[ about ]
Abhishek Reddy
I'm a security engineer in Seattle. My work sits at the platform layer — workload identity, cryptography, PKI, and the trust boundaries between services. I like problems where the interesting part is the failure mode: what happens when a certificate expires, a key rotates mid-request, or a service you trusted starts lying.
What I work on
- Workload identity & mTLS. SPIFFE/SPIRE topologies, issuance and rotation, and making zero-trust service meshes that operators can actually reason about.
- Applied cryptography & PKI. KMS integration, certificate lifecycle, and designing for safe rotation instead of heroic incident response.
- Secure-by-default systems. Controls that fail closed, are hard to misconfigure, and stay quiet until they're actually needed.
How I write here
Everything on this site is meant to teach a generalizable lesson, not to leak specifics. I keep to responsible-disclosure timelines and scrub anything tied to a current or former employer's internal systems. The filter is simple: if a writeup would help an attacker against a system I'm associated with, it doesn't get published — if it teaches a pattern anyone can apply, it does.
Elsewhere
Find me on GitHub, LinkedIn, or reach out at areddy1213@gmail.com. For anything sensitive, ask me for a PGP key first.