Session

From CSPM to Real-Time Compliance: Building an Automated Cloud Security Posture Engine

Cloud Security Posture Management (CSPM) has become table stakes —
but most implementations are reactive dashboards that flood teams
with findings they never fix. The real challenge isn't detection;
it's closing the loop between a policy violation and a verified,
auditable remediation — in real time, at scale, across multiple
cloud accounts and environments.

At Zscaler, our team manages cloud infrastructure spanning AWS
across multiple cells and environments — development, staging,
and production — each with distinct compliance requirements.
I'll share how we evolved from a traditional CSPM point-in-time
scan model to a continuous, event-driven compliance engine that
detects, classifies, and remediates posture violations before
they become incidents.

This talk draws directly from U.S. Patent US11722522B2 (assigned
to Zscaler, co-invented by me) on network security posture
architecture, as well as hands-on experience contributing to
CIS Benchmark definitions and building automated compliance
pipelines on AWS.

Ankit Rao

Senior Software Engineer, Zscaler

Bengaluru, India

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top