About
Sankalp Sandeep Paranjpe
Cloud Security & DevSecOps Consultant
I help engineering teams design secure cloud architecture, harden infrastructure, and build security into how they ship software.
Sankalp is a Cloud Security & DevSecOps Consultant at Ernst & Young (EY). He helps engineering teams design secure cloud architecture, harden infrastructure, and add security to their CI/CD pipelines, covering IAM design, CIS Benchmark compliance, threat detection, and incident response.
He is an AWS Community Builder (Security), leads the AWS User Group Pune, and was an AWS Cloud Captain. He writes and speaks about secure CI/CD, Kubernetes security, and infrastructure as code.
He is also learning AI/ML security on AWS, including the OWASP Top 10 for MCP.
Experience
Jan 2026 — Present
Consultant, Cloud Security and DevSecOps Engineering · Ernst & Young (EY)
- Advising engineering teams on secure cloud architecture, hardening infrastructure, and embedding security into how teams ship software.
- Using Wiz for cloud security posture management and vulnerability scanning across cloud environments.
- Developing reusable Terraform modules so engineering teams can provision infrastructure securely by default.
Jun 2024 — Dec 2025
DevSecOps Engineer · Intangles
- Performed cloud infrastructure security assessments and configuration reviews across multiple AWS accounts.
- Enforced IAM/RBAC/SCP Policies for AWS Infrastructure. Achieved 96% compliance with CIS Benchmarks v3.0.0, effectively remediating the findings and applying stringent security controls for secure, scalable, highly available, fault tolerant systems.
- Supported risk reduction efforts by implementing continuous threat monitoring using AWS GuardDuty, AWS Inspector, Security Hub CSPM, Config and remediating high-severity CVEs.
- Designed, deployed, and secured Kubernetes clusters (EKS), implementing container security best practices, RBAC, and vulnerability scanning for container images.
- Implemented secure CI/CD pipelines using CircleCI, GitHub Actions, and SonarQube for SAST, tfsec for IaC scanning; ensuring secure code deployments and automated vulnerability scanning. Collaborated with Site Reliability, IAM, and Networking teams to implement secure cloud infrastructure design, Zero Trust principles, and risk mitigation strategies.
- Acted as the primary point of contact for customer-led Third-Party Risk Management (TPRM) assessments, addressing security questionnaires, pentest reviews, and product/cloud security inquiries.
Apr 2024 — May 2024
Site Reliability Engineer Intern · Intangles
- Managed multiple AWS accounts via AWS Organizations, reviewed cloud architecture against the AWS Well-Architected Framework and presented recommendations to stakeholders, and assisted with automation, monitoring, and reliability improvements.
Tech stack
AWS
Cloud
Wiz
Security
Terraform
Infrastructure as code
GCP
Cloud
GitHub Actions
CI/CD
CircleCI
CI/CD
AWS DevOps
CI/CD
Python
Automation
Docker
Containers
Kubernetes
Containers
GRC
Governance
ISO 27001
Compliance
Credentials

AWS Certified Solutions Architect — Associate
Amazon Web Services (AWS)

AWS Certified SysOps Administrator — Associate
Amazon Web Services (AWS)

AWS Certified Cloud Practitioner
Amazon Web Services (AWS)
- CERT
AWS Academy Graduate — AWS Academy Cloud Foundations
Amazon Web Services (AWS)
- CERT
EY Cybersecurity — Bronze Learning
EY · 2026
- CERT
Operations with AWS — Level 2
Amazon Web Services (AWS)
Education
- 2020
Joy Senior Secondary School
Class 12th, Science Stream
Jabalpur, Madhya Pradesh, India
- 2024
MIT ADT University
B.Tech, Computer Science · Networks and Security
CGPA 8.89/10 · Pune, Maharashtra