Eshwar Desetty

Security Strategy, GRC & AI Risk

Experience

CMU Student Representative, ISPM

01/2026 - Fall 2026

Carnegie Mellon University

Selected as Student Representative for the ISPM cohort at Heinz College. Gather feedback from students, help shape events and programming, and support connection within the cohort to enhance the student experience.

Graduate Teaching Assistant

01/2026 - Present

Carnegie Mellon University

Host weekly office hours and manage Canvas LMS including grading and course administration for 40+ graduate students. Provide technical guidance on product management projects and contribute to course improvement initiatives.

Project Management Officer

06/2024 - 06/2025

CredXO

Coordinated engineering workflows for 12-15 member development team at blockchain-based fintech startup. Enforced security and operational policies including repository access controls and confidential data handling protocols. Supported Shark Tank INDIA pitch preparation.

Cybersecurity Analyst Intern

06/2023 - 08/2023

Hacker Bro Technologies

Completed intensive training in incident response, vulnerability assessment and security event monitoring using SIEM platforms. Practiced penetration testing techniques including network reconnaissance with Nmap, packet analysis using Wireshark and web application security testing with Burp Suite.

Projects

GRC Automation

Muster, AI Compliance Automation

LLM workflows that collect SOC 2 and NIST CSF audit evidence, with guardrails and manager sign off.

Product Security

EV Charging Product Security Assessment

An OCPP charge point stack tested against 13 ETSI EN 303 645 areas, with 6 gaps mapped to EN 18031.

Vulnerability Intelligence

ThreatLens

Connects NVD CVEs to MITRE ATT&CK, NIST 800-53 controls and Sigma detections to rank what to fix first.

AI Safety

U.S. Coast Guard, Secure AI Decision System

An offline AI workflow that grounds HAZMAT decisions in cited 49 CFR regulations.

Research, CyLab / SEI

LLM Vulnerability Discovery & Triage

A two stage self hosted LLM pipeline, benchmarked against SAST on precision, recall and false positives.

AI Governance

LLM Security Evaluation & Observability

38 LLM traces analysed for injection and compromise; 3 vulnerable models kept out of production.

AI Governance

Agentic AI Security & Governance

Practical security requirements for agentic AI: oversight, auditability, runtime controls and data protection.

Endpoint Compliance

SimplySecure

A macOS app that checks permissions, encryption and updates, and runs AI voice phishing drills.

Supply Chain Security

XRPL Guardrails

Preflight checks that block vulnerable dependencies before any XRP Ledger transaction runs.

Threat Intelligence

Cyber Threat Intelligence: Energy Sector

OSINT-led threat analysis of a Fortune 500 energy company, mapped with MITRE ATT&CK.

Incident Analysis

Change Healthcare Ransomware Attack

Root-cause analysis of a $2.3B attack on 15B healthcare transactions, plus the zero-trust plan to prevent it.

LLM Security

AI Security Research

An ML framework to detect, isolate and remediate prompt injection in LLMs.

Education

Carnegie Mellon UniversityMaster of Science in Information Security Policy and ManagementExpected 05/2027
Vellore Institute of TechnologyBachelor of Science in Computer Science08/2021 - 08/2025