I am a dedicated security software engineer boasting 8+ years of expertise in InfoSec research and development. I am passionate about security engineering and data analysis, with a profound understanding of programming, database design, and networking. Continuously seeking out superior opportunities in software design and development to fortify enterprise security.
Overview
8
8
Years of professional experience
10
10
Certifications
Work History
Security Software Engineer
Microsoft
, Washington
09.2018 - Current
As a Service Engineer with System Engineering and Infrastructure reliability domain knowledge, I specialize in maintaining the software quality, reliability, availability, and performance of enterprise-level security services with 150,000+ global customers. My expertise includes incident response, customer support engineering, robust systems monitoring and alerting, release engineering, business continuity/disaster recovery planning, automation, architecture and design, performance testing and optimization, and ensuring data reliability, consistency, and durability.
As a Senior Software Engineer since March 2024, I’ve driven software engineering, security, and operational excellence across two high-impact teams. At Microsoft Security, I led initiatives to automate pre-patch validation, enhance Azure DevOps pipelines, and strengthen Azure tenant security through JIT access, SFI remediation, and legacy authentication retirement. I also spearheaded the HRE Status Framework, mentored junior engineers, and built telemetry and alerting platforms to boost observability and resilience.
Architecting & Leading robust, reliable monitoring & alerting solution by implementing internal tools & technologies to support Microsoft Enterprise High-Risk-Environment. Transitioning to the SAVI team in January 2025, I continued to elevate engineering standards by
streamlining onboarding, remediating security issues, and optimizing CI/CD pipelines. I collaborated on AI product integrations (Southpaw and Pasco), addressed container vulnerabilities, and simplified Helm configurations. My leadership in threat modeling, failure mode analysis, and implementation of TLS, metrics, tracing, and high availability features significantly
improved service reliability and performance. I also contributed to PPE readiness through audit logging, graceful shutdowns, and OARS tracing, reinforcing system stability and security.
Information Security Engineer
FDM Group INC
New York
09.2017 - 08.2018
As an IT security consultant at a financial hedge fund firm, I played a pivotal role in safeguarding critical infrastructure and data integrity through a multifaceted approach.
Collaborating closely with cross-functional teams including cloud compute, network, and data specialists, as well as software developers, I spearheaded the development and deployment of robust security solutions for authentication and authorization.
My responsibilities encompassed investigating and troubleshooting security incidents, conducting penetration testing, and employing machine learning techniques to detect threats in real-time datasets.
Furthermore, I demonstrated proficiency in debugging, reverse engineering, and analyzing suspicious files, showcasing a comprehensive understanding of cybersecurity methodologies and tools.
Information Security Intern
Indusface Pvt. Ltd.
Vadodara
01.2015 - 12.2015
During my one-year internship at a web application security and firewall company, I conducted security audits and analysis on vulnerable applications, researched and developed core rules for OWASP vulnerabilities, and deployed WAF architecture using Apache mod security.
I also crafted Perl Compatible Regular Expressions (PCRE Regex) and developed automated web tools for identifying Zero-day patched reports and creating custom rules using templates for DoS prevention, information obfuscation, leakage prevention, and IP reputation & Injection attack.
CISO50 Innovation & Excellence Award, 2019, High-Risk-Environment - Microsoft Security
Publications
Assawakomenkool, N., Patel, Y., Voris, J., Network Aware Defenses for Intrusion Recognition and Response (NADIR), Proceedings of the Future Technologies Conference (FTC) 2018, 2019
Patel, Y., Digital age influence on IT risk management: Modern implications & consideration, International Research Journal of Engineering and Technology, 11, 8, 475-483, 2024
Patel, Y., Enhancing device management experience through information technology: Implementing a multi-step device lifecycle process, International Journal of Science & Engineering Development Research, 9, 8, 241-247, 2024
Patel, Y., Minimize security risk in managing production environment, International Journal of Creative Research Thoughts, 12, 8, f783-f788, 2024
Patel, Y., Security & compliance in managing production environment: Challenges with outsourcing IT, International Journal of Creative Research Thoughts, 12, 8, a581-a586, 2024
Patel, Y., Cybersecurity in Healthcare: Protecting Critical Infrastructure Against Evolving Threats, International Journal of Computer Trends and Technology, 72, 11, 23-30, 2024
Patel, Y., IT GOVERNANCE IMPLICATIONS & IMPLEMENTATIONS UNDER PANDEMIC, International Journal of Management IT and Engineering, 14, 33-39, 2024
Patel, Y., Zero-trust implementation for secure & reliable container architecture, Computer Science & IT Research Journal, 6, 4, 288-296, 2025
Patel, Y., Security Threats and Risk Mitigation in Home Automation: A Qualitative Review of Challenges and Public Safety Considerations, Journal of Information Systems Engineering and Management, 10, 55s, 567-572, 2025