Professional Summary
Product security engineer with 4+ years securing FDA-regulated medical devices across the full product lifecycle — from threat modeling and secure design through implementation, vulnerability management, and FDA premarket cybersecurity submissions. Builds reusable security frameworks and guardrails that scale across product lines: embedded Linux (Yocto, OpenSTLinux) and Windows golden-image hardening, Azure security baselines, DevSecOps pipeline templates, PKI automation, and SBOM intelligence. Translates regulatory expectations into engineering; partners across Regulatory, Quality, Engineering, and Project Management to ship audit-ready products. Tackles emerging industry problems including C/C++ SBOM generation via build interception, SBOM lifecycle intelligence, AI-assisted security workflows, and post-quantum cryptography readiness. Upstream Linux kernel contributor with two patches reviewed and merged into mainline.
Core Strengths
Reusable Security Frameworks & Guardrails: Windows golden images, OpenSTLinux/Yocto hardening baselines, Azure security configuration, DevSecOps pipeline templates, container/code signing, and certificate lifecycle automation that scale across multiple product programs.
Threat Modeling & Secure Design: Owns threat modeling, security requirements, and architecture reviews for embedded, cloud, and Windows-based medical device platforms; authors security architecture views aligned with FDA expectations and reused across product lines.
Shift Left & Developer Enablement: Centralized SAST/SCA, IaC-validated cloud security, self-service PKI and PIN provisioning, automated post-market vulnerability monitoring, and SBOM enrichment embedded directly into developer workflows.
Regulatory Translation: Turns FDA premarket cybersecurity guidance, FDA eSTAR, AAMI TIR57, and NIST CSF into concrete engineering deliverables, secure design artifacts, and audit-ready submission packages.
Emerging Problem Solving: C/C++ SBOM generation via build interception, SBOM end-of-life intelligence, automated cloud drift detection, AI-assisted security workflows, and post-quantum cryptography readiness.
Experience
BD (Advanced Patient Monitoring)October 2024 — Present
Staff Engineer II, Product Security — Irvine, CA · Promoted to Staff Engineer II in June 2026; joined via BD's acquisition of Edwards Lifesciences' Critical Care business unit.
- Lead product security across multiple medical device programs — threat modeling, secure design, vulnerability management, V&V, and cybersecurity documentation for FDA premarket submissions in partnership with Regulatory, Quality, and Program Management.
- Built hardened Windows golden images for AI-algorithm laptop platforms under a compressed FDA AI response timeline (BIOS, firmware, OS, access control, lockdown), converting urgent one-off execution into a reusable pattern projected to cut future hardening from months to ~1 week.
- Centralized Coverity SAST scanning across product teams into a controlled, scalable model and accelerated containerized build adoption across engineering.
- Led migration of Coverity and Black Duck (with historical scan data and checker configurations) from Edwards into BD, preserving audit continuity after the divestiture.
- Built a C/C++ SBOM generator using build-system interception to capture statically linked and manually included dependencies, addressing a known industry gap.
- Developed SBOM end-of-life enrichment with confidence scoring, released as the open-source SBOM Support Analyzer.
- Built self-service security automation (Microsoft Forms + Power Automate + Azure DevOps) for PKI certificate issuance and rolling PIN provisioning, replacing manual spreadsheets with authenticated, traceable flows.
- Built a post-market vulnerability monitoring pipeline from Black Duck and Microsoft RSS feeds into Jira, generating remediation tasks routed by ownership.
Edwards Lifesciences LLCAugust 2021 — October 2024
Senior Engineer, Product Security — Irvine, CA · Critical Care business unit divested to BD in October 2024.
- Owned product security across the full lifecycle of a Yocto-based embedded healthcare monitor — cybersecurity management plan, threat modeling, secure design, implementation, vulnerability management, and FDA premarket submission.
- Built the OpenSTLinux hardening baseline for the division's first embedded Linux product of its kind; reused across subsequent product programs.
- Established a QMS workflow wiring FDA eSTAR cybersecurity artifacts directly into the Product Development Lifecycle for repeatable compliance.
- Authored Azure security configuration requirements and built scripts validating Terraform-defined infrastructure against them — drift detection and security-as-code before it was common practice.
- Drove creation of a dedicated DevOps function: repo structure, secure build-agent strategy, a "build once, validate, promote" model, and reusable pipeline templates integrating SCA/SAST/IaC into IDEs and PR gates.
- Replaced Ubuntu-based containers with minimal Alpine images, cleaning up ~95% of vulnerability noise; deployed Prisma Cloud CSPM/Compute and architected a private DigiCert ONE environment for SSL, code signing, and container signing.
Esri (Environmental Systems Research Institute)October 2020 — July 2021
Security Engineer, ArcGIS Enterprise — Redlands, CA
- Stood up the threat modeling process for ArcGIS Enterprise and its applications; designed user-level access controls with the development team.
- Hardened Docker images on Kubernetes by triaging WhiteSource and Protecode findings; implemented runtime monitoring with Falco.
- Conducted black-box penetration testing of the Kubernetes cluster, pods, and services; triaged Acunetix findings and verified fixes across Windows and Linux patch releases.
Syracuse UniversitySpring 2019
Graduate Research Assistant — Syracuse, NY
- Built a Data Consistency Checker improving verification rate for distributed-systems consistency models (linearizability, eventual, sequential) by ~10%, hardened against result tampering by executing inside an Intel SGX enclave.
Open Source & Thought Leadership
- Linux kernel: Upstream contributor with two patches merged into mainline — an ocfs2 use-after-free fix in
ocfs2_fault() on VM_FAULT_RETRY (reviewed by Joseph Qi and Andrew Morton; mm tree), and a data-race fix in fat fat_clusters_flush().
- SBOM Support Analyzer: Open-source tool analyzing CycloneDX/SPDX SBOMs for component support status and end-of-support dates using real-time registry data (github.com/bharambetejas/sbom-support-analyzer).
- meta-stig: Ubuntu 22.04 DISA STIG controls as a Yocto Poky BitBake layer for a reusable embedded Linux hardening baseline (github.com/tb-kt/meta-stig).
- HVSS Calculator: Contributor to the Healthcare Vulnerability Scoring System reference lab (github.com/ewprodsec/hvss-calculator-lab).
- Asahi Fairydust DisplayPort: Built and documented USB-C DisplayPort output on the Asahi Linux fairydust kernel branch for Apple Silicon Macs; community PRs merged (github.com/bharambetejas/asahi-fairydust-display).
- Writing: Author of "From Manual Scanning to DevSecOps: My Practical Journey," with ongoing commentary on post-quantum readiness, SBOM maturity, and product security architecture.
Education
M.S., Cybersecurity — Syracuse University, Syracuse, NYAug 2018 — May 2020
B.E., Computer Engineering — K. J. Somaiya Institute of Engineering & IT, Mumbai, IndiaJul 2014 — May 2018
Skills
Security Architecture: Embedded Linux (Yocto, OpenSTLinux), Windows Hardening (STIG, golden images), Threat Modeling, Secure SDLC, Vulnerability Management, SBOM (CycloneDX, SPDX), DevSecOps / Shift Left, Cloud Security, PKI & Certificate Lifecycle, Container & Kubernetes Security, Runtime Monitoring, Penetration Testing, Post-Quantum Cryptography Readiness
Compliance & Regulatory: FDA Premarket Cybersecurity Guidance, FDA eSTAR, AAMI TIR57, HIPAA, NIST CSF, DISA STIG
Security Tooling: Black Duck, Coverity, Wiz, Snyk, Checkmarx, Prisma Cloud (CSPM & Compute), DigiCert ONE, Falco, OWASP Threat Dragon, Acunetix, Nessus, Metasploit, Burp Suite Pro, Wireshark, Nmap, American Fuzzy Lop
Cloud / DevOps: Azure, Azure DevOps, AKS, ACR, Terraform, Docker, Kubernetes, Power Automate, ServiceNow, Jira
Languages & Systems: C, C++, Python, Bash · RHEL, Ubuntu, Fedora, Kali, Windows