Arsen Vaneev

Cloud security, DevSecOps, AI security, automation.

01

Projects

Architecture diagram

Vulnerability Risk-Acceptance Engine

Python · GitHub Actions · CrowdStrike Spotlight · Vanta · CISA KEV

Pulls findings from two scanners over OAuth, deduplicates across both, and scores each CVE against a CVSS-vector rubric before writing a risk-acceptance justification that names the specific compensating control. Cleared 1,611 vulnerabilities ahead of an ISO 27001 audit and separated out 370 that needed patching instead.

Architecture diagram

AI Red-Team Harness

Ollama · Llama 3 · Garak · Promptfoo · PyRIT · OWASP LLM Top 10

Reproducible adversarial testing for self-hosted LLMs and RAG pipelines. Measures a success rate per technique rather than pass/fail, so mitigations can be compared — including an indirect prompt injection through a poisoned vector store and the fix that measurably cut its attack rate.

Architecture diagram

SecureLab

Actions · Docker · Terraform · Kubernetes · Trivy · Grafana

A CI/CD pipeline built to be attacked and then hardened: Trivy image and filesystem scanning gating every build, Terraform-declared infrastructure with drift detection against live state, and Prometheus and Grafana wired end to end over a kind cluster.

02

Experience

Aug – Dec 2026 · Remote

Security Intern — CCC Intelligent Solutions

Rotational internship across DevSecOps, GRC, and security operations.


Jun – Aug 2026 · Durham, NC

Information Security Engineer Intern — ElevateBio

Built the risk-acceptance pipeline above. Contributed to investigations across CrowdStrike Falcon, Palo Alto Panorama, NG-SIEM, Meraki, and Axonius, including a device-attribution chain that resolved a suspected malware alert as a WeChat false positive. Worked through 690+ posture findings, separating real MFA gaps from service-account and Okta-federated noise.


Jun 2025 – Jun 2026 · Raleigh, NC

Cybersecurity Analyst — NC State OIT

Mapped campus security controls to NIST CSF categories and 800-53 control families, ran third-party vendor risk assessments, and reported compliance posture to leadership weekly.

B.S. Computer Science, NC State · Graduating May 2027

03

About me

I build security automation and break AI systems on purpose. Most of my work starts the same way — a process someone runs by hand every quarter, or a system nobody has tried to attack yet — and ends with something reviewable that runs on a schedule. I care more about a finding someone else can act on without me in the room than about the finding itself.


Focus

Cloud security, DevSecOps, and AI security. Looking for full-time work starting May 2027.

Certifications

CompTIA Security+ (SY0-701), Feb 2026. SANS SEC495 — Building & Securing RAG and Agentic RAG, Jul 2026.

Logistics

Based in Raleigh, NC. US permanent resident — no sponsorship needed.


04

Talk to AI Arsen

Under construction

Planned: RAG over write-ups + résumé · citation-required answers · rate limited
Until then: email the human.