Drumin Gajjar — AI Security Engineer

Securing enterprise AI.
At full speed.

I lead enterprise AI security at MasterControl — building the gateways, guardrails, governance, and detection systems that let teams adopt AI safely.

Drumin Gajjar standing on Main Street in Park City, Utah
Park City, Utah · 2026
Selected work

Case studies, in depth

The work I would want to be judged on — what the problem was, what it had to live with, and what I would decide differently.

Program · MasterControl

Building an enterprise AI security program from zero

Enterprise AI adoption arrives team by team. I own the program that makes it safe at MasterControl — the gateway, the guardrails, the policy, and the training that makes people actually follow it.

One sanctioned path for enterprise LLM traffic, built to be inspected — and the governance to keep it that way.

Read the case study →
Detection engineering · MasterControl

Detecting prompt injection, data leakage, and shadow AI

Three threat classes that do not look like anything in a traditional SIEM. Building coverage means deciding what an attack even looks like when the payload is ordinary English.

A threat model and coverage design for three AI threat classes that conventional detection does not see.

Read the case study →
Platform security · MasterControl

Embedding security into the delivery pipeline

Security review that happens after the code is written is advice. Moving the checks into the pipeline — static analysis at the merge, signature verification at the cluster — turns them into constraints.

Findings move to the merge; image integrity is enforced at the cluster boundary rather than audited after it.

Read the case study →
Cloud security · MasterControl

Turning cloud findings into work someone owns

A finding in a dashboard is not a finding anyone is accountable for. Three pieces of automation that attribute cloud resources at creation, convert policy violations into tracked tickets, and keep the scanner and the issue tracker telling the same story.

Cloud security signals arrive as assigned work with a deadline, instead of as a dashboard someone has to remember to read.

Read the case study →
Approach

How I think about AI security

Chokepoints

Control points, not rules

A policy people have to remember is not a control. I would rather consolidate traffic onto one inspected path and enforce there than write a rule and hope it is followed.

Adoption

The safe path has to be the easy one

Security that adds friction gets routed around, and shadow usage is worse than imperfect coverage. The sanctioned path has to be genuinely better than the alternative.

Evidence

Detection over assurance

A control you cannot observe is a claim. I build the detection and the logging alongside the enforcement, so coverage is something we can measure rather than assert.

Experience

Security operations to AI security, at one company

Three years at MasterControl — from a SOC internship to owning the enterprise AI security program.

2026 — Present AI Security Engineer MasterControl
2025 — 2026 Cloud Security Engineer MasterControl
2024 Security Engineer Intern — Cloud Security & Vuln. Mgmt (FedRAMP) MasterControl
2023 Security Engineer Intern — Security Operations MasterControl

Full experience →