Yogesh S. Thanvi#
Cloud Security & DevSecOps | Securing Internet-Scale Infrastructure#
For more than fifteen years I have helped keep internet-scale infrastructure reliable, secure, and continuously compliant, the kind of infrastructure that serves a substantial share of global web traffic and that millions of people and businesses depend on every day. My work spans DNS and global traffic management, Kubernetes and cloud-native platform security, and DevSecOps governance, and I codify that practice into peer-reviewed research and into the standards my profession is measured against.
My focus today: engineering trust into modern systems, so that compliance is a property systems prove continuously, not a periodic activity they survive.
About · Research · Speaking · Leadership & Service · Recognition · Writing · Contact
Selected Achievements#
- Fifteen-plus years securing internet-scale cloud and edge infrastructure
- Author of eleven peer-reviewed papers (seven published in IEEE Xplore, four accepted), including sole-authored research
- Reviewer of more than thirty papers for international cybersecurity and AI conferences
- Named expert reviewer of the ISACA IT Audit Framework (ITAF), 5th Edition
- Member of ISACA’s IT Audit and Assurance Advisory Group and Emerging Trends Working Group
- Judge for the ISACA Foundation global scholarship program and ISACA Global Achievement Awards
- Invited speaker and panelist at ISACA and IEEE conferences
- ISACA Engage Forum Topic Leader, recognized publicly by ISACA
By the Numbers#
- 15+ years in cloud security and internet infrastructure
- 11 peer-reviewed papers (7 published, 4 accepted)
- 30+ conference paper reviews completed
- 3 invited conference talks and panels
- CISA & CDPSE certified; 12+ years ISACA membership at Gold level
Available For#
- Conference speaking and panels
- Research collaboration
- Peer review and technical program committees
- Cybersecurity and cloud-governance advisory
- Professional mentorship
Get in touch
Cloud security. DevSecOps governance. Continuous compliance. Cloud governance. Platform security. Zero Trust. DNS security. AI security governance.
Cloud Security & DevSecOps engineer securing internet-scale distributed infrastructure. Fifteen-plus years in cloud and edge security, DNS and global traffic management, Kubernetes platform security, and DevSecOps governance, paired with peer-reviewed research and active leadership in the global cybersecurity profession through ISACA.
Detecting insecure pods on Azure Kubernetes Service is not the same as preventing them. Here is how Azure Policy and OPA Gatekeeper move enforcement to admission time, so a misconfigured workload never reaches the cluster.
An audit framework tells you what to assure. It does not tell you how to enforce it in a live cloud. Here is how I map the IT Audit Framework onto concrete Azure controls, Azure Policy, Defender for Cloud, and Purview, so assurance objectives become running enforcement instead of a spreadsheet.
Defender for Cloud is excellent at telling you what is misconfigured. A finding is not a fix. Here is how I turn cloud security posture management on Azure from a dashboard of alerts into enforcement that blocks and remediates, using Azure Policy deny effects and admission-time control on AKS.
An AI agent that can call tools and take actions is not a chatbot. It is a new identity and a new attack surface. Here are the guardrails I would put around agentic workloads on Azure OpenAI and AI Foundry, built from the same principle I apply everywhere: enforce at the point every request passes through.
Generative AI on Azure introduces control points that traditional application security never had to handle. Here are practical governance patterns for Azure OpenAI and AI Foundry workloads, mapped to where the real risks live.
Most AI security programs pass the pilot and break in production. The reason is structural, not a tooling gap. Here are the seven failure modes scale exposes, and why governance, not more tools, is the fix.
Frameworks tell you what outcomes to achieve. They do not tell you how to instrument your system to produce them. That gap, between risk models and real enforcement, is where most AI governance programs are stuck.
Testing samples an AI system’s behavior at one moment. Trust requires governing that behavior continuously. Here is the trust triad, governance, validation, and monitoring, and why conflating the three is the mistake that breaks at scale.
Every production incident is a lesson the system has already paid for. Most teams capture that lesson in a postmortem document and then reintroduce the same failure months later. Here is how to convert incidents into automated controls that make a failure mode impossible to repeat.
Most Cloud Security Posture Management tools detect misconfigurations and stop there. Detection without enforcement leaves the exposure in place. Here is what changes when policy-as-code blocks and remediates at admission time.