Dubai · building at the AI × systems boundary

$ whoami

I build AI systems
that work in the real world.

Senior AI Engineer in Security at Deriv

I work across agentic AI, LLM infrastructure, backend architecture, and evaluation—turning promising models into systems that can reason, coordinate, and operate reliably.

Selected proof / 05

01 / ENGINEERING PROFILE

One engineer.
Three layers of depth.

AI is the work. Computer science is the foundation. Security is the constraint that makes the system trustworthy.

01

Primary practice

AI Engineering

Designing agentic workflows, retrieval systems, evaluation loops, and model-powered products that move beyond demos.

  • Agent architecture
  • Multi-agent systems
  • RAG
  • LLM evaluation
  • LLMOps
  • Transformers

02

Engineering depth

Core CS & Systems

Building the APIs, data flows, services, and storage layers that make intelligent software dependable at production scale.

  • System design
  • Distributed systems
  • Data pipelines
  • Backend engineering
  • Databases
  • Algorithms

03

Applied lens

Security Concepts

Applying adversarial thinking, observability, and controls to agent behavior, software boundaries, and real attack surfaces.

  • AI security
  • Security operations
  • Agent guardrails
  • Vulnerability research
  • DLP
  • Threat modeling

$ system.pipeline

context reasoning tools evaluation observability guardrails

02 / SELECTED WORK

Built, tested,
and shipped.

Projects that show range across model behavior, systems thinking, developer tooling, and applied security.

Security ML systems Deriv · company project

Next-Gen SOC

A machine-learning security operations platform that turns heterogeneous telemetry into prioritized, explainable investigation context. Source-aware feature and model pipelines preserve the behavior of each signal domain instead of forcing every event through one generic detector.

Telemetry → behavior → decision support ML-assisted SIEM with analyst-in-the-loop evaluation
  • ML-assisted SIEM
  • UEBA
  • Anomaly detection
  • Model evaluation
Company case study · architecture intentionally abstracted
detection_pipeline / conceptual
01
ingestmulti-source security telemetry
02
representsource-aware features and context
03
detectUEBA · behavioral and anomaly models
04
assistprioritized evidence for analyst review
Agent runtime security Company project · 2026

LobsterLock

A host-level policy layer for autonomous agents. LobsterLock attaches to an unmodified OpenClaw gateway at the Node.js runtime boundary, intercepting command execution, network calls, and filesystem access before they cross a risky edge.

Observe → enforce Policy-driven rollout without a platform fork
  • Runtime hooks
  • Policy engine
  • Audit telemetry
  • Node.js + Python
Company case study · source private for now
runtime_control_path
01 OpenClaw gateway unmodified host
02 Runtime loader Node.js boundary
cmdchild_process
netfetch · http(s)
fsread · write
allow · block · observe YAML policy → JSONL audit → optional telemetry
Agentic AI Team project · 2025

Natural-language agent builder

A platform for creating AI agents, multi-agent teams, and custom tools from natural language, with one-click deployment and the OpenAI Agents SDK.

2nd place Deriv AI Innovation Contest · $5K prize
  • Agent orchestration
  • Tool design
  • OpenAI Agents SDK
  • Deployment
LLM systems Data

DataLine

An LLM-powered data pipeline for migration, parsing, and natural-language querying with retrieval-augmented generation.

  • RAG
  • Vector databases
  • Data pipelines
Case study / private build
Multi-agent Finance

FinAgent

A multi-agent financial advisory system for portfolio analysis, market-trend reasoning, and personalized recommendations.

  • Agent architecture
  • LLMs
  • Financial systems
Case study / private build

02.1 / SECURITY RESEARCH

Found, reported,
and fixed.

Published vulnerability research across widely deployed software, handled through coordinated disclosure.

Electron security Credited reporter

Electron session-isolation research

Reported a cache-isolation flaw in Electron’s custom protocol handling. Under affected configurations, an upstream response could be reused across otherwise isolated session partitions.

CVE-2026-70606 Medium · CVSS 5.9 · CWE-668
Applied security Coordinated disclosure

OpenImageIO IFF decoder research

Discovered a heap-buffer-overread in the IFF decoder involving crafted files with Z-buffer data. The issue was fixed through coordinated disclosure.

CVE-2026-59956 Open-source vulnerability research
Read the disclosure note

02.2 / OPEN SOURCE

Built in public,
merged upstream.

Selected public builds and contributions accepted into external codebases.

Capital One logo
Capital OneVulnHunter
merged · PR #21

Security harness

VulnHunter

Fixed repository-basename collisions in batch scans by preserving owner and repository identity across checkout, logs, results, and resume state.

  • Python
  • Batch harness
  • 163 tests
View merged PR
Cisco AI Defense logo
Cisco AI DefenseDefenseClaw
incorporated upstream

Agent security observability

DefenseClaw

Added structured network-egress telemetry with query filters, blocked-call counts, alert surfacing, OpenTelemetry counters, and optional Splunk forwarding.

  • Go
  • Audit telemetry
  • OpenTelemetry
Open sourcerushitgit
maintained openly

Model internals

Transformer Visualizer

An interactive tool for exploring transformer components, attention mechanisms, and token representations through a lightweight BERT model.

  • Transformers
  • Visualization
  • Hugging Face
View source

03 / EXPERIENCE

From data systems
to intelligent systems.

A progression through databases, backend engineering, applied ML, and production AI—with security increasingly embedded in the work.

  1. 2025–26FEB–NOW

    Deriv · Dubai

    AI Engineering · Security

    Joined as an intern and continued across three roles in the security team.

    1. Senior AI Engineer

      Building agent-security controls, supply-chain defenses, and anomaly detection for internal systems.

    2. AI Engineer

      Worked across security operations, AI-assisted testing, and data-loss-prevention projects.

    3. AI Engineering Intern

    CURRENT
  2. 2024JUL–AUG

    JetSynthesys · India

    AI Engineering Intern

    Built NLP systems for brand tonality, created an OpenAI-powered nutritional database with a 95% cost reduction, and researched biomarker applications with MedGemini.

  3. 2023–24DEC–JUL

    xPERT BPDC Programme

    Database Engineer

    Designed a scalable quizzing-platform architecture using Firebase and Flask.

  4. 2023JUN–AUG

    Cybage Software · India

    Backend Developer Intern

    Prototyped a Spring Data Flow pipeline using Spring, PostgreSQL, RabbitMQ, and REST services.

  5. 2022JUL–AUG

    Force Motors · India

    Database Engineer Intern

    Designed an employee-correspondence database, improved retrieval speed by 35%, and built a Java-based OCR prototype.

04 / SIGNALS

Receipts,
not adjectives.

Research, teaching, competition, and open-source work—evidence of curiosity under different constraints.

Research

IEEE-published work on NLP

ChatGPT and the Social Media Echo: A Sentiment Analysis, presented at MoSICom 2023.

Teaching

Guest lecture: building with LLMs

Returned to BITS Pilani Dubai to speak with an LLM/AI class about codebase-aware AI tools and how software-development workflows are changing.

Building

AI Innovation Contest

2nd place · $5K for a natural-language platform that creates and deploys agents, multi-agent teams, and tools.

Computer science

NASA Space Apps

UAE winner · global nominee in the 2023 challenge, among more than 5,500 teams globally.

$ cat competitive-signal.log

Security is one proving ground—not the whole identity.

See the full record
GITEX Global CTF third-place certificate
2025 · FINALS

GITEX Global CTF

3rd place · Cyber Security Council

Kaspersky CTF UAE second-place certificate
2025 · 24 HOURS

Kaspersky CTF

2nd UAE · 12 / 415 across MEA, Türkiye & Africa

Hack The Box Global Cyber Skills Benchmark 2026 certificate showing team rank 23
2026 · GLOBAL 23RD · UAE 3RD

HTB Global Cyber Skills Benchmark

Project Nightfall · 122 / 126 challenges · 75,200 points

Snyk Fetch the Flag 2026 certificate
2026 · GLOBAL

Snyk Fetch the Flag

Rank 56 / 1,539 · 6 of 22 challenges

Hack The Box Cyber Apocalypse CTF 2026 certificate showing team rank 294
2026 · TOP 300 / 6,744 TEAMS

HTB Cyber Apocalypse

Rank 294 · three-person team · 83 / 136 challenges

  • 01Dubai Police CTFOnline qualifiers · rank 1 UAE
  • 02GITEX Global CTF3rd place · Cyber Security Council
  • 03Kaspersky CTF2nd UAE · 12 / 415 across MEA
  • 04HTB Project NightfallGlobal 23rd · UAE 3rd
  • 05HTB Cyber Apocalypse294 / 6,744 · three-person team

05 / TRAJECTORY

Long before the
AI job title.

The throughline has always been the same: understand the machine, then build something ambitious with it.

01

Foundations

QBasic → HTML

Started with small programs and websites, learning how instructions become behavior.

02

Core CS

C++ → Java

Moved into algorithms, object-oriented design, and the architecture behind larger programs.

03

Data systems

Python → SQL

Built fluency in data, storage, backend services, and the pipelines connecting them.

04

Machine learning

Neural nets → Transformers

Went from classical AI and CNNs to NLP, deep learning, and model internals.

05

Now

Models → Systems

Engineering agents, tools, evaluation, and safeguards into useful end-to-end systems.

Education

BITS Pilani, Dubai Campus

BTech · Computer Science · CGPA 9.11

Away from the keyboard

Chess keeps the clock honest.

FIDE-rated competitor, 3rd at the NYU inter-college tournament, and usually one move away from either clarity or panic.

06 / CONTACT

Say hello.

Always happy to compare notes on AI systems, infrastructure, or an interesting engineering problem.

palesharushit@gmail.com