Sandeep Rao

AI Infrastructure & Data Center Engineering — Building Sovereign & Private Cloud
Security Engineering & SMB Advisory — Product, Infrastructure, Compliance & Certification
Agentic Engineering — Orchestrating Claude, Cursor & Codex to Ship at Team Velocity, Solo

20+ years of experience spanning networking, security architecture, and cloud, now focused on building private and sovereign AI cloud infrastructure for enterprises. I advise on security architecture, controls review, and hardening — helping enterprises become audit-ready and compliant (ISO, SOC, RBI).

Currently

What I'm doing right now

Building

AI Sovereign Cloud — a sovereign, multi-tenant cloud + governed AI platform, architected and largely built through agentic engineering.

Advising

Startups and SMBs on AI-driven security architecture, cloud automation, and SOC/compliance readiness — most recently led a FinTech and Property Tech company's ISO 27001 & SOC 2 programme from zero.

Flagship platform

AI Sovereign Cloud

A sovereign, multi-tenant cloud deployed on-premises, extended into a governed on-prem AI platform. Owned end-to-end: architecture, implementation across six services, and security.

AI Infra Architect

AI Sovereign Cloud Platform
2024 — Present
Kubernetes Cilium Rook-Ceph KubeVirt / CDI Keycloak OpenBao Prometheus Chaos Mesh LiteLLM Ollama / vLLM Go Python React / TypeScript MongoDB Redis Claude Cursor Codex
6
Coordinated services
100%
AI requests audited
2-tier
Control / data-plane
  • Building a multi-tenant sovereign-cloud platform — a "private mini-AWS" deployed on-premises — targeting enterprises, then extended it into a governed on-prem AI platform. Owned the work end-to-end: product strategy, system architecture, hands-on implementation across six services, and security — much of it built solo through agentic, AI-assisted engineering.
  • Six coordinated services on a cloud-native stack — Go/OpenAPI REST API, React self-service UI, Python orchestration observer, Go state reconciler, CRD-based DNS controller, Ansible/Bash installer, and a GPU-as-a-Service supply plane — on Cilium, Rook-Ceph, KubeVirt/CDI, Keycloak, OpenBao, MongoDB, Prometheus.
  • Agentic engineering — built largely solo using Claude, Cursor, and Codex as coding agents, orchestrating them across parallel git worktrees and nine repositories under a content-verified review discipline, operating at the throughput of an engineering team while owning every architectural decision.
  • Governed AI Gateway — one multi-provider AI-compatible endpoint (tested against Anthropic and others) that classifies every prompt by sensitivity and routes confidential/PII to an on-prem sovereign GPU model and public traffic to governed frontier egress — metering every token per request and auditing 100% of requests. Fail-safe classifier routes anything it can't confidently read to sovereign rather than leaking it externally.
  • Full operator surface — a tenant Playground, a live Governance dashboard (per-tier spend, token metering, audit log, fail-safe rate), and a Routing-Policy taxonomy editor — plus an integration path exposing the gateway through messaging channels like Slack.
  • Custom dashboard framework — a widget-registry system for composable, drag/resize/configurable panels and a "focus card" visual language for live KPI, spend, and health metrics — replacing static Grafana iframes with an in-house, responsive, theme-aware UI powering every metering, capacity, and governance surface (AI Gateway, Fleet, GPU, billing) from one design system.
  • Custom dashboard framework — a widget-registry system for composable, drag/resize/configurable panels and a "focus card" visual language for live KPI, spend, and health metrics — replacing static Grafana iframes with an in-house, responsive, theme-aware UI powering every metering, capacity, and governance surface (AI Gateway, Fleet, GPU, billing) from one design system.
  • Tokenized billing, metering, and invoicing — rate cards, per-project/OU attribution, automated invoice generation with PDF output — and an on-prem "AI Foundry" product line, extending the platform from infrastructure into a monetizable product surface.
  • Fleet operations console — provider-wide, cross-tenant view unifying every VM, pod, and load balancer with live CPU/memory usage against reservation, Ceph/Rook storage-durability health flagging at-risk single-replica data, and a navigable workload⇄node⇄storage graph.
  • AWS-EBS-style managed disks — create, attach live, detach without data loss, re-attach — with an atomic Mongo-gated attachment path preventing concurrent-attach corruption, plus managed databases (CNPG Postgres, Percona MongoDB with real HA anti-affinity) and live VM elasticity via KubeVirt hotplug.
  • GPU-as-a-Service supply plane — brokering real NVIDIA GPUs from a partner cloud, per-second metered rentals, detached GPU jobs, three consumption modes.
  • Security hardening — authorized penetration test, threat model, hardening matrix, and a Chaos Mesh chaos-engineering practice across the fleet.
Flagship programme

Security and Compliance

Led the company's first ISO/IEC 27001:2022 and SOC 2 Type 2 certification programme end-to-end — from zero formal ISMS to a governance-ready documentation set, ahead of the external consultancy kickoff.

InfoSec & Cybersecurity Lead

FinTech and Property Tech
2026
45
Controlled documents
93
Annex A controls scoped
0→54/85
Audit-ready evidence items
30
Scored risks
Security Engineering Capabilities
  • Full-stack security architecture — spanning application and API security development, distributed systems, security orchestration, and threat analysis and investigation.
  • Framework-aligned — threat-defense architecture built against NIST, CSA, CIS Top 20, and PCI-DSS.
  • Secure architecture assessment — design and architecture review, code analysis, API gateway security audits (Kong, Nginx), microservice security, and API discovery and inventory.
  • Cloud security — across GCP, AWS, and on-prem, using Security Command Center and org policies for vulnerability assessment, observability, and automation.
  • Perimeter infrastructure security — DDoS protection, firewall and IDS management, application security incident response, and API abuse/fraud detection and prevention.
  • XDR — endpoint detection and protection, vulnerability assessment, and malware response.
  • API security — discovery, call tracing, anti-abuse detection, and documentation.
  • Incident response — log ingestion pipelines, threat modeling, and alerting built on open-source SIEM.
Compliance Documents Produced
ISMS coreScope Statement, Information Security Policy, Roles & Responsibilities, Risk Management Policy & Methodology, Risk Treatment Plan, Objectives, Control of Documented Information, Internal Audit Programme, Management Review, Nonconformity & Corrective Action — clauses 4–10 in full.
RegistersRisk Register (30 scored risks), Statement of Applicability (all 93 Annex A:2022 controls), ISO 27001↔SOC 2 Control Matrix, Policy Register, Legal & Regulatory Register, Findings Remediation Tracker (25 findings).
GovernanceSteering Committee Terms of Reference, Agenda & Minutes with a batch-approval Annex satisfying clause 7.5.2.
SOC 2Trust Services Categories Selection Memo, System Description (Section III).
Control policies (17)Access Control, Cryptography & Key Management, Information Classification, Data Retention & Deletion, Data Protection & Privacy, Incident Management, Supplier & Third-Party Security, Secure SDLC, Change Management, Logging & Monitoring, Vulnerability & Patch Management, Backup & Recovery, Malware Protection, Endpoint Security, Network Security, BC/DR, Physical & Environmental Security.
PeopleHR Security, Acceptable Use, Remote Working, Security Awareness & Training.
Judgment calls worth knowing about
Aligning documents with timelines
A SOC 2 observation window is forward-looking, so back-dating buys nothing — and it's trivially detectable via Office docProps timestamps, SharePoint history, and Entra sign-in logs. Everything ships current-dated.
Escalated a live P0 above the documentation programme
Critical and High pen-test findings remained open beyond SLA, unremediated across two assessment rounds. Flagged this as outranking every documentation gap — a major nonconformity against A.8.8, and worse for SOC 2 than never having tested at all.
Designed batch approval to survive audit
45 documents approved in one sitting, but each listed by title, version and approver in an annex — because the top-level Information Security Policy is the document an auditor examines hardest for evidence of top-management commitment.
Marked unknowns instead of inventing them
Unconfirmed facts were left as explicit markers for resolution rather than plausible-sounding filler that fails on the first evidence request.
Indian regulatory overlay (frequently missed on US-framework certifications)
DPDP Act 2023 CERT-In Directions — 6hr reporting IT Act 2000 s.43A / s.72A ISO/IEC 17021-1 independence
Career

Experience

2019 — 2024

Principal Engineer, Security

Grab — FinTech Joint Venture Engineering Group and Slice FinTech - Product Security Group

Full-stack product security across DigiBanking, Wallet, Payments, and Subscriptions — application & API security, distributed systems, security orchestration, and joint-venture security integrations across regional Fin-Tech partners.

  • Led the Joint Venture Engineering security team — full-stack integration & architecture for OVO Wallet and BookMyShow ticketing integrations.
  • Payment Gateway security for merchant integrations — Google Play, Netflix.
  • Security hardening of PoS/swiping devices (Ingenico, PAX) and secure device provisioning.
  • Seeded CASA security architecture for Grab DigiBank.
  • Designed & built "Kalo" — an Application Key Abstraction Layer for internal services — plus an API Inventory and API Call Trace tool for API discovery.
  • Cloud security across GCP/AWS — Security Command Center, org policies, vulnerability assessment; XDR, API abuse/fraud detection, and open-source SIEM-based incident response.
1999 — 2019

Technical Leader / Software Developer

Cisco Systems — Enterprise Networking Security Group (India & US)

20 years in network & IoT security, threat defense, software-defined access, and enterprise blockchain — architecting security into the network layer itself.

  • Architected policy-based segmentation using Security Group Tags — inline identity and policy metadata propagation over GRE, VXLAN, LISP, 802.3, 802.1Q.
  • Designed & developed IoT/M2M gateway firewalls combining application recognition with MUD-based (Manufacturer Usage Description) access control.
  • Security co-lead for an embedded Unified Threat Management solution for SMBs.
  • Contributed Hyperledger Fabric integration on enterprise routers & switches, including node authentication and certificate enrollment.
  • Co-led the Identity Distribution Framework — sharing identity/policy metadata across peer network devices; 802.1X and Web Authentication across routed, switched, and transparent-bridged ports.
  • Advanced Security Development Group — passive assessment and encrypted traffic analytics; contributed IETF drafts on IPSec event logging (OPSAWG) and DDoS threat signaling (DOTS).
Capability

Skills & frameworks

AI / Platform Infra
LLM gateway & policy routing On-prem model serving (Ollama/vLLM) Token metering & usage billing GPU-as-a-Service brokering Agentic / AI-assisted engineering at scale
Cloud & Kubernetes
Kubernetes (multi-cluster) Cilium Rook-Ceph KubeVirt / CDI CNPG / Postgres Keycloak OpenBao Prometheus Chaos Mesh AWS GCP
Security & Compliance
ISO/IEC 27001:2022 SOC 2 (TSC 2017 rev. 2022) NIST SP 800-61 OWASP Top 10 / API Top 10 DPDP Act 2023 CERT-In Directions Risk methodology (5×5) Pen-test programme management M365 / Entra ID hardening
Languages & Protocols
Go Python (FastAPI/Flask) React / TypeScript C REST / OpenAPI MongoDB Redis Kafka GRE / VXLAN / LISP 802.1X
Research

Patents & publications