thefullstackciso.com
Security, shipped
Vol. I — No. 1Falls Church, Va.Sunday, August 16, 2026Price: free, always

about the editor

The Full Stack CISO

A security leader who still writes the code, thinking out loud.


Portrait of the editor
The Editor

A chief information security officer is accountable for an organization’s security: the strategy, the risk, the compliance, the budget, and the answer the board actually gets. In most places that role lives in policy documents, frameworks, and slide decks, and hands the building to someone else.

A full stack CISO is the same role with the translation layer removed. Someone who sets the strategy and can also read the pull request, threat-model the design, write the query against the logs, and ship the patch before the CVE drops. Not because a CISO should do all of that, but because being able to means you are never guessing about what your own systems really do.

Who writes it

Rajat has spent nearly two decades in IT and security, more than a decade of it architecting cloud security at national scale. At Amazon Web Services he co-designed the two-layer encryption behind Login.gov, protecting 180 million-plus accounts and 730 million-plus annual sign-ins across every U.S. Cabinet agency, private even from privileged insiders. He co-authored the AWS Security Blog’s defense-in-depth guide to securing Amazon S3, a Best of 2018 post, and served as a technical editor on McGraw-Hill’s AWS Security Specialty exam guide. Today he is CISO of a multi-tenant AWS SaaS serving 97 countries.

This paper is a personal notebook. The opinions here are his own and not the position of any employer, past or present.

Why this exists

The most honest thing a security writer can publish is real work: a decision actually made, under real constraints, and what it cost. Every dispatch here comes from a system that shipped, usually on a free tier, usually with more traffic than budget. The postmortems are mine. The fixes I did not ship are here too.

selected work & recognition
  • Co-designed the two-layer encryption behind Login.gov — 180M+ accounts, 730M+ annual sign-ins across every U.S. Cabinet agency, private even from privileged insiders.
  • Co-authored the AWS Security Blog defense-in-depth guide to securing Amazon S3 (a Best of 2018 post); built GuardDuty threat-feed and WAF filtering tools adopted as official AWS open-source samples.
  • Technical editor, McGraw-Hill AWS Security Specialty and AWS Developer Associate exam guides.
  • Advised on eight published SANS GIAC Gold papers; contributor to the ISAO 300-2 threat-intelligence-sharing standard.
  • Judge, ISACA Global Achievements Awards; Vanta “25 to Trust” awardee for identity security.
credentials
Executive & governance
CISSP · CISM · Boardroom QTE · HITRUST CCSFP
Cloud & offensive
AWS Solutions Architect Professional · AWS DevOps Engineer Professional · AWS Security Specialty · GIAC GPEN · CEH
Education
M.S. Computer Science, The George Washington University · B.S. Computer Science, Michigan Technological University
colophon · how this paper is made

This paper is built the way it argues you should build. Static HTML rendered by Astro and served from Cloudflare’s edge. A strict Content-Security-Policy with no inline scripts, self-hosted fonts, no third-party trackers, and no cookies you did not ask for. You can check the headers yourself on the posture page, and the security.txt is where it should be. If a security blog cannot hold its own grade, why trust its advice?

verify me