Ankit Rao

Ankit Rao

Senior Software Engineer, Zscaler

Bengaluru, India

Actions

A passionate Cloud and Cloud Security enthusiast.
AWS Certified Solutions Architect | AWS Community Builder | Microsoft Azure | GCP | Cloud Security | Speaker | Blogger | CIS Contributor | DevSecOps

Area of Expertise

  • Information & Communications Technology

Topics

  • Cloud Security
  • Cloud & DevOps
  • Cloud Security Architecture
  • AWS
  • Azure
  • GCP
  • Cloud Native
  • Cloud Computig
  • Google Cloud
  • Cloud Technology
  • Cloud Containers and Infrastructure
  • Cloud App Security
  • Automation
  • Automated Security
  • User Group
  • Tech Community
  • Serverless
  • Serverless computing
  • Azure Serverless
  • Cloud Community Day
  • AWS Community Day

Supply Chain Security for Kubernetes Operators: Securing the Things That Secure You

There's a deep irony in modern Kubernetes security: the operators
we deploy to secure our clusters are themselves unsecured.
ArgoCD — which controls what runs in your cluster — often runs
with ClusterRole permissions that would make a penetration tester
weep. cert-manager manages TLS certificates for every service.
External Secrets Operator has read access to your entire secrets
vault. Strimzi controls your Kafka cluster. KEDA can scale any
workload.

These operators are privileged, trusted, and almost never audited.
They are also updated regularly, pulling new container images from
public registries. They are, in short, a perfect supply chain
attack surface — and most teams have zero visibility into it.

At Zscaler's Data Fabric team, we run 10+ operators in production
across multiple Kubernetes clusters. In this talk, I'll share
exactly how we threat-modelled, audited, and hardened our entire
operator ecosystem — and the automated guardrails we built to
keep it that way through upgrades.

From CSPM to Real-Time Compliance: Building an Automated Cloud Security Posture Engine

Cloud Security Posture Management (CSPM) has become table stakes —
but most implementations are reactive dashboards that flood teams
with findings they never fix. The real challenge isn't detection;
it's closing the loop between a policy violation and a verified,
auditable remediation — in real time, at scale, across multiple
cloud accounts and environments.

At Zscaler, our team manages cloud infrastructure spanning AWS
across multiple cells and environments — development, staging,
and production — each with distinct compliance requirements.
I'll share how we evolved from a traditional CSPM point-in-time
scan model to a continuous, event-driven compliance engine that
detects, classifies, and remediates posture violations before
they become incidents.

This talk draws directly from U.S. Patent US11722522B2 (assigned
to Zscaler, co-invented by me) on network security posture
architecture, as well as hands-on experience contributing to
CIS Benchmark definitions and building automated compliance
pipelines on AWS.

FinOps on Kubernetes: How We Cut Cloud Costs by 40% Without Touching a Single Application

FinOps isn't a finance team problem — it's an engineering problem.
And on Kubernetes, it's one of the hardest engineering problems
to solve well. Over-provisioned node groups, always-on batch jobs,
statically sized data clusters, and idle Spark executors silently
drain budgets while engineering teams remain focused on features.

At Zscaler's Data Fabric team, we run a large-scale Kubernetes
platform on Amazon EKS spanning Apache Spark, Apache Flink,
ClickHouse, Kafka (Strimzi), and RisingWave — across multiple
cells and environments. Over the course of a focused FinOps
initiative, we reduced our cloud infrastructure costs by over
40% — without rewriting applications, without reducing capacity,
and without impacting SLAs.

This talk tells the complete story: the audit that revealed where
the waste was, the architecture changes we made, the tools we
used, and the numbers before and after.

AIOps in Practice: Using AI Agents to Detect, Diagnose and Auto-Remediate Kubernetes Incidents

What if your Kubernetes cluster could fix itself at 3am — before
your on-call engineer even wakes up? In this talk, I'll talk about how
we built an AI-driven incident pipeline on our data platform that
detects anomalies, diagnoses root cause from logs and events, and
safely auto-remediates — with real cases and real guardrails.

Ankit Rao

Senior Software Engineer, Zscaler

Bengaluru, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top