Security Engineering Leader
Mohit Bansal.
I build and scale security engineering teams that turn reactive, manual programs into automated, telemetry-driven organizations.
01 / About
I'm a security engineering leader with 10+ years building and scaling high-impact teams across cloud infrastructure, detection & response, and application security.
My focus is turning manual, reactive security programs into automated, telemetry-driven ones, cutting risk exposure and shrinking remediation timelines. I've done this at Walmart, Okta, and now Webflow, where I lead Security Engineering across software supply-chain defense, cloud and container vulnerability management, and the endpoint and detection stack.
I care about security that fits how engineers actually build: secure-by-design, metrics-driven, and automated so the safe path is the easy one. I also write and speak about cloud and detection engineering.
What I focus on
- Cloud Security
- Detection & Response
- Application Security
- Vulnerability Management
- Threat Modeling
- Security Org Building
Recognition
- IEEE Senior Member
- AIUC-1 Consortium Member
02 / Experience
-
Webflow Senior Manager, Security Engineering
Lead Security Engineering: software supply-chain defense, cloud and container vulnerability management, and the endpoint and detection stack (EDR, MDM, SIEM).
-
Okta Engineering Manager, Application Security
Scaled automated security scanning across the engineering org and made threat modeling routine, without slowing release velocity.
-
Walmart Sr. Software Engineer, Security
Built automated vulnerability assignment and exposure tooling that turned a flat findings list into routed, owned, SLA-tracked work.
03 / Writing & Research
Published articles, press features, and talks across the security community.
Thought Leadership & Articles
- Jul 2026 We Spent 15 Years Securing the Supply Chain. AI Agents Just Reset the Clock to Zero SecureWorld
- Jun 2026 The AI Vulnerability Surge: Transforming Vulnerability Management The Purple Book Community
- Jun 2026 Audit trails are a feature, not a compliance tax Webflow Blog
- May 2026 The GitHub Breach Wasn't a Fluke, It Was a Preview of What's Coming for All of Us The Purple Book Community
- May 2026 Trusted by Default: The npm Attack Pattern Security Teams Miss SC Media
Featured & Interviews
- Jul 2026 Navigating Telemetry-Driven Security With Mohit Bansal An interview on building telemetry-driven security programs and moving detection and response from reactive to signal-first. HackerNoon
- Jun 2026 When AI Agents Go 'God Mode,' the Security Perimeter Must Move to the Database As AI agents widen database access across the org, enforcement has to move to the data layer itself, not just good faith. The Read Replica
- May 2026 AI Can Speed Up the SOC, But Humans Own the Hard Calls AI is strong on triage, enrichment, and correlation, but humans must own irreversible actions like shutting down services or rotating credentials. The Security Digest
Talks
- Sep 2026 Upcoming When the Package Is the Weapon: Detecting and Responding to npm Supply Chain Intrusions A defender's forensic reconstruction of two real npm supply chain campaigns, covering what standard endpoint telemetry missed and the detection queries and hardening that surface this attack class. Blue Team Con 2026, Chicago
- Sep 2026 Upcoming Securing the Agentic Pipeline: What Cloud Teams Get Wrong About AI Workload Trust Boundaries Speaking at CloudX (API World + AI TechWorld) on trust boundaries in agentic AI workloads. CloudX / API World 2026, Santa Clara
- Aug 2026 Upcoming 89 Seconds to Compromise: Inside npm Supply Chain Attacks and How to Fight Back A practitioner account of incident response during the Nx/s1ngularity and Axios npm breaches, from attacker playbook to the EDR and SIEM detection queries and IR steps that contain them. BSides Las Vegas 2026
- Jul 2026 The Slowest Agent in the Room: Redesigning Defense for a World That Moves at Machine Speed On defending against autonomous AI adversaries that finish a kill chain faster than teams can triage one alert, and automating the SOAR, SIEM correlation, and triage pipeline to keep pace. Tejas Cyber Network (virtual)
- Jun 2026 OWASP Bay Area Spoke at OWASP Bay Area. Bay Area, CA
Research
- Jul 2026 Securing AI Agents in the Enterprise: A Practitioner's Guide A practitioner's guide to deploying AI agents securely in the enterprise, covering agent permissions, governance frameworks, and operational trade-offs. The Purple Book Community
- Dec 2024 Permission Creep in Practice: A Longitudinal Study of Kubernetes RBAC Drift in Production Clusters A longitudinal study of how Kubernetes RBAC permissions drift from their least-privilege design in production clusters, with a model for drift velocity and the controls that curb it. IJCNIS, Vol. 16 No. 5
- May 2023 Rethinking Remediation SLAs: Measuring Exploit Exposure Reduction Under Severity-Based and Risk-Based Vulnerability Prioritization Models Compares severity-based and risk-based prioritization models, showing risk-based approaches deliver greater exploit exposure reduction per unit of remediation effort. IJISAE, Vol. 11 No. 6s