Skip to content
CloudSecOps

A security consultancy built after the cloud, and after AI.

CloudSecOps started in 2018 as an engineering blog about securing cloud infrastructure — automated remediation on AWS, Kubernetes admission control with OPA Gatekeeper, DevSecOps practice that survived contact with real pipelines. The consultancy grew out of the writing, and the writing never stopped.

How we're set up

Senior-only delivery. There is no bench of junior consultants, no handoff after the sales call, and no account manager translating between you and the person doing the work. The engineer who scopes your engagement is the engineer who runs it and writes your findings.

That structure has an obvious limit: we can only run a few engagements at a time. We'd rather tell you that than pad a team with people who learned your stack yesterday.

What makes it work is that automation absorbs the work that used to justify large teams — enumeration, correlation, evidence collection, regression testing. What's left is the work that actually needs seniority, and that's what you're paying for.

What we don't do

  • Staff augmentation or bodyshop placements
  • 24/7 monitoring or managed SOC services
  • Reselling security tools for commission
  • Compliance certification audits (we prepare you; auditors audit)
  • Azure-specific engagements — not our depth, and we'll say so

A short list of refusals is more useful than a long list of capabilities. If what you need isn't here, we'll point you somewhere honest.

Who you'll be working with

Setu Parimi — principal consultant. Cloud security architect based in New York, working across AWS and Google Cloud security since 2018, with a background in vulnerability assessment, third-party application security review, penetration testing, and remediation engineering. Author of the CloudSecOps technical writing on DevSecOps practice, automated cloud remediation, and Kubernetes policy guardrails.

Current practice focus: securing AI systems — agentic architectures, MCP tool surfaces, retrieval pipelines — and building the AI-driven automation that makes security engineering faster than it used to be.

We don't publish client names, logos, or case studies. Client work is confidential by default, and we'd rather earn your confidence with technical writing you can read and judge than with a logo wall you can't verify.

Read the work, then decide.