VIREN/SHAH

HANDS-ON ENGINEERING LEADER / BUILDER / RESEARCHER

I work where disciplines intersect.

I still design and build software—primarily Python—while also leading engineering and owning work across AI/ML and LLM systems, production platform engineering, security, privacy, compliance, and applied R&D.

> developer + leader + security + infrastructure + AI/ML
BUILDPython · backend · APIs · product · automation
AIRAG · semantic retrieval · LLM systems · agent-framework extensions
OPERATEAWS · Kubernetes · Terraform · cloud-native production
SECUREDevSecOps · SOC 2 · privacy · DPO · AI governance
RESEARCHDARPA · IARPA · program analysis · ontologies

CAREER SIGNAL

Where I spent time vs. where I went deep.

All shows the mix of technical domains within each role.

Focus shows how much of a role a domain occupied; depth / scope reflects technical complexity, ownership, and production consequence.

ROLE COMPOSITION What each job was made of

Segment width represents relative emphasis within that role, not depth of expertise.

01

THE THREAD

Research that survives contact with production.

A recurring part of my work has been tackling challenging problems, figuring out useful approaches, building them, and carrying them through to production—where architecture, operations, security, customer needs, and real-world constraints all matter.

Experience

Selected work and projects

More detail than a two-page résumé, while keeping the projects and technologies that explain the breadth of the work.

BlackBoiler

Director of Engineering, Security and Infrastructure

Arlington, VA

2019–Present

Joined as an early employee and co-lead engineering direction with the CTO. My role spans hands-on software and AI development, product engineering, production infrastructure, security, privacy, compliance, and technical strategy.

Software & AI

  • Remain deeply hands-on, spending roughly half my time writing code—primarily Python—across production services, backend systems, automation, and product capabilities.
  • Built semantic search and RAG for contracts and legal playbooks, including vector/embedding retrieval and dynamic relevance thresholding using gap and Otsu methods for automated contract review and editing.
  • Applied unsupervised clustering to contract sentences for rule development and section classification; developed separate data-augmentation methods to expand and diversify ML corpora.
  • Extended agentic AI/LLM frameworks by modifying agent routing and orchestration to support new tools, workflows, and execution paths.
  • Evaluated and implemented GenAI/LLM infrastructure using MLflow, Bifrost and AWS Bedrock, including model gateways, provider routing, observability, centralized model access, and Bedrock Guardrails.
  • Refactored core services to improve document-processing performance and reliability and developed backend services supporting ML/AI-driven document workflows.

Platform, security & operations

  • Built, operate, and continue to evolve a multi-region AWS platform spanning five EKS clusters using Kubernetes, Terraform and GitHub Actions, with automated failover, redundancy, monitoring, and >99.95% production uptime.
  • Built Python/boto3 deployment automation that reduced client deployment time from approximately one hour to under five minutes.
  • Developed a React/Python operational dashboard integrating EKS, AWS, Cloudflare and Sumo Logic data so Customer Success could deploy and triage client environments independently.
  • Re-architected and rightsized AWS workloads, reducing cloud infrastructure spend by approximately 25%.
  • Embedded security into the SDLC using SonarQube, Snyk, Scout, CrowdStrike and automated compliance controls, moving vulnerability detection earlier and reducing downstream security findings.
  • Initiated and lead SOC 2 Type II across multiple audit cycles and serve as Data Protection Officer, owning privacy practices and incident response while enabling enterprise customers that require formal compliance.

Leidos Innovations Center formerly SAIC

Senior Scientist

Arlington, VA

2011–2019

Led and managed R&D teams, helped propose and shape new efforts, and performed hands-on research and software development across software security, source and binary analysis, machine learning, cyber modeling, software big data and automated software engineering.

DARPA MUSE

  • Principal Investigator for DARPA MUSE Evaluation & Infrastructure, responsible for a ~22 TB software corpus, the analytics infrastructure around it, and cross-team technical evaluation.
  • Created challenge problems and hackathons that exercised the shared corpus and provided concrete technical evaluations of research-team capabilities.
  • Applied machine-learning techniques to identify likely software build methods and dependencies.
  • Developed software for automatically building previously unseen C, C++, Java and Android applications by inferring build methods and dependencies without prior knowledge of their build processes.
  • Spearheaded cross-team collaboration, working groups and shared evaluation activities across the multi-organization program.

DARPA CASE

  • Lead Engineer on DARPA CASE, developing techniques to adapt compiled binaries to new non-functional requirements without source code.
  • Developed a convergent behavior-modeling approach using execution traces, including Angr-generated traces, to characterize program behavior for binary adaptation.
  • Built an ontology for representing non-functional software requirements.

IARPA & internal R&D

  • On IARPA CAUSE, created attack templates for cyber-attack scenarios to model relationships between cyber activity and unconventional sensor data.
  • On IARPA STONESOUP, led analysis of technology gaps in static analysis and dynamic monitoring of Windows binaries.
  • Developed a tool to automatically generate large sets of vulnerable-code test cases for validating software-security research prototypes.
  • Combined static analysis with dynamic analysis/concolic execution for Android applications and developed static-analysis techniques to extract behavioral profiles for malware analysis.
Additional software projects
  • Architected and developed Android applications displaying real-time data using the TENA distributed-simulation protocol.
  • Helped port TENA middleware to Android so Android applications could participate directly in TENA-based distributed-simulation environments.
  • Research developer on an ONR project investigating automated generation of implementation code for network protocols.
  • Led technical working groups and collaborations across multi-company research teams, organizing evaluations, challenge problems and technical roadmaps.

Raytheon CSS formerly Virtual Technology Corporation

Principal Software Engineer / Sr. Technical Advisor / IT Department Head

Alexandria, VA

2005–2011

Worked across internal R&D, product strategy, architecture, developer infrastructure, corporate IT and security, including the technology transition during VTC's acquisition by Raytheon.

  • Served on the Leadership Team and worked directly with the VP of Technology to translate strategic priorities into technology and engineering initiatives.
  • Served as senior technical advisor across software architecture, infrastructure, development practices and security.
  • Created a 2–5 year technology and product roadmap for the company’s distributed-simulation portfolio, connecting customer needs, product strategy, and emerging technical capabilities.
  • Led internal R&D and built prototypes for future product domains—including cyber modeling and simulation—to test new technical and commercial directions.
  • Helped transition internal R&D prototypes and emerging technologies into product-oriented capabilities.
  • Spearheaded infrastructure modernization and virtualization and developed the IT infrastructure security plan.
  • Led the technology migration and integration following Raytheon’s acquisition of VTC, coordinating infrastructure, systems, and engineering-tool transitions while materially reducing integration cost and disruption.
  • Designed and rolled out company-wide engineering infrastructure for issue tracking, documentation, continuous integration, and version control, helping standardize development practices across teams.
Additional work
  • Rearchitected backup/recovery and high-availability infrastructure for critical data and services, driving server reliability above 99.9%.
  • Structured the acquisition-related technology transition to significantly reduce integration costs while enabling a smooth operational transition.
  • Coordinated standardization of development tools and engineering practices across teams following the acquisition.

Cigital formerly Reliable Software Technologies

Senior Research Alchemist / Principal Investigator / Manager

Dulles / Sterling, VA

1997–2005

Led and performed DARPA-, NASA- and NIST-funded software-security R&D, co-managed Cigital Labs, and supported the consulting organization as an SME in security, software analysis and reliability.

  • Researched and developed one of the early automated analysis suites for Java bytecode using static and dynamic analysis techniques for identifying software vulnerabilities.
  • Principal Investigator for a vulnerability scanner that analyzed program executables by reusing source-based pattern-detection engines, extending proprietary technology into a new binary-analysis capability.
  • Project Lead and Co-PI on a $1.8M research program investigating language-based security for resource-constrained Java/J2ME devices; the work produced tools exposing vulnerabilities in the J2ME reference implementation.
  • Project Lead and Co-PI on a $1.6M Aspect-Oriented Programming security effort; led design and implementation of a complete system including an aspect language and weaver.
  • Technical Lead on a $2M software-certification program for e-commerce applications, developing automated vulnerability detection for C and advanced static/dynamic analysis for Java bytecode.
  • Turned research from the software-certification program into technology that became the basis of Cigital’s commercial vulnerability-detection product and contributed to two U.S. patents.
  • Researched a constraint-optimization technique for whole-path analysis of C programs.
  • Performed a security risk assessment of a network-storage product, developed working exploits and traced technical risks through to business impact.
Additional research and consulting
  • Developed a quantitative, product-oriented software-certification methodology for a federal government agency.
  • Performed additional software-security consulting, technical assessments and risk analysis for enterprise and government clients.
  • Architected software configuration-management practices and contributed to secure software-development and IT-infrastructure design.
  • Led research and development teams and managed and mentored junior developers and researchers.
  • Authored and co-authored peer-reviewed publications and technical reports and organized or participated in research workshops and panels.

Visix Software

Software Developer

Reston, VA

1997

Developed components for cross-platform Java development tools, including UI components and networking libraries for application frameworks.

SELECTED TECHNICAL THREADS

Follow the work sideways.

AI / ML

From clustering to RAG and agents

Contract-language clustering and corpus augmentation → semantic retrieval and RAG → agent routing and LLM infrastructure with gateways and guardrails.

Software security

From program analysis to production controls

Static/dynamic analysis, vulnerability research and binary analysis → secure SDLC, cloud security, SOC 2, privacy and incident response.

R&D → product

Build it. Test it. Make it useful.

Cigital analysis research that fed commercial products, VTC prototypes that informed product direction, and BlackBoiler AI work moved into production.

Platform

Own the systems underneath the software

Developer infrastructure and virtualization → large-scale research infrastructure → multi-region AWS/Kubernetes production systems.

Background

Research, engineering and production work.

Education

M.S. & B.S., Computer Science

University of Mississippi

Ph.D. program, Educational Technology — Georgia Tech

Research programs

DARPA · IARPA · NASA · NIST · ONR

Software security, program analysis, software analytics, cyber modeling and automated software engineering.

Patents & publications

2 U.S. patents and peer-reviewed research

Software vulnerability detection, program analysis, robustness, software certification and aspect-oriented security.

LOOKING FOR

Problems with enough depth to need more than one kind of engineer.

Especially where hands-on development, technical leadership, AI/ML, systems, security and applied R&D need to work together.

Start a conversation →