TOKYO Independent · Freelance & SaaS · Open to US relocation

I build SaaS in security & data.

Independent builder, full-time. Ten years in cloud & data platform security — most recently leading the practice at KPMG Ignition Tokyo — with a long tail of open-source security contributions now living inside Apache, Kubernetes, Google, Microsoft, NASA, NIST, ClickHouse, ESLint, Vue, PyTorch and 60+ other public orgs. Same ten years as a relentless web-scraper too, though Claude now scrapes better than I ever did and I'm fine with that. I build products at the intersection of data and security, ideally both at once. Three are live today: invc.news, discover-onsen.com, and auditly.fyi.

Things I've built on
Azure
Databricks
OpenAI
Kubernetes
Kafka
Python
WordPress
Now · May 2026

Shipping auditly.fyi (compliance-as-code SaaS) · taking on one more cloud-security advisory client · in Tokyo through Q3 · open to senior / staff engineering roles in the U.S.

Live now

Three products shipping in production.

Each one solves a narrow, real problem at the intersection of data and security. All built solo. All running today.

Builder log

Everything else — side projects, OSS, and works in progress.

A decade of side bets across security and data infrastructure. Some made it. Many didn't. Each one taught me something I now use in the next build.

secure-credWIP

Dependabot remediation at scale

OSS · Python

Processes Dependabot alerts so vulnerable dependencies are patched consistently instead of accumulating as tech debt. Targets the #1 supply-chain failure mode.

github.com/arpitjain099/secure-cred
codeql-for-private-reposLive · OSS

CodeQL scanning for private repos

OSS · 2024

Enables GitHub Code Scanning (CodeQL) on private repositories that would normally need a paid Advanced Security seat — lowering the barrier for small teams.

View repo
supply-chain toolkitWIP

Unified OSS supply-chain security toolkit

OSS · in progress

Trivy + Grype + Gitleaks + Trufflehog + CodeQL behind one policy engine. Drops into GitHub Actions or Azure DevOps with one file. SBOM-native (SPDX/CycloneDX), AI-assisted risk scoring.

Coming soon
osint-aggregatorWIP

Multilingual OSINT vulnerability aggregator

OSS · in progress

Pulls advisories from NIST & Vulners.com, enriches via OpenAI, publishes translated bulletins in four languages. For engineering teams that don't read English-first.

Coming soon
py-codescan-2900Archived

Code scanning across 2,900+ Python repos

OSS · 2023 · learning

Large-scale GitHub automation experiment: orchestrate CodeQL scans across thousands of popular Python projects. Didn't mature into a service — but the orchestration patterns I learned still inform every pipeline I build now.

Post-mortem unwritten
+ many moreOngoing

Merged PRs across the open-source ecosystem

Kubernetes · NIST · Azure · Mermaid · Vue · Metasploit · …

Years of small-but-real fixes shipped into the libraries and platforms that power the modern internet. A dedicated page tracks every merge, by org.

See the full list
How I build

Four habits that survive every project.

01

Ship something thin.

The first version is intentionally embarrassing. invc.news launched with one source and one language. The toolkit ships with one CI integration. Iteration beats grand plans.

02

Pipelines, not pages.

I build automated systems, not one-off scripts. If it can run on a cron and not need me, it will. That's how a side project survives a day job.

03

Boring infra, sharp output.

Azure, Python, Postgres, ffmpeg. The interesting bit is what you compose, not what you run — most of my pipelines are five APIs in a trench coat.

04

Open the source.

Most of my tools eventually become OSS. Other people find bugs faster than I do, and the discipline of public code makes the internal version better too.

Background

The decade that built the toolkit.

KPMG

KPMG Ignition Tokyo

DOMAIN LEADER · CLOUD & DATA PLATFORM SECURITY · 2018 — 2026

For seven years I led a small team running detection & response across client cloud environments — about 2,500 alerts a year — and the secure-SDLC programs that prevented half of them from happening in the first place. I've since left to build independently full-time.

  • Key engineer on the 2018 Coinbase $500M hack investigation — on-chain validation via Databricks, Azure Data Factory, Data Lake, and AWS S3. Now KPMG IP across four member firms.
  • Defended a Hong Kong Government client through two UDP-reflection DDoS attacks plus two confidential high-severity incidents.
  • Owned ISO 27001 / 27017:2022 / ISMS documentation — three consecutive successful renewals.
  • Rolled out GitHub Advanced Security across critical workloads; built the SBOM & supply-chain risk register.
  • Hired 7 full-timers and 3 interns from 80+ interviews; represented KPMG at GitHub Universe and the Official Cybersecurity Summit, NYC.
  • Received the 2025 KPMG Ignition Tokyo "MIP — Make the Impossible Possible" award for cybersecurity leadership on a 2023–24 cloud migration program.
Now · 2026 →
Independent — freelance engagements in cloud & supply-chain security while I ship my own SaaS.
Earlier · 2016–2018
SBI BITS — low-latency HFT platform peaking at ~1M trades/sec on Kafka, K8s, Docker, Linux.
Earlier · 2015–2016
Xerox Research Centre India — co-author on a peer-reviewed paper + two USPTO patents.
Education
IIT Kanpur — B.Tech + M.Tech in Computer Science. CGPA 9.2/10 (PG).
Languages
English · Japanese (N4–N3) · Hindi (native).
2025
3 talks · OpenSSF Tokyo
Linux Foundation. Secrets in public repos, AI-era vulnerabilities, OSS incident-response tabletop.
2025
MIP Award · KPMG
"Make the Impossible Possible" — cybersecurity leadership on a major cloud migration.
2014
Charpak Scholarship
Government of France merit scholarship via Campus France for master's-level research.

Want to build something?

I'm open to senior / staff engineering roles in the U.S., advisory work in security and data infra, and collaboration on open-source supply-chain tooling. The shortest path is email.