Vikram Das

Cloud and enterprise security architect. I design the security architecture of large, regulated estates — and the governance that keeps it standing after I leave.

Metro Atlanta, Georgia

What I do

I work on the parts of security architecture that have to survive contact with a real organization: multi-account cloud landing zones, identity and access design, encryption and key management, and the review boards and standards that decide what gets built. Most of my career has been spent on estates measured in billions of dollars and hundreds of systems, where the hard problem is rarely the control itself — it is making the compliant path the fast path, so that engineering teams adopt it instead of routing around it.

Recent work centres on three areas: cloud security architecture and governance at scale; post-quantum readiness, including cryptographic inventory and the transition planning most enterprises have not yet started; and the security and governance of AI systems, which I treat both as a discipline and as a daily practice.

Stated plainly, because it matters in this field: AWS at deep implementation level, Azure at architecture-review level, GCP at working knowledge. Containers and Kubernetes at review level.

Selected outcomes

Antifragile Cybersecurity

Antifragile Cybersecurity is my independent advisory practice. The name is borrowed from Nassim Taleb's idea that some systems do not merely withstand stress but improve because of it — which is the standard I think security architecture should be held to, rather than the lower bar of resilience.

The work is architecture and governance rather than implementation: cloud security architecture review, identity and access design, post-quantum readiness assessment, AI security and governance frameworks, and helping organizations build an architecture practice rather than a queue of one-off reviews.

Writing

I publish Cybersecurity, Risk, AI, a newsletter on cloud security architecture, enterprise risk and the practical governance of AI systems. Recent pieces have covered the cryptographic transition to post-quantum standards, why revocation remains the weakest link in the Web PKI, and what a cybersecurity architect interview is actually testing.

Read the newsletter on LinkedIn →

Background

Twenty-five years across enterprise architecture and security, most of it inside large regulated environments — Amazon Web Services Professional Services, General Electric across Power, Aviation and Digital, and Genpact. Thirteen Fortune 500 clients; seventeen GE awards for delivery.

Post Graduate Diploma in Management (equivalent to MBA), All India Management Association. Bachelor of Commerce, University of Calcutta. Higher Diploma in Software Engineering. Stanford University coursework in AI and machine learning (CS221, CS230, CME295). U.S. citizen.

Contact