Cloud Security & DevSecOps Consultant/Ernst & Young (EY)/Pune District, Maharashtra, India

Sankalp Sandeep Paranjpe

Cloud Security & DevSecOps Consultant

I help engineering teams design secure cloud architecture, harden infrastructure, and build security into how they ship software.

Sankalp Sandeep Paranjpe

Tech stack

Tools I work with

AWS

Cloud

Wiz

Security

Terraform

Infrastructure as code

GCP

Cloud

GitHub Actions

CI/CD

CircleCI

CI/CD

AWS DevOps

CI/CD

Python

Automation

Docker

Containers

Kubernetes

Containers

GRC

Governance

ISO 27001

Compliance

Experience

Where I have worked

Ernst & Young (EY)· Jan 2026 — Present

Consultant, Cloud Security and DevSecOps Engineering.

  • Advising engineering teams on secure cloud architecture, hardening infrastructure, and embedding security into how teams ship software.
  • Using Wiz for cloud security posture management and vulnerability scanning across cloud environments.
  • Developing reusable Terraform modules so engineering teams can provision infrastructure securely by default.
Intangles· Jun 2024 — Dec 2025

DevSecOps Engineer.

  • Performed cloud infrastructure security assessments and configuration reviews across multiple AWS accounts.
  • Enforced IAM/RBAC/SCP Policies for AWS Infrastructure. Achieved 96% compliance with CIS Benchmarks v3.0.0, effectively remediating the findings and applying stringent security controls for secure, scalable, highly available, fault tolerant systems.
  • Supported risk reduction efforts by implementing continuous threat monitoring using AWS GuardDuty, AWS Inspector, Security Hub CSPM, Config and remediating high-severity CVEs.
  • Designed, deployed, and secured Kubernetes clusters (EKS), implementing container security best practices, RBAC, and vulnerability scanning for container images.
  • Implemented secure CI/CD pipelines using CircleCI, GitHub Actions, and SonarQube for SAST, tfsec for IaC scanning; ensuring secure code deployments and automated vulnerability scanning. Collaborated with Site Reliability, IAM, and Networking teams to implement secure cloud infrastructure design, Zero Trust principles, and risk mitigation strategies.
  • Acted as the primary point of contact for customer-led Third-Party Risk Management (TPRM) assessments, addressing security questionnaires, pentest reviews, and product/cloud security inquiries.
Intangles· Apr 2024 — May 2024

Site Reliability Engineer Intern.

  • Managed multiple AWS accounts via AWS Organizations, reviewed cloud architecture against the AWS Well-Architected Framework and presented recommendations to stakeholders, and assisted with automation, monitoring, and reliability improvements.

Focus areas

What I work on

Security across the delivery lifecycle, from design to detection.

  1. 1Design

    Cloud Security Architecture

    AWS Organizations, SCPs, least-privilege IAM, and secure multi-account setups.

  2. 2Build

    DevSecOps & CI/CD

    Secure CI/CD pipelines with GitHub Actions and CircleCI, including SAST, dependency and license scanning, and role-based deployments.

  3. 3Deploy

    Infrastructure as Code

    Terraform with security checks, such as tfsec, in the pipeline.

  4. 4Run

    Containers & Kubernetes

    Docker and EKS security: image scanning, RBAC, and access control for cluster tools.

  5. 5Detect & Respond

    Detection & Response

    Threat detection and monitoring with GuardDuty, Security Hub, Inspector, CloudTrail, and Config.

Across all stages

Cloud Engineering & Automation

Python automation, AWS DevOps tools, monitoring, and Well-Architected reviews.

Contact

Let's work together

0%

Loading Sankalp Sandeep Paranjpe's portfolio