01 · Advisory
Security advisor
Periodic senior guidance for founders, CTOs and security teams.
- Architecture and threat-model reviews
- Security strategy and technical decisions
- Founder, customer or investor discussions
Fractional security engineering leadership
I work with founders, CTOs and engineering teams at AI, cloud and infrastructure companies that need senior technical security direction—without building an executive role too early.
Embedded leadership system
One owner. Four engineering surfaces. Decisions that hold together.
The moment before the org chart catches up
Enterprise deals now come with security questions your team cannot answer from a policy template.
The CTO is making the security calls because nobody else owns the architecture.
Cloud, Kubernetes and IAM have grown faster than the controls around them.
Agents can reach customer data, tools or infrastructure—and the trust boundaries are still implicit.
A small security team needs senior direction, not another backlog of undifferentiated findings.
A full-time security leader is premature, but waiting another year is no longer credible.
Architecture, not theatre
AWS, GCP, Kubernetes, network architecture and workload isolation.
Secure design, threat modeling and controls that fit the engineering system.
Runtime policy, tool access, sandboxing, MCP and agentic delivery workflows.
IAM, service identity, customer authorization and privilege boundaries.
Material design decisions, preventive controls and technical trade-offs.
The technical evidence and operating discipline behind customer assurance.
A roadmap the team can actually ship, with ownership and sequencing made explicit.
Three ways in
01 · Advisory
Periodic senior guidance for founders, CTOs and security teams.
02 · Primary engagement
Ongoing, embedded leadership that gives security a senior owner.
03 · Scoped
A defined technical problem, investigated deeply and made actionable.
No 90-day discovery theatre
Products, architecture, team, customers and the pressure that made security urgent.
Separate architecture and operating risk from noise, checklists and inherited backlog.
Sequence the few changes that reduce real exposure and unblock the business.
Review designs, make decisions, unblock owners and build controls into delivery.
Communicate decisions, remaining risk and measurable progress to the people who need it.
Why Saransh
Eight years across product, cloud and security leadership roles. I am Head of Security at Composio and founder of Burrow, an agent runtime security platform. The work spans AI agents, multi-cloud architecture, IAM, Kubernetes, application security and the controls around production engineering.
The research is here because technical leadership should be inspectable.
Start with the pressure
A useful first conversation is about the architecture, the customer pressure and what the engineering team needs—not a pitch deck.