Jibin Benny

Cloud Security Engineer @ Equifax | Building Secure-by-Default Cloud Platforms (AWS, GCP, Azure) | IAM · Policy-as-Code · CI/CD Supply Chain Security · Kubernetes

Role
Cloud Security Engineer at Equifax
Location
Kochi, KL, IN
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Jibin Benny

Security that catches failures at design time — not at 2 AM after a breach. That\'s the standard I build to. Over 5 years across AWS, GCP, and Azure, I\'ve built preventive security platforms serving 12 engineering teams that eliminate entire failure classes before production. What I\'ve shipped: → Secure-by-default AWS landing zone across ~45 accounts — Terraform-enforced IAM boundaries, network segmentation, and encryption controls eliminating ~82% of common misconfiguration failure modes → OPA/Conftest policy gates across 18 Terraform repos — catching ~35 insecure patterns per week and reducing production security findings by ~65% in 4 months → OIDC-based CI/CD trust model across 22 pipelines — eliminated 34 long-lived credential sets, reducing credential exfiltration attack surface to zero → Kubernetes admission + runtime controls (Gatekeeper + Falco) — zero privileged container deployments in production clusters → Automated detection pipelines (GuardDuty + CloudTrail Lake) — reduced MTTR from ~6 hours to ~8 minutes My design principles: • IAM is the control plane • Policy-as-code is the enforcement layer • CI/CD pipelines are trust boundaries — designed, not assumed • Security controls should be developer-friendly or they\'ll be bypassed Open to Senior Cloud Security Engineer and Security Platform Engineer roles at product-first companies building at scale. AWS Security Specialty — in progress (2026)

Experience

  1. Cloud Security Engineer

    Equifax

    Jul 2024 — Present · Trivandrum, IN

    Architected a secure-by-default multi-account AWS landing zone spanning ~45 accounts and 8 business units by building reusable Terraform modules with mandatory IAM boundaries, network segmentation, encryption-at-rest defaults, and tagging guardrails — eliminating ~82% of common privilege-escalation and misconfiguration failure modes before production, enabling developer self-service provisioning without security tickets.• Shifted security enforcement left by implementing OPA/Conftest policy gates across 18 Terraform repositories used by ~60 developers, catching ~35 insecure patterns per week including overly permissive IAM policies, open security groups, and non-compliant resource configurations — reducing production security findings by ~65% within 4 months.• Redesigned CI/CD identity and trust model across 22 pipelines using OIDC federation, eliminating 34 long-lived credential sets and reducing credential exfiltration attack surface to zero for all production deployment paths. Conducted threat modeling on pipeline compromise scenarios (compromised runners, malicious PRs) to validate blast-radius containment.• Established software supply-chain trust controls by enforcing Cosign artifact signing and SBOM validation across 14 build pipelines, blocking unsigned or tampered artifacts from promotion to production — reducing software supply chain risk exposure for 28 production services.• Operationalized cloud security posture management using Wiz across 45 cloud accounts, identifying 12 toxic combinations and 7 critical exposure paths, driving remediation through engineering ownership with a 5-day median time-to-remediation for critical findings.• Built automated detection and response workflows integrating GuardDuty, Security Hub, and CloudTrail Lake with EventBridge-driven Lambda functions, reducing MTTR for recurring cloud risks from ~6 hours to ~8 minutes while decreasing alert noise by ~74% through tuned suppression rules and contextual enrichment.

Education

  • APJ Abdul Kalam Technological University (KTU), Thiruvananthapuram

    BTech, Electrical and Electronics Engineering

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Jibin Benny — Cloud Security Engineer at Equifax in Kochi, KL, IN | Unifers