CISO & DPO leading AI security, AI governance, privacy, and compliance at Locus — part of the Ingka Group (IKEA) — a cloud-native logistics AI platform powering 1.5B+ deliveries across 30+ jurisdictions.
A decade across AI SaaS, healthcare, logistics, edtech, robotics, and defense — building security programs from the ground up, leading crisis response, and translating AI risk into revenue and regulatory posture.
Recognized CISO of the Year (2022 and 2023). Doctorate in AI and Cybersecurity.
Function CISO + DPO (unified AI security + privacy)
Scale 30+ jurisdictions · 1.5B+ deliveries · cloud-native logistics AI
Frameworks NIST AI RMF · ISO/IEC 42001 · EU AI Act · SOC 2 · GDPR · DPDPA
Team / Budget Lean team of 5 · ~$1M annual
Outcomes 70,000+ vulnerabilities remediated · SOC 2 Type II delivered
96% reduction in late-stage vulnerabilities
AI governance stood up aligned to NIST AI RMF + ISO 42001
Controls stack: LLM guardrails (input/output) · prompt-injection defense · PII redaction before inference · model inventory with version pinning · AI-assisted SAST/SCA/secrets on AI-generated code · indirect-injection filters on RAG sources · phishing-resistant IAM (FIDO2) · CASB · multi-channel DLP · Zero Trust substrate.
| Role | Organization | Scope | Signature Outcome |
|---|---|---|---|
| CISO & DPO | Locus · Ingka / IKEA | 30+ jurisdictions · 1.5B+ deliveries | AI governance program · SOC 2 Type II · 96% fewer late-stage vulns |
| CISO | Teachmint | 35M+ student records · 33 countries · 600+ schools | First AI-enabled connected classroom secured · GDPR / COPPA / DPDPA |
| CISO | Byju's Great Learning | 100+ countries · 2K+ employees · 5K+ teachers | Company-wide Zero Trust · ISO certifications unlocked 50+ B2B deals |
| CISO | Meditab | 5,000+ person org in active crisis | IR + 24×7 SOC built from zero · HITRUST i1 · SOC 2 II · ISO 27001/27701 |
| Security Architecture | TCS | EKA supercomputer (Chandrayaan 2, Mangalyaan) | 200K+ EPS SOC · modernization across 1,000+ offices |
Built in the open. Community-driven. Zero enterprise licensing.
|
Autonomous AI pentester White-box, source-code-aware security testing for web applications and APIs. Plans, executes, and reports across OWASP Top 10 for LLMs — prompt injection chains, jailbreaks, indirect injection via RAG, data-extraction probes — plus the full web/API surface.
|
SAST / SCA false-positive reduction Five-layer AI triage pipeline that eliminates the noise that kills AppSec programs. Open-source. Transparent rulings. Audit-friendly. In development |
Safe outbound automation Human-mimicry by design. Always safe-mode. Full jitter. Never 24/7. Built on the principle that the account is load-bearing. In development |
Public pull requests to repositories I don't own — auto-refreshed daily.
21 merged · 17 in review · 11 closed across 31 external project(s).
- projectdiscovery/nuclei-templates (12.8K ⭐) — Community curated list of templates for the nuclei engine to find security vulnerabilities.
✅ 6 merged · ⚪ 3 closed · merged diff +154 / −66 - Tencent/AI-Infra-Guard (4.5K ⭐) — A full-stack AI Red Teaming platform securing AI ecosystems via OpenClaw Security Scan, Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.
✅ 2 merged · 🟡 1 in review · merged diff +651 / −0 - msoedov/agentic_security (2.0K ⭐) — Agentic LLM Vulnerability Scanner / AI red teaming kit 🧪
✅ 2 merged · merged diff +720 / −7 - GRCEngClub/claude-grc-engineering (372 ⭐) — Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.
✅ 2 merged · ⚪ 1 closed · merged diff +1,698 / −7 - ReversecLabs/spikee (231 ⭐) — Simple Prompt Injection Kit for Evaluation and Exploitation
✅ 2 merged · 🟡 1 in review · merged diff +199 / −2 - redcanaryco/atomic-red-team (12.4K ⭐) — Small and highly portable detection tests based on MITRE's ATT&CK.
✅ 1 merged · 🟡 1 in review · merged diff +111 / −0 - NVIDIA/garak (8.8K ⭐) — the LLM vulnerability scanner
✅ 1 merged · ⚪ 1 closed · merged diff +107 / −0 - intelowlproject/IntelOwl (4.7K ⭐) — IntelOwl: manage your Threat Intelligence at scale
✅ 1 merged · merged diff +376 / −0 - vulnerability-lookup/vulnerability-lookup (562 ⭐) — Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD).
✅ 1 merged · merged diff +50 / −0 - sublime-security/sublime-rules (369 ⭐) — Sublime rules for email attack detection, prevention, and threat hunting.
✅ 1 merged · merged diff +1 / −1 - Yamato-Security/hayabusa-rules (222 ⭐) — Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.
✅ 1 merged · merged diff +407 / −0 - kubescape/regolibrary (131 ⭐) — The regolibrary package contains the controls Kubescape uses for detecting misconfigurations in Kubernetes manifests.
✅ 1 merged · merged diff +96 / −3 - KeygraphHQ/shannon (46.8K ⭐) — Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
🟡 1 in review - projectdiscovery/nuclei (30.5K ⭐) — Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
🟡 1 in review - gitleaks/gitleaks (28.7K ⭐) — Find secrets with Gitleaks 🔑
🟡 2 in review - blacklanternsecurity/bbot (10.4K ⭐) — The recursive internet scanner for hackers. 🧡
🟡 1 in review - PyCQA/bandit (8.2K ⭐) — Bandit is a tool designed to find common security issues in Python code.
🟡 1 in review - Pennyw0rth/NetExec (5.8K ⭐) — The Network Execution Tool
⚪ 1 closed - ossf/scorecard (5.6K ⭐) — OpenSSF Scorecard - Security health metrics for Open Source
⚪ 1 closed - RhinoSecurityLabs/pacu (5.3K ⭐) — The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
🟡 1 in review - confident-ai/deepteam (2.4K ⭐) — DeepTeam is a framework to red team LLMs and AI agents.
🟡 1 in review - DataDog/stratus-red-team (2.4K ⭐) — ☁️ ⚡ Granular, Actionable Adversary Emulation for the Cloud
⚪ 1 closed - stacklok/toolhive (2.0K ⭐) — ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.
⚪ 1 closed - utkusen/promptmap (1.2K ⭐) — a security scanner for custom LLM applications
🟡 1 in review - safedep/vet (1.1K ⭐) — Protect against malicious open source packages 🤖
⚪ 1 closed - trailofbits/fickling (662 ⭐) — A Python pickling decompiler and static analyzer
⚪ 1 closed - ossf/malicious-packages (597 ⭐) — A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
🟡 1 in review - trailofbits/semgrep-rules (515 ⭐) — Semgrep queries developed by Trail of Bits.
🟡 1 in review - sigstore/model-transparency (244 ⭐) — Supply chain security for ML
🟡 1 in review - t0sche/cvss-bt (226 ⭐) — Enriching the NVD CVSS scores to include Temporal & Threat Metrics
🟡 1 in review - falcosecurity/rules (184 ⭐) — Falco rule repository
🟡 1 in review
All pull requests
| Repository | ⭐ | Pull Request | Diff | Status |
|---|---|---|---|---|
| projectdiscovery/nuclei-templates | 12.8K | #16053 fix(tomcat-default-login): order payloads to dodge LockOutRealm (FN) | +51 / −55 | ✅ Merged |
| projectdiscovery/nuclei-templates | 12.8K | #16055 add: LiteLLM proxy unauthenticated /model/info exposure | +51 / −0 | ✅ Merged |
| projectdiscovery/nuclei-templates | 12.8K | #16385 dns: add internal IP address disclosure in DNS A records | +42 / −0 | ✅ Merged |
| projectdiscovery/nuclei-templates | 12.8K | #16056 add: ChromaDB unauthenticated collections API exposure | +9 / −3 | ✅ Merged |
| projectdiscovery/nuclei-templates | 12.8K | #16050 fix: drop clear-site-data matcher from http-missing-security-header… | +0 / −7 | ✅ Merged |
| projectdiscovery/nuclei-templates | 12.8K | #16052 fix(CVE-2021-40438): support custom interactsh server hostnames (FN) | +1 / −1 | ✅ Merged |
| redcanaryco/atomic-red-team | 12.4K | #3370 Add T1567.004 - Exfiltration Over Webhook (Discord/Slack/Teams) | +111 / −0 | ✅ Merged |
| NVIDIA/garak | 8.8K | #1859 fix: catch OpenAI AuthenticationError before multiprocessing pickle | +107 / −0 | ✅ Merged |
| intelowlproject/IntelOwl | 4.7K | #3802 Add CVE_Exploitability analyzer (CISA KEV + FIRST EPSS) for CVE obs… | +376 / −0 | ✅ Merged |
| Tencent/AI-Infra-Guard | 4.5K | #427 feat(eval): add agentic-tool-misuse evaluation dataset | +384 / −0 | ✅ Merged |
| Tencent/AI-Infra-Guard | 4.5K | #424 feat(data): add 6 llama.cpp CVE rules (RPC RCE + GGUF/tokenizer mem… | +267 / −0 | ✅ Merged |
| msoedov/agentic_security | 2.0K | #321 feat: config-pluggable refusal classifiers and leak detectors | +491 / −4 | ✅ Merged |
| msoedov/agentic_security | 2.0K | #320 fix: wildcard CORS + credentials spec violation, path-traversal gua… | +229 / −3 | ✅ Merged |
| vulnerability-lookup/vulnerability-lookup | 562 | #431 new: [perf] add pg_trgm GIN indexes for sighting source/vulnerabili… | +50 / −0 | ✅ Merged |
| GRCEngClub/claude-grc-engineering | 372 | #72 feat(frameworks): Reference-depth India DPDPA plugin (ind-dpdpa) | +1,425 / −0 | ✅ Merged |
| GRCEngClub/claude-grc-engineering | 372 | #71 ci(plugins): validate manifests against JSON Schema on every PR | +273 / −7 | ✅ Merged |
| sublime-security/sublime-rules | 369 | #4655 fix: replace deprecated $alexa_1m with $tranco_1m in link_cuttly di… | +1 / −1 | ✅ Merged |
| ReversecLabs/spikee | 231 | #109 feat: add homoglyph encoding plugin (Unicode confusables) | +197 / −0 | ✅ Merged |
| ReversecLabs/spikee | 231 | #111 docs: fix GOAT citation and note workspace-only status in 02_builti… | +2 / −2 | ✅ Merged |
| Yamato-Security/hayabusa-rules | 222 | #1036 ci: block merge when a rule id (UUID) is used by more than one rule… | +407 / −0 | ✅ Merged |
| kubescape/regolibrary | 131 | #753 feat(C-0021): cover AI/ML inference and MLOps interfaces in sensiti… | +96 / −3 | ✅ Merged |
| KeygraphHQ/shannon | 46.8K | #322 Security hardening, CLI bug fixes, and SARIF report output | +1,677 / −40 | 🟡 In review |
| projectdiscovery/nuclei | 30.5K | #7495 feat(reporting): add CSV result exporter (-csv-export) | +294 / −0 | 🟡 In review |
| gitleaks/gitleaks | 28.7K | #2177 feat(rules): add Pinecone and LangSmith API key detection rules | +89 / −0 | 🟡 In review |
| gitleaks/gitleaks | 28.7K | #2178 feat(rules): add Anthropic OAuth refresh token rule (sk-ant-ort01-) | +36 / −0 | 🟡 In review |
| redcanaryco/atomic-red-team | 12.4K | #3359 Add T1213.005 - Data from Information Repositories: Messaging Appli… | +187 / −0 | 🟡 In review |
| blacklanternsecurity/bbot | 10.4K | #3235 excavate: add AIApplicationExtractor for LLM endpoints, SDKs, and l… | +202 / −0 | 🟡 In review |
| PyCQA/bandit | 8.2K | #1441 fix(B614): suppress false positive on non-literal weights_only; add… | +44 / −0 | 🟡 In review |
| RhinoSecurityLabs/pacu | 5.3K | #534 fix(sns__enum): paginate list_topics and list_subscriptions_by_topi… | +247 / −7 | 🟡 In review |
| Tencent/AI-Infra-Guard | 4.5K | #429 feat(agent-scan): add memory/RAG poisoning detection skill | +177 / −0 | 🟡 In review |
| confident-ai/deepteam | 2.4K | #236 feat(attacks): add Caesar, Morse, hex, zero-width & homoglyph encod… | +859 / −1 | 🟡 In review |
| utkusen/promptmap | 1.2K | #10 feat(rules): add indirect_injection category (12 rules) | +240 / −3 | 🟡 In review |
| ossf/malicious-packages | 597 | #1329 docs: add a consumer guide for using the reports | +235 / −0 | 🟡 In review |
| trailofbits/semgrep-rules | 515 | #83 python: add hf-trust-remote-code rule (HuggingFace trust_remote_cod… | +103 / −0 | 🟡 In review |
| sigstore/model-transparency | 244 | #642 feat: Add in-memory signing API returning the Sigstore bundle as bytes | +130 / −4 | 🟡 In review |
| ReversecLabs/spikee | 231 | #110 feat(judges): add secret_leak judge for credential/PII exfiltration… | +324 / −0 | 🟡 In review |
| t0sche/cvss-bt | 226 | #46 feat: add exploit_maturity_source column for auditable E-value prov… | +158 / −1 | 🟡 In review |
| falcosecurity/rules | 184 | #373 new(rules): detect GPU/accelerator cryptojacking and device access … | +81 / −0 | 🟡 In review |
| projectdiscovery/nuclei-templates | 12.8K | #16054 add: Langflow unauthenticated flow API exposure detection | +80 / −0 | ⚪ Closed |
| projectdiscovery/nuclei-templates | 12.8K | #16386 add: Qdrant vector database - unauthenticated collections exposure | +48 / −0 | ⚪ Closed |
| projectdiscovery/nuclei-templates | 12.8K | #16051 fix(CVE-2025-58360): switch GeoServer XXE detection to OAST (FN on … | +15 / −8 | ⚪ Closed |
| NVIDIA/garak | 8.8K | #1858 probes: add many-shot jailbreaking probe | +195 / −0 | ⚪ Closed |
| Pennyw0rth/NetExec | 5.8K | #1289 fix(mssql): print a clean error for --rid-brute without authentication | +3 / −0 | ⚪ Closed |
| ossf/scorecard | 5.6K | #5103 checks/sast: detect Semgrep, Bandit, and gosec SAST workflows | +162 / −0 | ⚪ Closed |
| DataDog/stratus-red-team | 2.4K | #886 Add MITRE ATLAS as a first-class framework mapping (Cost Harvesting… | +27 / −1 | ⚪ Closed |
| stacklok/toolhive | 2.0K | #5588 Add CORS support to the transparent MCP proxy | +665 / −4 | ⚪ Closed |
| safedep/vet | 1.1K | #745 feat: add pre-commit hook for local dependency scanning (closes #443) | +116 / −0 | ⚪ Closed |
| trailofbits/fickling | 662 | #283 Add recursive directory and glob scanning to the CLI for bulk pickl… | +330 / −1 | ⚪ Closed |
| GRCEngClub/claude-grc-engineering | 372 | #70 fix(plugins): use object form for plugin.json author field | +7 / −7 | ⚪ Closed |
AI & LLM Security — MLSecOps · Prompt injection defense · AI red teaming · Model supply chain · OWASP Top 10 for LLMs · RAG security · Agentic controls · Inference-time abuse monitoring
AI Governance — NIST AI RMF · ISO/IEC 42001 · EU AI Act high-risk categorization · AI DPIA · AI TPRM · Responsible AI · Human-in-the-loop design
Privacy & Compliance — GDPR · DPDPA · COPPA · HIPAA · HITRUST i1 · SOC 2 Type II · ISO 27001 · ISO 27701
Security Programs — Zero Trust architecture · Phishing-resistant IAM (FIDO2) · DevSecOps · AppSec automation · Incident response · Crisis leadership · Bug bounty & red teaming
Boardroom — Risk translation · Regulatory strategy · B2B revenue unlock via certifications · AI risk appetite framing
- CISO of the Year — 2022 and 2023
- Doctorate — AI and Cybersecurity (ISTM)
- Postgraduate — Symbiosis Centre for Information Technology
- Board advisor · fractional CISO · keynote speaker on AI security strategy and AI governance program design
Advisory · AI governance program design · AI compliance readiness (NIST AI RMF · ISO 42001 · EU AI Act) · board briefings
devamshah.github.io · LinkedIn · devamshah91@gmail.com
Security programs built to ship — transparent, open-source, board-defensible.

