Ravinder Varuni.

Rajat
Ravinder
Varuni

I co-designed the cryptography behind Login.gov. Amazon shipped two of my published solutions as product features. I certified ISO 27001 on the first attempt with zero nonconformities.

Everything below links to the thing that proves it, and most of that proof was published by somebody other than me.

Role
CISO and Senior Director, Operations
Also
Cryptographer, builder, judge, named inventor
Based
Aldie, Virginia. Washington DC metro.
Now
Carnegie Mellon CISO Executive Certificate, Cohort 27
Find me
LinkedIn   GitHub
01 / Proof

Claims,
with receipts

A resume asserts. This page links. Every source below opens in one click, and none of it was written by me.

180M+
User accounts

The cryptography behind Login.gov

As Security Architect at AWS I partnered with the GSA CISO to design a NIST-peer-reviewed, two-layer cryptographic scheme for Login.gov. It seals each person's data under their own password, so it stays private even from privileged insiders.

Login.gov's own August 2026 program roadmap puts the service at 180+ million user accounts, 500+ million sign-ins a year, 700+ live sites and services, and 54 agencies and states.

Passed
FedRAMP office review

Cloud security at federal scale

I led the TIC 2.0 Overlay pilot as Security Officer at 18F, proving federal systems could meet Trusted Internet Connection requirements while running on native cloud services, assessed against NIST SP 800-53. Run with DHS, Sandia National Laboratories, the FedRAMP office and AWS.

It passed, and I presented the findings at AWS re:Invent 2015. FedRAMP authorizations followed for Login.gov, cloud.gov and vote.gov.

2
Solutions productized by AWS

Amazon built my work into the product

I published geographic filtering for AWS WAF as an official AWS sample. It proved popular enough with Department of Defense and financial services customers that AWS built the capability into the product itself.

My GuardDuty threat-intelligence automation was adopted into Login.gov's live security operations. My S3 defense-in-depth guide ranked eighth of 125 posts on the AWS Security Blog that year, and was cited publicly by Amazon's CTO.

None
Noted
Audit result, 2024 and 2025

The auditors left without a finding

ISO 27001:2022 certified on the first attempt with zero nonconformities, ISOQAR Stage 2 under UKAS accreditation. The 2024 and 2025 cycles across HIPAA, SOC 2 Type II, ISO 27001, GDPR, CCPA and LGPD all closed with results recorded as "None Noted".

I did not build these frameworks from nothing. I inherited them, carried ISO 27001 from the 2013 standard to 2022, took PCI DSS to 4.0.1, and added UKAS accreditation plus the EU, UK and Swiss privacy frameworks, without disrupting a customer or a certification.

89
Control gaps I put in front of my own CEO

Agentic AI, running under live audit

A fifteen-agent security platform runs in production, chaining triage, enrichment, response and case-writing across fifteen accounts, with a budget killswitch. Autonomous endpoint triage closes verified false positives daily under a hard rule that it may never auto-close anything touching credential access, and the SOC 2 reasoning is logged for every run.

I activated the ISO/IEC 42001 AI management control set in June 2025, ahead of demand. Nine months later it answered AI governance gates for two enterprise accounts. An honest self-assessment surfaced 89 control gaps across 17 domains, and I took that number to the CEO rather than burying it.

4 hrs
No customer impact

An AI insider incident, contained the same afternoon

An insider moved company data into an unsanctioned AI tool. It was contained in four hours, with no customer impact and no notification required.

What changed afterwards matters more. It triggered a full AI governance build: every platform AI capability touching customer data inventoried, an AI Use Policy written in-house that superseded the version outside counsel drafted, and org-wide guardrails with a board-approved primary tool.

Vanta, March 2025

Rajat has revolutionized government security, shaping Vote.gov and Login.gov with cutting-edge compliance automation and encryption strategies.

25 to Trust Award citation
02 / Commercial

Security that
speeds deals up

Every security leader calls themselves a business enabler. Here is what that actually looked like, with ticket numbers behind it.

5 days
Down from two weeks

Enterprise security review, cut by more than half

The last two reviews cleared three days ahead of the customer's deadline. A 246-question Cigna diligence pack closed in minutes rather than weeks, with 175 of 218 questions auto-answered from a maintained library.

Internal attribution put first-year deal value at roughly ten times the security tooling spend. Enterprise reviews cleared for Cigna, BT and Centene.

10 days
to zero
Pre-sales response time

The bottleneck was email, so I removed the email

I built sales a self-service trust portal and retired the queue that ran through my inbox. Pre-sales security response went from ten days to immediately available. That is one fewer reason for a deal to stall on my desk.

03 / Recognition

What other
people said

None of this is self-assessment. Two of them are printed objects, and one is a letter on the publisher's letterhead.

The Modern CISO Network Board Book page as carried in the New York Times
The Board Book, carried in the New York Times

Selected for the Board Book

Chosen for the third edition of The Modern CISO Network: Board Book, the directory boards use to find cybersecurity expertise, published by Lacework and carried in the New York Times.

Somebody else decided that list was worth a page in that newspaper. I am on it.

Amazon announced it themselves

I won the AWS re:Invent hackathon in 2014, building an application that identifies features in photographs sent back by the Mars rovers. Amazon posted the result, and the post is still live twelve years later.

Amazon Web Services announcing the re:Invent 2014 hackathon winners
re:Invent 2014, the winners on stage
SANS Technology Institute

The best-written paper on this subject to date.

Stephen Northcutt, then President and CEO
McGraw Hill, Feb 2021

By approaching the content with his relentlessly high standards, Rajat has undoubtedly guaranteed the publication of the best possible content.

Lisa McClain, Senior Editor, McGraw Hill Professional Computing
CISO Series, Aug 2026

I wrote the scenario that split the hosts

My "What's Worse?!" scenario ran on the CISO Series podcast. The hosts disagreed with each other on air, which is the best outcome that segment can produce.

04 / Credentials

Eight badges,
two that matter

All five AWS certifications by December 2016, when fewer than seventy people outside Amazon had done it.

ISC2 CISSP ISACA CISM HITRUST Certified CSF Practitioner GIAC GPEN, Penetration Tester AWS Certified Security, Specialty EC-Council Certified CISO
CEH Boardroom Certified QTE CMU Heinz, CISO Executive Certificate, in progress
The honest read

HITRUST CCSFP and GIAC GPEN are the two that still differentiate at this level: one is the healthcare framework nobody wants to sit through, the other is a hands-on penetration testing exam. CISSP and CISM are table stakes, and I would rather you heard that from me than worked it out yourself.

05 / Published

Writing,
editing, judging

Eleven years deciding what met the bar for publication, and a standards document with a number on it.

Standards

ISAO 300-2

Co-authored a published standard on automating cyber threat intelligence sharing, for the ISAO Standards Organization.

Papers and guides

SANS, AWS, McGraw-Hill

Two SANS whitepapers, the earlier one sole-authored in 2010. Three guides on the AWS Security Blog, two of them shipped with open-source code as official AWS samples. Technical editor on two McGraw-Hill AWS certification guides, and an author of AWS certification examination questions. When the original author of one of those guides left mid-project, I recruited the replacement author team. The publisher's letter says the book would likely not have reached market otherwise.

140k
Members of the body whose highest honours I judged

Judging and peer review

Judge for the ISACA Global Achievement Awards, for an association serving 140,000 professionals across 180 countries, and a Journal reviewer since 2018. Eleven years on the editorial board of the Journal of Information Systems Education and reviewing for the ACM. Academic advisor to a graduate cybersecurity certification program.

06 / Built

I still
ship

A CISO who can read the engineer's pull request, because he has opened a few of his own.

Live on both stores

CertScore and Honor Library

CertScore verifies a credential against the issuer that granted it, rather than taking the claim on trust. Honor Library is book sharing inside trusted circles on a give-economy model. Both are live on the App Store and Google Play. I founded V2C.org, a 501(c)(3), and built and shipped its products.

Patent pending

Named inventor

Named inventor on a pending U.S. patent for third-party verification of digital credential ownership.

2
Production controls I wrote myself

Not a slide deck, a pull request

An AI change-review agent that reads a proposed change's intent and blast radius and returns a rated risk, and secrets-leakage detection wired through the company password manager. Both are running. I wrote both.

07 / Path

How it
went

2026

Carnegie Mellon, Heinz College

CISO Executive Certificate, Cohort 27. Six months, in progress.

2024 to now

CISO and Senior Director, Operations, SuccessKPI

Security, IT, SRE, DevOps and a 24x7 NOC across two continents. Quarterly board reporting, with risk priced in dollars rather than heat maps.

2023

Principal Security Architect, then CISO

SuccessKPI. Two promotions in nineteen months.

2017 to 2023

Security Architect, Amazon Web Services

Login.gov cryptography, GuardDuty automation, WAF geographic filtering. Zero direct reports, and the work reached 180 million accounts.

2015 to 2017

Security Officer, 18F

The TIC 2.0 Overlay pilot. FedRAMP authorizations followed for Login.gov, cloud.gov and vote.gov.

2006 to 2017

Systems, network engineering and IT management

Veris Group, Valiant Solutions, Dataprise, Community Connections, AACAP, Anacomp, University of Maryland Global Campus.

2000 to 2006

Michigan Technological University, then George Washington University

B.S. and M.S. in Computer Science.