About us

Security engineering, not security theatre

SecAI Solutions is an independent consultancy for organisations building on the cloud and adopting AI. We combine hands-on platform and security engineering with the governance work that makes it defensible.

Mission

Make strong security the path of least resistance

Most organisations do not fail at security because they lack intent. They fail because the secure option is slower, harder or invisible at the moment someone has to choose it. Our work is to change that calculus — by designing controls into the platform, the pipeline and the architecture, so the default behaviour is the safe one.

Vision

Security that keeps pace with how software is now built

Cloud-native delivery and AI have changed the shape of the attack surface faster than most security programmes have adapted. We want to see security practices that move at the same speed as the engineering they protect — automated, measurable, and owned by the teams doing the building.

How we work

Four principles we hold to

These are the things we will not trade away, and the reason engagements with us look the way they do.

Risk before compliance

A control that satisfies an auditor but does not reduce exposure is overhead. We choose controls that would be worth implementing even if nobody were checking — then map them to the frameworks you carry.

Guardrails over gates

Security that depends on people remembering it does not survive contact with a release deadline. We prefer defaults, policy as code and pipeline enforcement to review checkpoints.

Say what we actually know

We distinguish confirmed findings from suspected ones, and we tell you when something is out of scope, uncertain, or not worth your money. Overstated risk is as damaging to a security programme as missed risk.

Leave capability behind

The measure of a good engagement is whether your team can maintain the improvement without us. Documentation, enablement sessions and reusable code are part of the deliverable, not an upsell.

Positioning

Business-aligned, technically grounded

There is a gap in the market between large advisory firms that produce excellent strategy documents without touching the environment, and testing boutiques that find issues without helping fix them. We work in that gap.

In practice, that means the same people who write the roadmap can also open a pull request. We can present a risk position to a board, and we can sit with a platform engineer and refactor an IAM policy. Security decisions get made with an understanding of both the commercial pressure and the operational cost.

We are deliberately small and senior. Engagements are delivered by the consultants you meet, and we take on work where we can be genuinely useful rather than everything we are asked to quote for.

The team

Who you work with

Two senior practitioners with complementary backgrounds — platform and security engineering on one side, offensive security and security governance on the other.

Dev

Principal Consultant — DevSecOps, Cloud & AI Security

Noida, Uttar Pradesh, India

Engineering leader with 13+ years across Site Reliability Engineering, DevOps, cloud infrastructure and security operations, focused on embedding security into how platforms are built, delivered and run.

  • Red Hat Certified Specialist in OpenShift Administration
  • HashiCorp Certified Terraform Associate
  • Securing the Use of Generative AI in Your Organization
  • CHFI | Computer Hacking Forensic Investigator
  • Cyber Forensic Investigation
  • Cyber Law Certification
  • AI in SecOps: Building & Breaking LLMs in Practice
  • Certificate Course in Cyber Law & Digital Ethics

Focus areas

  • DevSecOps & secure software delivery
  • Google Cloud Platform security
  • AWS cloud architecture & security
  • Kubernetes & container platforms
  • Security operations (SecOps) & incident response
  • Compliance automation (SOC 2)
  • Infrastructure as Code & GitOps
  • AI security
  • Site Reliability Engineering
  • FinOps & cloud cost efficiency

Selected experience

  • Currently drives Security Operations and Site Reliability Engineering across Google Cloud Platform for an AI-powered product platform, covering cloud security, DevSecOps, compliance automation and incident response.
  • Progressed from DevOps engineering into Security Operations leadership, building teams and standardising engineering workflows along the way.
  • Contributed to SOC 2 compliance initiatives and security automation.
  • Designed cloud infrastructure, CI/CD pipelines, GitOps workflows and Infrastructure-as-Code solutions across AWS and GCP.
  • Delivered cloud modernisation, Kubernetes adoption, Terraform automation and FinOps initiatives across multiple engineering organisations.
  • Consulting background delivering DevOps and cloud transformation engagements for enterprise clients, including AWS migrations and Kubernetes-based microservices platforms.

Source: Supplied professional profile (LinkedIn export).

Preet Ladhar

Principal Consultant — Application Security, GRC & Security Operations

Toronto, Ontario, Canada

CISSP, CCSP and CISM-certified security engineer whose work spans application security and penetration testing through to running a full cybersecurity programme — risk, compliance, vulnerability management and incident response.

  • Certified Information Systems Security Professional (CISSP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Security Manager (CISM)
  • Cisco Certified Network Associate (CCNA)

Focus areas

  • Application & web security
  • Penetration testing & ethical hacking
  • Secure SDLC and shift-left AppSec
  • Threat modelling & secure design review
  • Governance, risk & compliance (GRC)
  • SOC 2, PCI DSS, ISO 27001, NIST
  • Vulnerability management programmes
  • Incident response & SOC collaboration
  • Cloud Security Posture Management
  • Data loss prevention
  • Third-party / vendor risk
  • Security awareness & phishing simulation

Selected experience

  • Designs, implements and manages cybersecurity programmes, with roadmaps driven by risk assessment, compliance obligations, maturity gaps and incidents.
  • Runs GRC practice covering policy frameworks, risk registers, risk analysis and mitigation, and reporting risk to senior management.
  • Has conducted PCI and SOC 2 compliance gap assessments and worked directly with auditors; familiar with SOC, ISO 27001, NIST and PCI DSS.
  • Built KPI, KRI and KGI dashboards and monthly scorecards to make security programme performance visible to leadership.
  • Matured shift-left practices by embedding AppSec into the SSDLC — threat modelling, secure design reviews, SCA/SAST/DAST pipelines, CI/CD gating and developer training.
  • Runs vulnerability management programmes across network, hosts, containers and endpoints, driving remediation to policy and compliance deadlines.
  • Implemented Cloud Security Posture Management practices to detect misconfigurations, enforce policy and improve cloud compliance.
  • Investigates incidents, validates threats and coordinates response with SOC, privacy and legal teams, working to reduce MTTD and MTTR.
  • Managed end-to-end delivery of 50+ application security assessments as a penetration tester, including infrastructure, application, physical and social engineering testing for global clients.

Source: Supplied professional profile (CV).

A note on the claims made on this site

Consultant biographies, certifications, experience and areas of expertise on this website are drawn from the professional profiles supplied by each individual. Each profile page states its source.

We do not publish client names, logos, testimonials or case studies without written client permission, and none appear on this site at present. Statements about outcomes describe what engagements are designed to achieve — they are not guarantees, and no security engagement can make any system completely secure.

Third-party product, platform and framework names are the property of their respective owners. Their appearance here indicates working experience with the technology and does not imply any partnership, endorsement or accreditation unless explicitly stated.

Work with us

If the way we describe the problem matches how you see it, we are probably a good fit. Start with a conversation.