Curriculum Vitae
Independent Systems & AI Security
Anish Varma
Systems & AI/ML Security Researcher
Security researcher and founding engineer focused on AI/ML systems, offensive security, and trust-boundary analysis. Specializing in mechanistic interpretability, model alignment, cgroups/eBPF sandboxing, and autonomous agent safety. Proven track record of high-severity coordinated vulnerability disclosures and formal systems research.
Founding Engineer
SecNode- Architecting autonomous offensive security execution pipelines and multi-agent workflows using LangGraph and model-routing abstractions.
- Engineering container isolation boundaries using minimal cgroups cgroupv2 configurations and eBPF network socket filters to enforce rigorous sandboxing of untrusted tool execution.
- Developing automated vulnerability auditing modules with custom parser analyzers to detect and flag trust-boundary escalation risks in runtime nodes.
Independent Security Researcher
AI & Distributed Systems Research- Isolated safety-refusal representation subspaces in Qwen-3.5 residual stream layers; coordinate-disclosed low-rank abliteration techniques with zero capability degradation.
- Discovered and patched CVE-2026-40281 (Critical CVSS 9.8 container socket escape / RCE) in autonomous agent orchestration frameworks via coordinated vulnerability disclosures.
- Identified and securely reported high-severity XML Entity Expansion / Billion Laughs vulnerabilities to NASA's Vulnerability Disclosure Program via Bugcrowd.
Technical analysis isolating safety-refusal pathways in the late transformer residual stream layers and projecting out refusal steering vectors via targeted weight orthogonalization.
Academic exploration modeling non-deterministic privilege escalation vectors, dynamic tool introspection abuses, and context-pollution exploits inside autonomous agent orchestrators.
SecNode API Pentester
AI-augmented schema-driven microservices auditor focused on automated OpenAPI ingestion, multi-stage fuzzing pipelines, and authorization-bypass discovery.
Kai Agent Framework
High-performance Rust-based defensive scanner executing offensive vulnerability assessments inside strict eBPF containment boundaries.
PurgeProof
Cross-platform block-level data sanitization engine built to comply with NIST SP 800-88 Rev.1 secure erasure and auditable reporting standards.