I build the thing that notices when something is wrong.
I'm Subhash, a network security and detection engineer in Bengaluru. Most of what I do sits in one narrow band: the gap between a system doing something bad and somebody finding out about it. Detection rules, SIEM plumbing, the tooling that makes an analyst's day shorter. It's unglamorous work and I like it a great deal.
What I actually do
Day job: software engineer at Parivartan Technologies since October 2025, promoted in April 2026. I brought up the company's infrastructure from bare hypervisors: RKE2 Kubernetes across three libvirt/KVM hosts, air-gap capable, provisioned with Terraform and Ansible, with CloudNativePG, Strimzi Kafka, MinIO, cert-manager and Longhorn on top. Then I spent a long time inside a compliance connector framework designing the state machine and capability model that sixteen connectors are built against.
Nights and weekends: open source. Three projects, 79 detection rules and a 28-tool MCP server, all under MIT or Apache 2.0. The through line is that security tooling is far too expensive for the people who need it most. A small water treatment plant cannot write a six-figure cheque to a commercial OT vendor, and it should not have to be blind because of that.
How I think about the work
Detection is a claim, and claims need evidence. A rule that fires on its own test log proves nothing. The half that matters is the benign corpus, traffic engineered to look almost like an attack, which the rule must stay quiet about. My NIST pack ships 57 passing evidence tests for exactly this reason: an alert that an analyst learns to ignore is worse than no alert at all.
Do not overclaim. Every project page on this site has a “scope and limits” section. OT Sentinel has 29 rules; only the 8 Modbus ones are hardware-validated, and I say so in the README, on the project page, and here. Security is a field with an unusually high tolerance for marketing language, and I would rather be the boring, checkable one.
Build for the person on the other end. The question that shaped sb-siem-mcp was never “how do I connect an LLM to Wazuh”. That part is easy. It was “how do I connect an LLM to Wazuh without regretting it.” Rate limits, a confirmation gate on anything destructive, credential redaction before output reaches the model. Capability is cheap; restraint is the engineering.
Away from the terminal
I ride. A Bajaj NS400Z when I want the road to mean something, and a Royal Enfield Classic for the mornings where slow is the entire point. A useful amount of my thinking about a stuck problem has happened on a road out of Bengaluru before the city woke up.
I'm studying Japanese, working towards the JLPT, and aiming at a move to Tokyo. I watch F1 with the specific misery of someone who has picked a driver. There is a page on this site that is nothing but a photograph and a quote about finishing races. You'll find it if you look.
This site
Built like a cabin in a forest, and not by accident. The dark green outside is the woods: the landing, the life page, the chrome. The warm paper you're reading now is the inside: a lit room where the long-form writing lives. You walk in from the dark to read.
Under the hood it's deliberately boring: Next.js exporting to static HTML, five runtime dependencies, plain CSS in one file, content as markdown. No analytics, no cookies, no pop-ups, no newsletter modal at 40% scroll, the privacy page is short because there is genuinely nothing to declare. It should still build in ten years, and if it doesn't, the markdown moves to whatever's next in an afternoon.
Currently
Open to security engineering and DevSecOps roles. If you're hiring, or you have a detection problem that's been annoying you for months, I'd like to hear about it.
Subhash Bharadwaj · Bengaluru, India