Security Engineering Β· Vulnerability Research Β· Detection Engineering Β· AI Infrastructure
I work across the boundary between how systems fail and how defenders detect that failure.
On the research side, I audit source code in AI infrastructure, container runtimes, cloud integrations, and security-sensitive backend systems. That work has led to published vulnerabilities, Google VRP findings, coordinated disclosures, and upstream security fixes.
On the defensive side, I build controls that are tested end to end rather than treated as configuration: detection logic, controlled triggering, incident generation, investigation evidence, false-positive measurement, and deployment as code.
More recently, those two sides have started to converge in my work: security tooling and detection systems that combine source-level analysis, operational telemetry, reproducible engineering, and ML where it improves the security workflow.
Open-source ML network-flow detector that turns unlabeled CICFlowMeter-compatible traffic into deterministic analyst-facing security incidents.
The v0.1 release includes a frozen temporally validated model, causal feature pipeline, deterministic incident aggregation, versioned incident-v1 output, Python CLI, Docker distribution, real-model end-to-end regression, and public CI.
The project is intentionally explicit about its limits: usable as a research/evaluation product, but not presented as production-ready.
- GHSA-7gwp-5pfp-969j β MLflow, Critical: unauthenticated full-read SSRF through redirect and DNS-rebinding weaknesses in webhook delivery.
- CVE-2026-46517 / GHSA-9xq9-36w5-q796 β vulnerability in
lmdeploy, an AI model inference server, resolved through coordinated disclosure. - Google Cloud VRP award β SSRF, API-key disclosure, and response forgery through a per-request
baseUrloverride affecting Gemini and Vertex AI client paths. - llm-serving-security β security reference for the LLM serving stack, covering vulnerability classes and hardening across vLLM, Triton, lmdeploy, SGLang, BentoML, Ollama, and TGI.
azure-sentinel-detection-engineering
Detection-as-Code on Microsoft Sentinel and Defender: KQL detections mapped to MITRE ATT&CK, controlled triggers, incident generation, investigation evidence, false-positive measurement, and PR-gated deployment through GitHub Actions and OIDC.
Merged security and hardening work across projects including:
- Google gVisor
- Kubernetes
- Firecrawl
- Azure Sentinel
- Swift Package Manager
- OSV-Scanner
- Tink
The work spans container hardening, validation boundaries, race conditions, crash handling, sandbox behavior, shared-memory security, SSRF defenses, and protocol/API behavior.
Coordinated disclosure experience includes GitHub Security Advisories, Google VRP, Microsoft MSRC, and CERT/CC VINCE.
Hands-on work spans cloud, endpoint, identity, and network telemetry:
- Microsoft Sentinel, Defender XDR, Defender for Endpoint, Entra ID
- KQL, Sigma, MITRE ATT&CK
- Security Onion, Suricata, Zeek, Wazuh
- Elastic / Kibana
- pfSense
- Windows Server / Active Directory
- Python and PowerShell
I have also worked through live red-team / blue-team engagements involving segmented WAN/DMZ/LAN environments, IDS/IPS, firewall policy, honeypots, incident response, and maintaining service availability under sustained attack.
- Vulnerability research: source-level analysis of AI infrastructure, cloud integrations, container boundaries, and security-sensitive backend systems.
- Detection engineering: tested detections, Detection-as-Code, SIEM/XDR engineering, and operational signal quality.
- AI infrastructure security: model-serving systems, inference infrastructure, isolation boundaries, and attack surfaces created around AI workloads.
- Security tooling: reproducible systems that connect detection, program analysis, automation, and ML without hiding the evidence behind the result.
- Security & compliance engineering: SOC 2, ISO 27001, HIPAA, and NIST controls implemented as measurable operational systems rather than policy-only artifacts.
Research
Detection & cloud
Platforms
Open to remote roles and selected technical work in security engineering, vulnerability research, detection engineering, and AI infrastructure security.
Website: ibondarenko.com
LinkedIn: ievgen-bondarenko-b13098241
Email: hi@ibondarenko.com





