// about

About me

I'm Yash Kant. Over four years I've grown from hands-on security analyst to security engineer, working across enterprise endpoint security, security operations, detection engineering, incident response, and automation. Today I own security platforms end-to-end at fleet scale — across Zomato, Blinkit, Hyperpure, and District.

My day-to-day is Microsoft Defender and Sentinel (Advanced Hunting with KQL), Intune, WDAC, Jamf, and Netskope — threat hunting, incident response, insider-threat investigation, and vulnerability management. And when the manual way doesn't scale — triaging every alert, or removing risky software from thousands of endpoints by hand — I build the tooling that does. Automation in service of stronger security, not for its own sake.

A principle runs through everything I ship: read-only by construction. My investigation agents read, correlate, and recommend — they never act on their own. The one write-capable tool is deliberately isolated behind a hard allowlist and dry-run-by-default, so an automation bug can never touch the whole fleet. Separation of privilege isn't bolted on; it's the architecture.

I like the problems others walk away from — insider data-theft cases that span the SIEM, endpoint, CASB, and identity, or client failures that support teams couldn't root-cause. If it's slow, manual, and important, it's a candidate for automation.

// focus areas

Endpoint security & hardeningDetection engineering (KQL)SOC & security automationIncident responseInsider-threat investigationNetskope SSE / CASB / DLPVulnerability management

// education

B.Tech, Computer Science

RBS Engineering Technical Campus

2018 – 2022

// certifications

Netskope Cloud Security Specialist

Netskope

Netskope Administrator Accreditation

Netskope