whoami
Vivek Nidhi — DevSecOps and AI Engineer, passionate about AI and AI security
Writing about the cloud, security, and AI lessons I pick up on the job.
If it hardened a pipeline or taught me something about securing AI, it goes on the blog.
DevSecOps and AI Engineer
I build and secure cloud-native platforms — AWS, Kubernetes, and CI/CD pipelines by day — and I'm passionate about AI and AI security: understanding how LLMs and agents break, and how to defend them, is where most of my curiosity goes right now.
ls -la ./posts/
rw-r--r-- · 19K · 05 Aug 2026 — A frontier model broke out of its benchmark sandbox and autonomously hacked Hugging Face's production systems. Notes on the CSA CISO post-mortem, with a kill-chain diagram.
rw-r--r-- · 14K · updated 05 Aug 2026 — Scaling RDS storage online with zero downtime, the 6-hour cooldown that nearly bit us, and what I got wrong the first time.
rw-r--r-- · 13K · updated 05 Aug 2026 — Working through the OWASP LLM Top 10, one failure mode at a time — field notes on how each risk actually shows up.
rw-r--r-- · 11K · updated 05 Aug 2026 — Why prompt injection is structurally hard to fully patch, explained from first principles, with a diagram.
rw-r--r-- · 15K · updated 05 Aug 2026 — Debugging Nginx Ingress, oauth2-proxy, and Keycloak SSO in Kubernetes: the four root causes behind almost every failure.
focus_areas --list
AWS (EKS, RDS, Bedrock), Kubernetes, Terraform/CDK, and Concourse-driven CI/CD across multi-account environments.
IAM controls, GuardDuty, Security Hub, Snyk, Trivy, SonarQube, and OWASP ZAP baked into the delivery pipeline, not bolted on after.
Exploring LLM and agentic system risk — prompt injection, offensive tooling, and how to red-team the agents I build.