automated threat detection using CloudTrail.

  • Developed defensive AWS security solutions using native services
  • Designed hands-on cloud attack labs for simulation and training
  • Tracked simulation progress via CloudTrail and Lambda
Aug 2024 — Dec 2024

Cloud Security Researcher

CheckRed India

Built ASM components and 50+ unique attack paths across AWS, Azure, and GCP; enhanced product security for CSPM, SSPM, CWPP, and CIEM modules.

  • Mapped 50+ unique attack paths across AWS, Azure, and GCP
  • Enhanced CSPM, SSPM, CWPP, and CIEM modules
  • Strengthened API and DNS security through advanced detection
May 2022 — Jul 2024

Cloud Security Engineer

Payatu

Performed threat modeling and simulation on cloud architectures, implemented cloud-native security, and contributed to HIPAA compliance.

  • Conducted threat modeling across AWS, Azure, and GCP
  • Implemented cloud-native security for Containers and Kubernetes
  • Deployed ELK stack for real-time cloud security monitoring
  • Contributed to HIPAA compliance implementation
Nov 2020 — May 2022

Software Engineer, Cloud Security

SysCloud Technologies

Managed AWS cloud security, IAM, and Active Directory; built organization-wide security modules and collaborated with SRE for secure deployments.

  • Managed internal and external AWS cloud security policies
  • Built organization-wide security modules and guardrails
  • Worked with SRE for secure CI/CD deployments

Achievements & Certifications

MeitY — Govt. of India

Cloud Security Assessments Talk

Talk on cloud security assessments, audit methodologies, and implementing practical controls at India's Ministry of Electronics and IT.

AWS Certified Solutions Architect Associate

SAA-C03. Validates expertise in designing distributed systems and architectures on AWS.

Projects & Contributions

aws-ar

Open-source CLI tool on PyPI that simplifies chaining AWS AssumeRole credentials across multi-account environments for secure, scalable access management.

PythonAWSIAMPyPI
Tool

Bucket-Explorer

Web-based GUI for discovering and exploring cloud storage buckets. Supports file preview, metadata inspection, and controlled downloads during security assessments.

WebCloud StorageS3Security

Technical Skills

Cloud Platforms

AWSAzureGCP

Cloud Security

CSPMCNAPPCWPPKSPMSSPMCIEMAttack Path AnalysisThreat Modeling

AI + Cloud

LLM SecuritySageMakerVertex AIBedrockAI Threat DetectionML Pipeline Security

Compliance

CISNISTISO 27001HIPAAGDPR

DevOps & Automation

GitHub ActionsJenkinsDockerKubernetesEKSAKSGKETerraformCloudFormation

Security Tools

nmapWiresharkBurp SuiteSQLMapOWASP ZAPScoutSuitePacuProwlerNucleicloud_enum

Writing & Media

Latest Videos

Giving Back

Winja CTF / NullCon Community

Supported global CTF events for the security community and collaborated with organizers to deliver large-scale cybersecurity events.

SABAL NGO

Supported social initiatives through technical coordination and digital enablement. Mentored interns and coordinated community awareness campaigns.

Clients & Associations

Let's Secure Your Cloud.

Need a security assessment, compliance review, or hands-on cloud engineering? I'm open to consulting engagements.

shashank@cloud-sec ~ %
visitor@shashank ~ $