~/enjay

Austin, Texas · Electronic Arts

Nilesh Jaiswal

Lead Service Engineer · Platform & Infrastructure

Building scalable cloud platforms, automating infrastructure, advancing zero-trust security — and publishing research that bridges academia and industry.

Portrait of Nilesh Jaiswal
  1. Software Engineer, then
  2. Build Engineer, then
  3. DevOps Engineer, then
  4. Cloud Engineer, then
  5. Platform Engineer, then
  6. Infrastructure Architect, then
  7. SRE, then
  8. Researcher, then
  9. Technology Leader

pipeline: career · 9 stages passed · currently running

About

Two and a half decades of shipping infrastructure

I started my career building and shipping software the hard way — manual releases, customer escalations, midnight fixes. Over 25 years that work evolved through build engineering, DevOps, cloud, and platform engineering at Symantec, Acxiom, Intel, and now Electronic Arts, where I lead service engineering within the Platform, Infrastructure & Engineering organization.

My engineering philosophy is simple: if a human has to do it twice, automate it; if a platform team has to approve it, make it self-service; if security is a gate at the end, move it to the beginning. That philosophy took a 48-hour cluster provisioning runbook to under 2 hours, and it is the thread running through my work on API gateways, certificate automation, and cloud governance.

In recent years the practice turned into research. Five peer-reviewed IEEE papers on zero-trust DevSecOps, shift-left security, agentic-AI identity, risk-adaptive authorization, and trust-coupled elastic scaling came directly out of problems I solved in production. I believe the best infrastructure research is written by people who carry a pager.

Views and research published here are my own and do not represent the position of any current or former employer.

# experience
25+ years

# current focus
API gateways · PKI · cloud governance · agentic-AI security

# education
B.E. Computer Technology, Nagpur University
PGP AI/ML, UT Austin McCombs (2021)

# community
IEEE Senior Member · awards judge · peer reviewer · mentor

Career pipeline

The journey, stage by stage

  1. Jan 2026 → present · Electronic Arts

    Lead, Service Engineering

    Problem
    EA's centralized code-signing infrastructure had systemic protocol-level latency bottlenecks, and platform security/identity initiatives needed dedicated technical leadership across the Service Enablement organization.
    Solution
    Promoted to Lead, Service Engineering; ran a formal root-cause latency analysis of the code-signing infrastructure, drove Certificate-as-a-Service onboarding, and lead onboarding/platform-education programs across the team's core toolchain.
    Impact
    Delivered architecture recommendations to resolve code-signing bottlenecks at scale; elevated to IEEE Senior Member.

    Certificate-as-a-ServicePlatform SecurityMentorship

  2. 2026 · IEEE — ICAISET & SoutheastCon

    Published Researcher & Panelist

    Problem
    Industry zero-trust practice and academic research were evolving in parallel with little cross-pollination.
    Solution
    Published five peer-reviewed IEEE papers (SATHOS, shift-left security, identity fabric for agentic AI, risk-adaptive authorization, HydraScale elastic scaling); panelist at ICAISET 2026 in Cairo on building trusted AI-driven infrastructure.
    Impact
    Research grounded in production-scale platforms it was built on.

    Zero TrustDevSecOpsAgentic AIAuthorization

  3. Jan 2025 → Dec 2025 · Electronic Arts — Platform, Infrastructure & Engineering

    DevOps Engineer III

    Problem
    Provisioning a production OpenShift cluster involved heavy manual effort across multiple production datacenters; certificate lifecycle and API gateway modernization were still early-stage.
    Solution
    Led OpenShift/Kubernetes platform automation toward majority-automated cluster deployment, designed a Kubernetes label/tag governance framework, and automated certificate lifecycle and token rotation.
    Impact
    Reduced manual operational overhead and improved security posture through certificate/token automation; laid groundwork for platform-wide API gateway rollout.

    OpenShiftKubernetesTerraformAnsibleArgoCDHelmKyverno

  4. Oct 2021 → Oct 2024 · Intel Corporation

    Sr. DevOps Engineer

    Problem
    Kubernetes/VM deployment and infrastructure monitoring in dynamic build environments were largely manual and reactive.
    Solution
    Built AI-enhanced deployment frameworks for Kubernetes pods and Azure VMs, Kubernetes operators with KubeBuilder/Go, and AI-powered Prometheus exporters and JIRA-ticketing automation.
    Impact
    Higher infrastructure reliability and developer velocity through predictive, AI-assisted automation.

    AzureKubernetesGoLangPrometheusJenkinsGitHub Actions

  5. 2020 → 2021 · UT Austin — McCombs School of Business

    PG Program, AI & Machine Learning

    Problem
    Bridging two decades of infrastructure practice with formal grounding in AI/ML.
    Solution
    Completed post-graduate AI/ML program while working full time.
    Impact
    Foundation for the agentic-AI security research line that followed.

    PythonMLApplied AI

  6. Sep 2018 → Oct 2021 · Acxiom

    Sr. DevOps Engineer

    Problem
    Data-platform environments across AWS, Azure, and GCP were provisioned inconsistently, with fragmented compliance enforcement.
    Solution
    Built reference architectures and end-to-end Terraform automation; enforced infrastructure compliance via Terraform Cloud and Sentinel policy-as-code; integrated vulnerability scanning via Nexpose.
    Impact
    Repeatable, compliant multi-cloud environments with automated CI/CD frameworks (Jenkins, AWX, Terraform).

    TerraformAWSAzureGCPJenkinsSentinel

  7. Aug 2017 → Sep 2018 · Braves Technologies

    DevOps Engineer

    Problem
    A production application had slow release cycles with little early signal on integration issues.
    Solution
    Built a CI/CD framework with Jenkins and PowerShell DSC-based deployment automation, and led sprint planning and Scrum ceremonies.
    Impact
    Increased release frequency and earlier issue detection during development.

    JenkinsPowerShell DSCCI/CD

  8. Jan 2011 → Aug 2017 · HARMAN International

    Product Architect, Software Engineering

    Problem
    Engineering teams needed a scalable, automated private cloud and streaming-data foundation instead of manual, ad hoc provisioning.
    Solution
    Designed a private cloud architecture on VMware vRealize Automation and AWS EC2, built real-time streaming pipelines (Kinesis, SQS, S3), and automated environment provisioning with Chef and Vagrant.
    Impact
    Client Recognition Award from MSC Software for leading the private cloud modernization and infrastructure implementation.

    AWSChefVagrantJenkinsKinesis

  9. 2004 → 2011 · Symantec & early roles

    Software / Build Engineer

    Problem
    Enterprise release cycles were slow, manual, and fragile — customer escalations demanded fixes in days, not weeks.
    Solution
    Owned build and sustenance engineering at Symantec (VxVM kernel module, installer engineering); supported a prepaid telecom billing platform at CGI and embedded set-top box software at Broadband Pacenet before that.
    Impact
    Standing Ovations Award and Star Award at Symantec for engineering performance and product quality.

    ShellBuild systemsRelease engineering

Technical expertise

Depth, measured in years

Cloud

  • AWS10y · Expert
  • Azure5y · Advanced
  • GCP4y · Proficient

Containers & Platforms

  • Kubernetes8y · Expert
  • OpenShift6y · Expert
  • Docker9y · Expert

Infrastructure as Code

  • Terraform8y · Expert
  • Ansible9y · Expert
  • Helm6y · Expert

CI/CD & GitOps

  • GitLab CI7y · Expert
  • ArgoCD5y · Expert
  • GitHub Actions4y · Advanced
  • Jenkins8y · Advanced

Programming

  • Python12y · Expert
  • Go5y · Advanced
  • Shell20y · Expert
  • JavaScript/TypeScript6y · Proficient

Observability

  • Prometheus6y · Expert
  • Grafana6y · Expert
  • Splunk / ELK7y · Advanced

Security & DevSecOps

  • Zero-Trust Architecture4y · Expert
  • Policy as Code (Kyverno/OPA)4y · Expert
  • PKI / Certificate Automation5y · Expert
  • IAM / RBAC6y · Advanced

Architecture

  • Platform Engineering7y · Expert
  • API Gateways (APISIX)3y · Advanced
  • Microservices8y · Advanced
  • Agentic AI Security2y · Advanced

Research

Peer-reviewed publications

Papers
5
Citations
0
h-index
0
i10-index
0
2026IEEE MLISE 2026 · IEEE

HydraScale: Trust-Coupled Elastic Scaling for Federated CI/CD Pipelines Using Bounded Autonomous Agents

Continuous integration and delivery (CI/CD) pipelines increasingly execute across heterogeneous runner pools spanning standard, regulated, and isolated execution domains. Conventional autoscalers provision capacity using compute signals such as queue depth, CPU, or pending job count, but they ignore whether the target runner domain remains trusted. We define this mismatch as the scaling-security decoupling problem (SSDP): a pipeline controller may admit jobs or scale replicas into a domain whose runtime trust score has degraded below an acceptable threshold, causing unsafe admissions, compliance stalls, or provisioning deadlock. This paper presents HydraScale, a trust-coupled elastic scaling framework for federated CI/CD pipelines. HydraScale combines a four-component runtime trust vector with a three-tier bounded-autonomous control plane that couples queue, capacity, and trust signals before each scale-out, scale-in, or migration decision. We implement HydraScale as a service mesh of seven Python micro-services with Open Policy Agent enforcement, evaluate it against three baselines (static, queue-only predictive, reactive trust) across five scenarios, four scaling systems, and ten random seeds (200 paired runs), and report unsafe admissions, queuing stability, decision latency, and audit completeness. HydraScale admits no unsafe jobs across the five evaluated scenarios versus baseline means of 4.04 (reactive trust) to 204.56 (trust-blind), with Mann-Whitney U p ≤ 2.2 × 10−4 across the test family, p99 decision latency of 17 µs, and complete audit traces in all measured decisions.

Eliminates unsafe job admissions across all evaluated scenarios by coupling trust signals with elastic scaling decisions.

zero-trustCI/CDautoscalingKubernetesSPIFFEOPAagentic AIbounded autonomy

DOI0 citations
2026IEEE ICAISET 2026 · IEEE

SATHOS: Self-Adaptive Trust-Hierarchical Orchestration for Zero-Trust DevSecOps Pipelines

Modern DevSecOps pipelines execute workloads across heterogeneous environments, including cloud runners, on-premises agents, and ephemeral containers, yet orchestration frameworks assume pre-trusted execution agents and rely on static policy gates. This assumption fails under agent compromise, configuration drift, and trust asymmetry between cloud and on-premises zones. We present SATHOS (Self-Adaptive Trust-Hierarchical Orchestration System), a zero-trust orchestration framework that models CI/CD pipelines as trust-governed directed acyclic graphs (DAGs) where each node's execution is conditioned on dynamically evolving four-dimensional trust vectors covering identity, platform, behavioral, and contextual evidence. SATHOS introduces a distributed trust negotiation protocol over mutual TLS with replay protection and cryptographic transcript verification, combined with a self-adaptive trust evolution mechanism that adjusts trust scores based on execution outcomes without requiring policy redeployment. Evaluated on a Kubernetes-based testbed with three pipeline topologies (3-5 nodes), three experimental conditions, and three random seeds (27 runs), SATHOS blocks 100% of compromised agent execution requests with zero false positives (p < 0.001, Fisher's exact test). The five-message trust negotiation protocol adds a median per-node latency of 4.73 ms (p50), and the Wilcoxon signed-rank test confirms bounded overhead (p = 0.065, one-sided). The system achieves zero false allows and zero false denies across all trial configurations.

Framework grounded in production experience automating enterprise Kubernetes/OpenShift delivery at scale.

zero trustDevSecOpsCI/CD securitysupply chain

DOI0 citations
2026IEEE ICAISET 2026 · IEEE

Policy-Driven Shift-Left Security for Hybrid OpenShift CI/CD Pipelines

This paper presented a policy-driven shift-left security framework for hybrid OpenShift CI/CD pipelines that integrates container vulnerability scanning (Trivy), Kubernetes policy enforcement (OPA/Rego with eight denial rules), and governance tag validation into a unified pre-deployment gate. Through a controlled experiment of 50 pipeline builds per configuration, the framework detected and blocked all 15 insecure builds (8 vulnerable images, 5 policy violations, 2 governance violations) while allowing all 35 compliant builds to deploy, achieving a 100% detection rate with zero false positives. The shift-left pipeline introduces a mean overhead of 28.3 seconds per build, with container scanning accounting for 82.2% of the added time. The results demonstrate that early-stage, automated security enforcement can prevent insecure artifacts from reaching production environments without disrupting legitimate workloads. The layered three-gate architecture provides defense in depth across image vulnerabilities, deployment misconfigurations, and governance metadata, addressing a gap in existing CI/CD security research that has focused on individual controls in isolation.

shift-leftpolicy as codeOpenShiftOPA/Regocontainer security

DOI0 citations
2026IEEE ICAISET 2026 · IEEE

Future-Proofing Identity Security for Agentic AI Systems: Design, Implementation, and Evaluation of an Identity Fabric

Agentic AI systems composed of dynamically instantiated, tool-enabled agents operating across trust boundaries introduce identity failures that exceed the assumptions of existing identity and access management frameworks. This paper identifies five identity gaps in agentic AI systems and introduces six composable security primitives that address ephemeral identity, delegation integrity, capability-level control, cross-domain trust, behavioral assurance, and content provenance: Ephemeral Attested Agent Identity (EAAI), Intent-Bound Delegation Tokens (IBDT), Identity-Constrained Capability Sandboxes, Decentralized Agent Identity Registries (DAIR), Continuous Behavioral Attestation, and Content Provenance Binding. We implement the architecture on Kubernetes using SPIFFE/SPIRE workload identity and mutual TLS for all inter-service communication. Across 33 mTLS test cases (n=100 per operation), the system achieved 100% delegation fidelity (20/20 narrowing tests), sub-25 ms mean latency for credential issuance and delegation, and 6/6 abuse-resistance rejections. In an end-to-end pipeline with Claude Sonnet, total identity overhead was 203 ms, representing 2.6% of inference latency.

agentic AIidentityIAMSPIFFE/SPIREworkload attestation

DOI0 citations
2026IEEE SoutheastCon 2026 · IEEE

Risk-Adaptive Authorization for Agentic AI Systems

Agentic AI systems deploy autonomous agents that execute transactions with delegated authority, yet existing authorization mechanisms rely on static role-based policies that are inadequate for contexts varying in risk. Authentication protocols for ephemeral agents include SPIFFE, OAuth Token Exchange, and DPoP, addressing the question of "who is the agent?" This paper extends that foundation to address "what should the agent be allowed to do?" We present an authorization flow combining workload identity (SPIFFE/SPIRE), token exchange (RFC 8693), policy evaluation (Open Policy Agent), AI-based risk scoring, sender-constrained tokens (DPoP), and CIBA-inspired human approval for high-risk transactions. The architecture implements a three-tier authorization model: Tier 1 transactions receive automatic approval, Tier 2 transactions require supervisor-agent approval, and Tier 3 transactions trigger human-in-the-loop verification. We validate the approach through a retail exchange scenario. Measurements across 120 authorization requests show cold-path latency of 32.7 ms (SD = 18.5 ms) and warm-path latency of 4.7 ms (SD = 2.3 ms), a 7x speedup with token caching. Delegation narrowing enforcement blocks all invalid privilege escalation attempts across 20 test cases. The results indicate that risk-adaptive authorization adds acceptable overhead for agentic systems while enabling contextual policy decisions and human oversight for high-risk operations.

authorizationrisk-adaptiveagentic AISPIFFE/SPIREzero trust

DOI0 citations

Analytics

Growth, charted

Publications by year

Average depth by domain (years)

Selected work

Platforms shipped

OpenShift Cluster Automation Framework

Infrastructure

End-to-end automation for provisioning production OpenShift clusters across three datacenters, replacing a 48-hour manual runbook.

  • 48h → <2h provisioning
  • 85% automation coverage
  • EU1 / IAD1 / IAD1-ISO

AnsibleTerraformArgoCDHelmKyvernoGitLab CI

API Gateway Modernization (Apache APISIX)

Platform

Engineering lead and de facto product owner for EA's next-generation API gateway platform, replacing legacy gateway infrastructure.

  • Gateway-as-a-service model
  • Declarative route management

APISIXKubernetesGoGitOps

Certificate-as-a-Service Platform

Security

Headless certificate lifecycle platform with API-first issuance; includes latency analysis and phased re-architecture of a centralized code-signing service handling ~1M requests/day.

  • ~1M signing requests/day analyzed
  • Conduit provisioning integration

Venafi TPPCloud HSMcert-managerEKS

Cloud Account Registry

Governance

Registry and governance layer for cloud accounts with group-based edit permissions and RBAC via a central IAM platform.

  • Group-based permissions model
  • MVP co-led with platform architects

PythonRBACIAM

Custom Terraform Providers

Open Source / IaC

Upgraded and maintained custom Terraform providers for Device42, MAAS, and Infoblox — SDK migrations, linting, and CI/CD pipeline hardening.

  • Three providers maintained
  • SDKv2 migration

GoTerraform Plugin SDKGitLab CI

Slack → JIRA Automation Bot

Developer Experience

Slack bot (Bolt framework) for automated JIRA ticket creation with YAML-driven forms, Redis state, back-navigation, and status cascade logic.

  • YAML-configurable forms
  • Zero-touch ticket routing

PythonSlack BoltRedisJIRA API

VM Tag Management & Chargeback

Observability

vROPs/aROPs tag management system with chargeback reporting, Prometheus metrics export, and Grafana dashboards; NetApp Active IQ alert automation.

  • Automated chargeback reporting
  • Fleet-wide tagging compliance

PythonPrometheusGrafanavROpsNetApp

Professional impact

Measured, not claimed

48h → <2h
OpenShift cluster provisioning time
85%
Automation coverage across cluster lifecycle
~1M/day
Code-signing requests analyzed & re-architected
3
Datacenters migrated (EU1 · IAD1 · IAD1-ISO)
4
Peer-reviewed IEEE papers, 2026
25+
Years in enterprise infrastructure

Speaking · Awards · Credentials

Beyond the terminal

Speaking

  • Building Trusted AI-Driven Infrastructure

    IEEE ICAISET 2026 — Panel · Cairo, Egypt · 2026

  • Peer Reviewer — Medical AI and Deep Learning papers

    IEEE-ICCA 2026 · International · 2026

Memberships

  • IEEE Senior Member #102178087
  • IEEE Peer Reviewer — ICCA 2026 (Medical AI/CT imaging, Computer Vision/Industrial Defect Detection)
  • IEEE Collabratec member — active research community participant

Awards & recognition

  • Judging Panel — Claro® Awards for Tech Excellence

    Claro Awards · 2026

  • Client Recognition Award (from MSC Software)

    HARMAN International · 2011–2017

  • Standing Ovations Award

    Symantec · 2006–2011

  • Star Award

    Symantec · 2006–2011

Certifications & education

  • PG Program in AI & Machine Learning

    UT Austin — McCombs · 2021

    PythonMLApplied AI

Contact

Let's talk platforms or papers

Open to speaking invitations, research collaboration, peer review, and conversations about platform engineering, zero-trust architecture, and agentic-AI security.