Cybersecurity professional · AI security researcher · Author · Speaker

Secure the systems.
Shape what’s next.

I’m Ravindra Annam. For more than 20 years, I’ve worked across application and API security, cloud platforms, threat modeling, DevSecOps, incident response, and data protection. Today I also research how to secure AI agents as they act across those systems.

20+ years in cybersecurityResearch · Writing · SpeakingPlano, Texas
Teal and blue pathways crossing a network of security boundaries
Selected work & serviceCSO OnlineVentureBeatPeer-reviewed researchISC2SANS
About

Experience across the security landscape.

My career spans secure architecture, product and application security, cloud, web and APIs, and security operations. I connect technical controls with practical decisions that engineering and business teams can use.

My current research examines what changes when AI systems can call tools, access sensitive data, and delegate actions. Through writing, speaking, mentoring, and community review, I share approaches to both established and emerging security challenges.

Illustration of distinct AI agents coordinating across connected tools within visible boundaries
Focus areas

Application and API security, cloud security, DevSecOps, threat modeling, logging and response, data protection, and agentic AI security.

AI securityThreat modelingAppSecCloud securityDevSecOpsIncident response
Research & frameworks

Map the authority.
Control the action.

Research on how untrusted influence can cross into privileged agent behavior, and the controls needed at execution time.

Peer-reviewed research · 2026

Runtime Authority-Aware Threat Modeling for Agentic AI Systems

A framework for intent, context, authority, tool capability, memory, delegation, and action composition.

Read the paper ↗
Technical report · 2026

The AI Runtime Threat Matrix

A threat taxonomy and control framework for autonomous agent systems, including the RAAI runtime control loop.

View report ↗
Research direction

RAAI Runtime Security Model™

Continuous assessment, authorization, action, and audit for systems whose authority changes through a workflow.

Explore framework ↗
Threat modeling

Agentic AI Runtime Attack Tree

Tracing attack paths through prompts, context, memory, tools, APIs, permissions, and downstream actions.

Research overview ↗
Enterprise practice

ANNAM Framework

Architecture, runtime protection, monitoring, and governance controls for enterprise AI systems.

Research overview ↗
Broader cybersecurity practice

Security across the
whole technology stack.

My work spans secure design and engineering for enterprise products, cloud platforms, web and API ecosystems, and the software delivery lifecycle.

Application & API security

Secure architecture reviews, threat modeling, web and API risk, vulnerability prevention, and practical controls built into product development.

Cloud & platform security

Security design for AWS and Azure environments, cloud-native services, identities, workloads, and the connections between enterprise systems.

DevSecOps & vulnerability management

Embedding security into delivery through SAST, DAST, software composition analysis, container testing, risk-based triage, remediation, and verification.

Threat modeling & secure architecture

Mapping how attackers reach assets and abuse trust boundaries, then translating findings into design decisions teams can implement.

Security monitoring & incident response

Designing useful logging and telemetry, detecting abnormal behavior, investigating incidents, containing impact, and strengthening controls after recovery.

Data protection & privacy controls

Protecting sensitive data with classification, data loss prevention, least-privilege access, and encryption at rest and in transit across applications and cloud services.

Selected writing

From architecture
to operations.

Research and practitioner writing on the decisions security teams face as AI agents enter production.

ACM Queue · Forthcoming

Running an Agentic Threat Model

Accepted for publication and scheduled for October 8, 2026. A practitioner approach to agent behavior, tools, authority, and runtime controls.

Scheduled
VentureBeat · Aug 2026

AI agents need their own identity before they need a gateway

Why attribution and task context have to travel with an agent’s actions.

Read ↗
CSO · Aug 2026

The first 24 hours of an AI agent security incident

A response playbook for containment, blast radius, investigation, and recovery.

Read ↗
CSO · Aug 2026

Practical lessons from deploying AI securely at scale

Enterprise controls for AI systems operating inside real workflows.

Read ↗
Speaking

Make the risks concrete.

Sessions for engineers and security leaders on agent attacks, runtime controls, and practical security architecture.

Accepted · October 13, 2026 · Online

ConfusedPilot: Breaking Delegated Authority Across AI Agents and Tools

[re]aligned, the online extension of CanSecWest. An accepted presentation on tracing, limiting, and revoking delegated authority across agent workflows.

Event ↗
Upcoming · October 9, 2026

Breaking AI: Real-World Attacks & Defenses for Agentic AI Systems

University of Texas at Dallas · Richardson, Texas

Official event ↗
July 2026

Securing AI Agents: Guardrails and Runtime Controls for the Autonomous Enterprise

ISC2 Think Tank · Speaker and panelist

Session details ↗
Topics

Talks grounded in real workflows

Agent identity and authorization · Prompt injection and tool abuse · AI incident response · Threat modeling autonomous systems.

Discuss a session ↗
Professional service

Review. Judge. Contribute.

Technical evaluation and community work across research, professional content, awards, standards comments, and open-source security practice.

Judging

SANS SIFT Find Evil! AI Hackathon

Industry judge for AI and cybersecurity work.

View event ↗
Editorial & awards

ISACA reviewer

Article Reviewer, 2026–2027, and reviewer for the 2027 Global Achievement Awards and Hall of Fame.

View contributions ↗
Research & community

Peer review and AI security initiatives

Journal of Cybersecurity Education, Research and Practice reviewer; contributions to OWASP generative AI security initiatives.

View contributions ↗
Peer review · 2026

NeurIPS JUDGe workshop

Completed formal reviews for the workshop on reliable evaluation for language models.

Review activity completed
Open source · 2026

Runtime authority conformance

Contributed delegated-authority invariants, an independent resolution-semantics runner, and adversarial test cases across A2A and ERDL work. Related conformance tests were merged.

View merged work ↗
Standards engagement · 2026

NIST technical comments

Submitted comments on draft cybersecurity and AI guidance, including NIST IR 8613. Comments are under consideration.

Public-comment contribution
Connect & follow

Let’s build more secure systems.

For cybersecurity and AI security research, speaking, technical discussion, or professional service, connect with me on LinkedIn. Follow The Security Frontier for commentary on AI security and enterprise cyber risk.