Eshwar Desetty

Security Strategy, GRC & AI Risk

Open to security roles
Location
Pittsburgh, PA
Focus
GRC, Risk Management, AI Security
Program
MS Information Security Policy & Management, Carnegie Mellon
Graduating
May 2027

Security that makes sense. Risk, policy and controls, turned into decisions people actually follow.

Selected work

Projects & case studies

Experience

Where I've worked

4
Roles
3
Organisations

01/2026 - Fall 2026

CMU Student Representative, ISPM

Carnegie Mellon University

Selected as Student Representative for the ISPM cohort at Heinz College. Gather feedback from students, help shape events and programming, and support connection within the cohort to enhance the student experience.

LeadershipStudent AdvocacyEvent PlanningCommunity Building

01/2026 - Present

Graduate Teaching Assistant

Carnegie Mellon University

Host weekly office hours and manage Canvas LMS including grading and course administration for 40+ graduate students. Provide technical guidance on product management projects and contribute to course improvement initiatives.

TeachingCanvas LMSProduct ManagementCourse Administration

06/2024 - 06/2025

Project Management Officer

CredXO

Coordinated engineering workflows for 12-15 member development team at blockchain-based fintech startup. Enforced security and operational policies including repository access controls and confidential data handling protocols. Supported Shark Tank INDIA pitch preparation.

Project ManagementSecurity PoliciesBlockchainFintech

06/2023 - 08/2023

Cybersecurity Analyst Intern

Hacker Bro Technologies

Completed intensive training in incident response, vulnerability assessment and security event monitoring using SIEM platforms. Practiced penetration testing techniques including network reconnaissance with Nmap, packet analysis using Wireshark and web application security testing with Burp Suite.

SIEMPenetration TestingNmapWiresharkBurp Suite
About

In my own words

What do I focus on?

Security issues aren't always technical problems. Often they're communication problems. I work where risk, policy and engineering meet: assessing risk, mapping controls to frameworks, and making the case for the fix people will actually adopt.

How do I think about it?

Like an attacker and a defender at once. I've tested LLMs with malicious prompt injections, analysed real-world breaches down to their root cause, and built tooling that blocks risky changes before they ship.

What am I looking for?

Teams that treat security as a product: measurable, well-governed, and built with the people who use it. I'm always happy to talk shop.

Education

  • Carnegie Mellon UniversityMaster of Science in Information Security Policy and ManagementExpected 05/2027
  • Vellore Institute of TechnologyBachelor of Science in Computer Science08/2021 - 08/2025

Certifications

CISSP (Candidate)CompTIA Security+ (Candidate)Google Bits and Bytes of Computer Networking
Toolkit

What I work with

Governance, Risk & Compliance

  • Risk Assessments
  • Security Policy Drafting
  • Control Mapping
  • Audit Evidence Support

Frameworks & Standards

  • NIST CSF
  • ISO 27001
  • PCI DSS
  • HIPAA
  • GDPR
  • OWASP Top 10

Security Operations

  • Log Monitoring & Triage
  • Incident Response
  • Vulnerability Assessment
  • Splunk & ELK
  • Burp Suite & Nessus
  • Wireshark
  • Nmap & Suricata

Engineering & OT

  • Python & Bash
  • PowerShell
  • Linux
  • YARA Rules
  • ICS & SCADA
  • Network Segmentation
Contact

Let's talk security

The best conversations don't start with a checklist.

You don't need a perfect match to reach out, whether it's a role, a project, research, or just a conversation. If you're working on risk, compliance or AI security, I'd like to hear about it.