Mohit Kumar

Security Engineer · AI for Security & Security for AI

5 open-source scanners · 1,350+ passing tests · 47 real escalation paths found · 13 blog posts · 5 research papers.

Security Engineer at ITC Infotech working across AI for Security and Security for AI — building an open-source defensive tooling suite, hardening ML & agent supply chains, and running SOC/VAPT and GRC (J-SOX/MICS) audits. Deep ML background in adversarial robustness, multi-agent systems, and detection engineering.

I’m a Security Engineer at ITC Infotech, blending deep AI/ML expertise with security operations. I work in two directions at once — AI for Security (autonomous detection tooling and SOC-grade anomaly detection) and Security for AI (protecting models, agents, and software supply chains from attack) — alongside GRC control auditing (J-SOX, MICS). During my internship I built a production multi-agentic email threat-neutralization system; today I maintain an open-source security tooling suite spanning the modern software supply chain, and run VAPT and detection engineering (Microsoft Sentinel, Splunk). Before pivoting to security I built production ML systems — Legal AI (HybEx-Law, 98.5% F1), multi-agent research platforms, and computer vision (98.99% mAP). I believe the future of security is AI-native — and the future of AI must be secure.

Featured Projects

  • Bastion: Kubernetes RBAC & Attack-Path Analyzer — Reads your Kubernetes manifests and tells you who can become cluster-admin, and how — treating privilege escalation as the graph problem it actually is.
  • Bulwark: The Security Stack for Agentic AI — Three composable scanners that audit the entire AI-agent supply chain — the parts, the assembly, and the governable whole.
  • Lattice: Post-Quantum Cryptography Readiness Scanner — Statically inventories every cryptographic asset in a codebase, grades each for quantum and classical weakness, and emits a prioritized migration roadmap to the NIST post-quantum standards.
  • Portcullis: CI/CD Pipeline Security Scanner — Statically analyzes GitHub Actions, GitLab CI, and Jenkins pipelines through one normalized model — and scores every finding by whether attacker-controlled input can actually reach it.
  • Stowaway: Offline Supply-Chain Integrity Scanner — Catches the supply-chain attacks that have no CVE — typosquatting, dependency confusion, install-time malware, and lockfile tampering — across npm, PyPI, Go, and Cargo, fully offline.
  • Schema-Grounded NL→KQL: An Intermediate Representation for SIEM Rule Generation — An explicit, schema-validated intermediate representation between natural language and KQL that cuts field hallucination in LLM-generated Microsoft Sentinel detection rules from 93% to 13%.

All projects · Experience · Blog · Resume