Prof. Rohan Sen
MSc, CKA, Terraform Certified

Embeds security into the software delivery lifecycle, with deep expertise in CI/CD pipelines and infrastructure as code.
Professor Rohan Sen is a Professor of DevSecOps and Automation at GICCT, where he teaches organisations and individuals how to build security into software delivery rather than bolting it on at the end. He sits at the intersection of development, operations, and security — a vantage point from which he has helped engineering teams ship faster without sacrificing safety. In an industry that has spent years treating security as the team that says no, he represents a different model: security as an enabler of speed, embedded so deeply in the delivery process that it becomes invisible.
Background and career
Professor Sen came up as a software engineer before moving into platform and infrastructure work, and finally into the emerging discipline of DevSecOps. That trajectory gave him a rare, genuine fluency in all three worlds: he has written production code, run production systems, and secured both. He understands why developers resist security friction, why operations teams fear change, and how to design processes that satisfy security without slowing delivery to a crawl.
He has built secure delivery pipelines for high-growth technology companies, introducing automated security testing, infrastructure as code, and the cultural practices that make security a shared responsibility rather than a final gate. He holds the Certified Kubernetes Administrator credential and is Terraform certified, and he remains hands-on with the toolchains his field depends on, from GitHub Actions and GitLab CI to Terraform, Docker, and Kubernetes.
Areas of expertise
Professor Sen’s expertise covers CI/CD pipeline security, infrastructure as code and its security implications, container security, secrets management, and automated security testing including SAST, DAST, and software composition analysis. He has particular depth in supply-chain security — an area that has moved to the centre of the industry’s concerns as attackers increasingly target the software build process itself.
Beyond the tools, he specialises in the harder problem of organisational change: how to introduce security practices into engineering teams in a way that sticks, rather than being resented and circumvented. He argues that the cultural side of DevSecOps is ultimately more decisive than any single tool, and his teaching reflects that conviction.
Teaching philosophy
Professor Sen teaches security as a natural property of good engineering rather than an external imposition. His courses are intensely practical, built around real pipelines and clusters that students configure, secure, and break themselves. He believes that abstract security principles only become real when students have automated a security check, watched it catch a genuine flaw, and understood how it fits into a delivery workflow.
He places strong emphasis on the “shift-left” philosophy — catching problems early, when they are cheap to fix — and on building feedback loops that make secure choices the easy choices for developers. His students leave able not just to use DevSecOps tools but to advocate for and implement the practices in real engineering organisations.
A practitioner’s perspective
Professor Sen brings a working engineer’s realism to his teaching. He knows that security initiatives fail not because the technology is wrong but because they ignore how engineering teams actually work — the pressure to ship, the friction of new processes, the human tendency to route around obstacles. His courses address this head-on, teaching students not just how to implement security controls but how to introduce them in ways that teams will accept and sustain.
He stays current with a fast-moving field, tracking developments in supply-chain security, the rise of policy-as-code, and the security implications of the platform-engineering movement. He shares these not as abstract trends but as practical considerations his students will face in their own organisations, helping them anticipate where the discipline is heading rather than just where it stands today.
At GICCT
At the institute, Professor Sen leads the DevSecOps Engineering program and contributes to the container and cloud security curriculum. He is a passionate advocate for the idea that security and speed are not opposites — that done well, security automation actually accelerates delivery by catching problems before they become expensive. For developers and operations professionals looking to move into security, or security professionals needing to understand modern delivery, his courses offer a bridge grounded in genuine engineering practice.