Adesh Gairola

Builder. At enterprise scale.

Sydney · LinkedIn · GitHub · hi@adeshgairola.com

What I do
{
  "profile": "AI security nerd",
  "mission": "return ResponsibleAI();"
}

15+ years putting security between things that move fast and things you can't afford to break. Network. Cloud. Now AI.

I build practices, platforms, and tools at enterprise scale. Always starting from the business outcome, not the security checklist. Not weekend projects.

Three times at increasing scope: 30-engineer APAC team at Cisco. APJ AI Security specialist team at AWS Professional Services that ran a $4M consulting practice plus two products shipped to the AWS customer fleet. Founding team at raxIT today.

Why this — to make powerful AI protection accessible, not just to enterprises with the budget for it.

Currently Selected work

AWS ANZ AI Security Consulting Practice

Built and operated as a $4M business inside AWS Professional Services. $0 to $4M ARR across 150+ enterprise pre-sales engagements spanning financial services, government, resources, telecom, and professional services. Co-built the APJ AI Security specialist team (11 specialists across AU, NZ, Singapore, India, Korea, Japan) that became the region's center of expertise. Defined the AI/ML security review methodology adopted regionally.

Apr 2023 – Dec 2025

AWS Threat Composer · AI threat-modeling framework

Co-authored the AI / agentic-application threat-modeling framework (STRIDE + MAESTRO) adopted by AWS teams through 2024–2025. Productised as part of AWS Threat Composer, AWS Labs' open-source threat-modeling ecosystem.

2024 – 2025

AWS Control Tower · Proactive Controls

Led the project to ship native Proactive Controls in AWS Control Tower (CloudFormation Hooks). Now deployed across the AWS customer fleet, preventing non-compliant resources at policy time rather than detecting after deployment.

Apr 2023 – Dec 2025

Multi-modal content moderation for ANZ enterprise GenAI platforms

Built and shipped the AWS multi-modal content-moderation offering adopted by multiple Tier-1 Australian banks for their centralized internal GenAI platforms. Modular toxicity guardrails with first-class exception handling, fine-tuned across media, telecom, and FSI deployments.

Apr 2023 – Dec 2025

model-scanner · open source

Apache 2.0 Claude Code skill. Runs four independent scanners on ML model files, scores risk 0–100, maps findings to OWASP LLM Top 10 and Australian ISM-2072 (the first government framework to mandate non-executable model formats).


								npx skills add raxITlabs/skills@model-scanner
							

github.com/raxITlabs/skills

Released 2025

GrayZoneBench · open source

Apache 2.0 AI safety benchmark. Tests how frontier models handle tricky gray-zone requests, the kind that sit between "obviously safe" and "obviously refuse." CLI for running benchmarks, web dashboard for exploring results.

github.com/raxITlabs/GrayZoneBench

Released 2025

mcp-oauth-sample · open source

OAuth 2.1 authorization plus an MCP server on Vercel for MCP clients. Real-time analytics and threat detection. Reference implementation for securing the Model Context Protocol ecosystem.

github.com/raxITlabs/mcp-oauth-sample

Released 2025

DirePhish · open source

AI-agent red-team simulator. Hand it your company URL. It clones your team into agents, drops a threat actor into Slack and email, and runs the breach 100 times under regulatory time-bounds (GDPR 72h, insurance 48h). You get a distribution of how your org actually behaves under pressure. Not what the binder says.

Released April 2026

Cisco APAC VPN Security Team

Led 30 engineers supporting AT&T, BT, and Verizon enterprise networks. Built Python and Shell automation that cut MTTR on customer escalations and was adopted across the global TAC.

Jun 2012 – Aug 2017
Writing

Long-form analysis on frontier AI security incidents. A few that landed:

More on LinkedIn, raxIT Labs, and Substack.

How I think Background
Dec 2025 – present Founder & CTO · raxIT
Apr 2023 – Dec 2025 Senior Security Consultant · AWS
Sep 2017 – Apr 2023 Security Consultant · Cloud Architect · Cloud Security Engineer · AWS
Jun 2012 – Aug 2017 SME / Security Customer Support Engineer · Cisco
2009 – 2012 Network Security Engineer · HCLTech · Infosys · vCustomer

Education. B.Tech, Computer Science, College of Engineering Roorkee (2005–2009). Certifications. Cisco CCIE Security · AWS Solutions Architect Professional · AWS Security Specialty · IPv6 Forum Certified Security Engineer. Recognition. OWASP LLM Top 10 contributor.

Connect
if (curious || building || securing) {
  let's_connect();
}

LinkedIn · GitHub · hi@adeshgairola.com

— A