[ about ]

Abhishek Reddy

I'm a security engineer in Seattle. My work sits at the platform layer — workload identity, cryptography, PKI, and the trust boundaries between services. I like problems where the interesting part is the failure mode: what happens when a certificate expires, a key rotates mid-request, or a service you trusted starts lying.

What I work on

  • Workload identity & mTLS. SPIFFE/SPIRE topologies, issuance and rotation, and making zero-trust service meshes that operators can actually reason about.
  • Applied cryptography & PKI. KMS integration, certificate lifecycle, and designing for safe rotation instead of heroic incident response.
  • Secure-by-default systems. Controls that fail closed, are hard to misconfigure, and stay quiet until they're actually needed.

How I write here

Everything on this site is meant to teach a generalizable lesson, not to leak specifics. I keep to responsible-disclosure timelines and scrub anything tied to a current or former employer's internal systems. The filter is simple: if a writeup would help an attacker against a system I'm associated with, it doesn't get published — if it teaches a pattern anyone can apply, it does.

Elsewhere

Find me on GitHub, LinkedIn, or reach out at areddy1213@gmail.com. For anything sensitive, ask me for a PGP key first.