I build the systems that decide whether a device can be trusted.
13+ years in backend and cloud engineering. I currently lead engineering for IBM MaaS360 Mobile Threat Defense (MTD) — real-time protection for iOS and Android against device, network, and app-level threats, integrated into MDM/UEM, SIEM, and IAM workflows.
01 / About
From Windows agents to cloud-native risk pipelines
I joined IBM India Software Labs in 2019 as a backend engineer on MaaS360, IBM's Unified Endpoint Management and Security platform — starting on Windows patch management and device policy, then moving deep into C# and the Windows Agent itself. Since 2021 I've led engineering for Mobile Threat Defense (MTD), MaaS360's real-time protection layer against device threats (jailbreak/root, disabled passcode or encryption), network threats (man-in-the-middle, rogue Wi-Fi, SSL attacks), and app threats (malware, rootkits, sideloaded apps) — plus OS vulnerability and patch management, all surfaced through dashboards and reporting, and wired into customers' existing MDM/UEM, SIEM, and IAM stacks.
Along the way I've built the SDK that connects MaaS360 to AWS-hosted OpenSearch, led the team's migration onto Red Hat OpenShift, and shipped features — like real-time device quarantine — that are now core to how the product handles active threats. Outside of IBM, I spent five years leading telecom delivery at Comviva and building CMS platforms at Antly Logistic. I write occasionally about Windows security internals and mobile threat defense, and I'm looking at what's next: senior backend or platform-engineering roles, remote-friendly.
02 / Experience
Where I've built
- Lead the Mobile Threat Defense (MTD) engineering team for MaaS360, covering real-time device, network, and app-level threat protection for iOS and Android — owning technical direction, delivery, and mentoring; grew from individual contributor into team lead.
- Built the SDK connecting MaaS360 to an AWS-hosted OpenSearch cluster, powering the Security Dashboard across 29 risk parameters; it became the standardized library adopted platform-wide.
- Led migration of the Zero Trust module onto Red Hat OpenShift (OCP/ROSA) and shipped real-time device quarantine for Windows and Android.
- Conceived a Domain Join proof-of-concept later recognized as a patent-worthy innovation; two-time SGR finalist (2023, 2024).
- Replaced MaaS360's BigFix-based patch management with an Opswat-integrated solution after IBM divested BigFix — delivered the full migration in 4 months.
- Designed native Windows Defender policy management within MaaS360's MDM framework.
- First engineer on the team to develop cross-domain expertise in both the MaaS360 backend and the C# Windows Agent.
- Built and maintained a CMS platform powering websites and mobile apps for multiple schools.
- Automated the internal support ticketing workflow, speeding up ticket creation and resolution.
- Led telecom software projects end-to-end as subject-matter expert for customers in Indonesia and Vietnam, including on-site UAT and delivery.
- Built the Campaign Management platform and End-of-Call Notification product used across telecom deployments.
03 / Selected Work
Four projects that shaped MaaS360's security posture
Case studies from six years of Mobile Threat Defense and Windows platform engineering.
OpenSearch SDK & facet library
Designed the API layer and reusable integration library connecting MaaS360 to AWS-hosted OpenSearch, powering the Security Dashboard and Risk Rules engine. Later adopted as the platform-wide standard for OpenSearch access across multiple MaaS360 teams.
BigFix → Opswat patch management
After IBM divested BigFix, led design and delivery of a new Opswat-integrated patch management system for Windows devices — shipped in four months with zero disruption to existing customers.
Real-time device quarantine
Designed and built the quarantine action for Windows and Android (AMAPI) devices, giving administrators the ability to instantly isolate a compromised device from the network.
Domain Join without IT intervention
Built a POC letting standard, non-admin Windows users join a corporate domain without elevated privileges — solving a real onboarding pain point for devices shipped direct from manufacturers. Recognized internally as a patent-worthy innovation.
04 / Writing
Notes on Windows security & mobile threat defense
Deciphering Windows Privileges: Rights, Privileges & Permissions
A walkthrough of how Windows rights, privileges, and permissions differ and interact — grounded in Microsoft's own documentation.
Unlocking the Full Potential of Mobile Threat Defense
Why device permissions are the deciding factor in how effectively MaaS360 Mobile Threat Defense can detect and respond to threats.
@manishpes
Code, experiments, and this site's source.
05 / Skills