VIREN/SHAH

HANDS-ON ENGINEERING LEADER / FROM RESEARCH THROUGH PRODUCTION

I work where disciplines intersect.

I design and build software while also leading engineering and owning work across AI/ML and LLM systems, production platform engineering, security, privacy, compliance, and applied R&D.

Product engineering Applied AI Platform & infrastructure Security & governance Applied R&D

RANGE & DEPTH

Different parts of my background often change the same engineering decision.

These are examples of where knowing the adjacent discipline changed the design, the operating model, or the path into production.

01

AI · PLATFORM · PRIVACY

One search system with two data boundaries

Legal teams needed one corpus they could reuse across clients without mixing confidential material.

How the range helpedMy search experience pointed toward a common retrieval service. My security and privacy work made the data boundary part of the architecture, and my platform background led to two deployments used together: a shared public corpus and a separate confidential corpus for each client.

Semantic search case study

02

PRODUCT · CLOUD · AUTOMATION

Giving customers a second cloud in six weeks

A client needed BlackBoiler hosted in GCP, while the product had previously run only in AWS.

How the range helpedPlatform experience let me map the full environment across clouds. Security and identity work helped preserve the controls around it, and my development background led me to build testing and regression tooling alongside the Terraform. I had a working automated deployment in six weeks, which showed the client that we could meet its hosting requirement and made the product available to other clients that required GCP.

GCP infrastructure case study

03

RESEARCH · INFRASTRUCTURE · COLLABORATION

Making 22 TB of code usable across a research program

Several research teams needed to analyze the same software corpus using different methods.

How the range helpedMy research background helped me understand what the teams needed from the corpus. Infrastructure and software experience shaped the storage, search, analytics and build services, while program leadership helped us reach agreement on a shared ontology and interfaces. Every team adopted the platform.

MUSE case study

CAREER SIGNAL

Where I spent time vs. where I went deep.

The chart shows how my work was divided across technical domains in each role. The domain buttons serve as the color legend and filters.

Focus reflects how much of the role involved that domain. Depth / scope reflects complexity, ownership, and production responsibility.

Select a domain to compare roles. Select a company to see the work behind it.

ROLE COMPOSITION What each job was made of

Segment width represents relative emphasis within that role, not depth of expertise.

HOW THE RANGE DEVELOPED

Each stage added another part of the system.

The career arc shows when each part of the range entered my work.

1997–200501

CIGITAL / RST

Security research became working software.

I built analysis tools, led funded research, and helped turn research into commercial vulnerability-detection technology.

DevelopmentSecurityR&D
2005–201102

VTC / RAYTHEON CSS

Infrastructure became part of product and technical strategy.

My work expanded into architecture, developer infrastructure, corporate technology, internal R&D, and the technical side of an acquisition.

PlatformStrategyR&DLeadership
2011–201903

LEIDOS INNOVATIONS CENTER

Research programs required shared platforms and cross-team agreement.

I led research teams and built software and infrastructure for work spanning software analysis, machine learning, cyber modeling, and software data.

R&DSoftwareDataCollaboration
2019–PRESENT04

BLACKBOILER

The domains now meet in one SaaS product.

I work across software and AI development, engineering leadership, production infrastructure, security, privacy, compliance, and technical strategy.

ProductAI/MLPlatformSecurityGovernance
Read the detailed work history

Experience

Selected work and projects

More detail than a two-page résumé, while keeping the projects and technologies that explain the breadth of the work.

BlackBoiler

Director of Engineering, Security and Infrastructure

Arlington, VA

2019–Present

Joined as an early employee and work with the CTO to set engineering direction. My role spans hands-on software and AI development, product engineering, production infrastructure, security, privacy, compliance, and technical strategy.

Software & AI

  • Spend slightly over half my time writing code—primarily Python—across production services, backend systems, automation, and product capabilities.
  • Built a semantic-search platform with a shared public legal corpus and separate client-confidential corpora, including vector retrieval, batch and asynchronous ingestion, corpus analytics, and an MCP interface for AI tools.
  • Built a Python service that uses multiple statistical methods to select similarity thresholds for each legal rule, replacing manual estimates and adding training-data quality diagnostics.
  • Applied unsupervised clustering to contract sentences for rule development and section classification; developed separate data-augmentation methods to expand and diversify ML corpora.
  • Extended and hardened an existing multi-agent platform for contract workflows by adding tools, execution paths, model-provider support, authentication, request isolation, scope controls, tracing, and cost attribution.
  • Evaluated and implemented GenAI/LLM infrastructure using MLflow, Bifrost and AWS Bedrock, including model gateways, provider routing, observability, centralized model access, and Bedrock Guardrails.
  • Refactored core services to improve document-processing performance and reliability and developed backend services supporting ML/AI-driven document workflows.

Platform, security & operations

  • Built, operate, and continue to evolve a multi-region AWS platform spanning five EKS clusters using Kubernetes, Terraform and GitHub Actions, with automated failover, redundancy, monitoring, and >99.95% production uptime.
  • Evolved Python/boto3 provisioning scripts into a guided deployment service that coordinates an 18-step AWS, identity, data-service, Helm, and ArgoCD rollout with dry runs, preflight checks, and resumable background work.
  • Built a multi-cluster operations dashboard integrating EKS, CloudWatch, Prometheus and DocumentDB data so teams could inspect nodes, pods, logs, resource use, and cluster history in one place.
  • Built a self-service signup and resumable provisioning workflow spanning Cloudflare and AWS, with distributed locking, retry-safe handoffs, service authentication, and entitlement setup.
  • Re-architected and rightsized AWS workloads, reducing cloud infrastructure spend by approximately 25%.
  • Embedded security into the SDLC using SonarQube, Snyk, Scout, CrowdStrike and automated compliance controls, moving vulnerability detection earlier and reducing downstream security findings.
  • Initiated and lead SOC 2 Type II across multiple audit cycles and serve as Data Protection Officer, owning privacy practices and incident response while enabling enterprise customers that require formal compliance.

Leidos Innovations Center formerly SAIC

Senior Scientist

Arlington, VA

2011–2019

Led and managed R&D teams, helped propose and shape new efforts, and performed hands-on research and software development across software security, source and binary analysis, machine learning, cyber modeling, software big data and automated software engineering.

DARPA MUSE

  • Principal Investigator for DARPA MUSE Evaluation & Infrastructure, leading a roughly 22 TB software corpus and the shared search, metadata, analytics, build, cloud, and evaluation services used across the program.
  • Ran cross-team working groups that shaped shared ontologies and infrastructure, developed software that inferred how to build previously unseen C, C++, Java, and Android projects, and organized common challenge problems and hackathons.

DARPA CASE

  • Lead Engineer on DARPA CASE, developing techniques to adapt compiled binaries to new non-functional requirements without source code.
  • Developed a convergent behavior-modeling approach using execution traces, including Angr-generated traces, to characterize program behavior for binary adaptation.
  • Built an ontology for representing non-functional software requirements.

IARPA & internal R&D

  • On IARPA CAUSE, created attack templates for cyber-attack scenarios to model relationships between cyber activity and unconventional sensor data.
  • On IARPA STONESOUP, led analysis of technology gaps in static analysis and dynamic monitoring of Windows binaries.
  • Developed a tool to automatically generate large sets of vulnerable-code test cases for validating software-security research prototypes.
  • Combined static analysis with dynamic analysis/concolic execution for Android applications and developed static-analysis techniques to extract behavioral profiles for malware analysis.
Additional software projects
  • Architected and developed Android applications displaying real-time data using the TENA distributed-simulation protocol.
  • Helped port TENA middleware to Android so Android applications could participate directly in TENA-based distributed-simulation environments.
  • On ONR AGNES, helped design an ontology-backed code-generation system that produced a working C implementation of a RIPv2 daemon and represented CWE detection and mitigation requirements as inputs to secure generation.
  • Led technical working groups and collaborations across multi-company research teams, organizing evaluations, challenge problems and technical roadmaps.

Raytheon CSS formerly Virtual Technology Corporation

Principal Software Engineer / Sr. Technical Advisor / IT Department Head

Alexandria, VA

2005–2011

Worked across internal R&D, product strategy, architecture, developer infrastructure, corporate IT and security, including the technology transition during VTC's acquisition by Raytheon.

  • Served on the Leadership Team and worked directly with the VP of Technology to translate strategic priorities into technology and engineering initiatives.
  • Served as senior technical advisor across software architecture, infrastructure, development practices and security.
  • Created a 2–5 year technology and product roadmap for the company’s distributed-simulation portfolio, connecting customer needs, product strategy, and emerging technical capabilities.
  • Led internal R&D and built prototypes for future product domains—including cyber modeling and simulation—to test new technical and commercial directions.
  • Helped transition internal R&D prototypes and emerging technologies into product-oriented capabilities.
  • Spearheaded infrastructure modernization and virtualization and developed the IT infrastructure security plan.
  • Led the technology migration and integration following Raytheon’s acquisition of VTC, coordinating infrastructure, systems, and engineering-tool transitions while materially reducing integration cost and disruption.
  • Designed and rolled out company-wide engineering infrastructure for issue tracking, documentation, continuous integration, and version control, helping standardize development practices across teams.
Additional work
  • Rearchitected backup/recovery and high-availability infrastructure for critical data and services, driving server reliability above 99.9%.
  • Structured the acquisition-related technology transition to significantly reduce integration costs while enabling a smooth operational transition.
  • Coordinated standardization of development tools and engineering practices across teams following the acquisition.

Cigital formerly Reliable Software Technologies

Senior Research Alchemist / Principal Investigator / Manager

Dulles / Sterling, VA

1997–2005

Led and performed DARPA-, NASA- and NIST-funded software-security R&D, co-managed Cigital Labs, and supported the consulting organization as an SME in security, software analysis and reliability.

  • Researched and developed one of the early automated analysis suites for Java bytecode using static and dynamic analysis techniques for identifying software vulnerabilities.
  • Principal Investigator for a vulnerability scanner that analyzed program executables by reusing source-based pattern-detection engines, extending proprietary technology into a new binary-analysis capability.
  • Project Lead and Co-PI on a $1.8M research program investigating language-based security for resource-constrained Java/J2ME devices; the work produced tools exposing vulnerabilities in the J2ME reference implementation.
  • Project Lead and Co-PI on a $1.6M Aspect-Oriented Programming security effort; led design and implementation of a complete system including an aspect language and weaver.
  • Technical Lead on a $2M software-certification program for e-commerce applications, developing automated vulnerability detection for C and advanced static/dynamic analysis for Java bytecode.
  • Turned research from the software-certification program into technology that became the basis of Cigital’s commercial vulnerability-detection product and contributed to two U.S. patents.
  • Researched a constraint-optimization technique for whole-path analysis of C programs.
  • Performed a security risk assessment of a network-storage product, developed working exploits and traced technical risks through to business impact.
Additional research and consulting
  • Developed a quantitative, product-oriented software-certification methodology for a federal government agency.
  • Performed additional software-security consulting, technical assessments and risk analysis for enterprise and government clients.
  • Architected software configuration-management practices and contributed to secure software-development and IT-infrastructure design.
  • Led research and development teams and managed and mentored junior developers and researchers.
  • Authored and co-authored peer-reviewed publications and technical reports and organized or participated in research workshops and panels.

Visix Software

Software Developer

Reston, VA

1997

Developed components for cross-platform Java development tools, including UI components and networking libraries for application frameworks.

CONTACT

Interested in the work behind the résumé?