Rajesh Sharma
Co-Founder & Chief Architect · AttackIQ
Rajesh Sharma is co-founder and Chief Architect of AttackIQ, the Los Altos company whose platform continuously attacks its customers' own security controls to prove whether they actually work. He spent more than twenty years before that as a principal engineer and software architect writing kernel-level security code at Websense, Guidance Software and Resolution 1 Security.
Last reviewed: Sep 19, 2026
Rajesh Sharma
Co-Founder & Chief Architect AttackIQ
Last Reviewed: September 19, 2026
Executive Summary
Rajesh Sharma is co-founder and Chief Architect of AttackIQ, a Los Altos company built on an uncomfortable premise: most organisations have no evidence that the security products they have bought actually stop the attacks they were bought to stop. AttackIQ’s platform continuously runs real adversary behaviours — mapped to the MITRE ATT&CK framework — against a customer’s own live controls, and reports what got through. Sharma is the engineer behind the architecture. He spent more than two decades before AttackIQ writing kernel-level security software as a principal engineer and software architect at Websense, Guidance Software and Resolution 1 Security, work that put him inside the endpoint at the layer where enforcement either happens or does not. That background is the reason the company’s validation runs are meant to be safe to execute in production rather than in a lab.
Career Highlights
- Co-founder and Chief Architect of AttackIQ, confirmed in the company’s own author biography.
- More than 20 years in the security industry before AttackIQ, as Principal Engineer and Software Architect at Websense Inc. (now Forcepoint), Guidance Software Inc. (now part of OpenText), and Resolution 1 Security (now AccessData Group Inc.).
- Developed key kernel components used in Websense’s Client Policy Manager, the EnCase suite of forensic products, and the R1 Endpoint Solution.
- Architect of a platform now spanning AttackIQ Flex for on-demand exposure validation, AttackIQ Ready as a managed continuous service, AttackIQ Enterprise, the Command Center for standardising validation across teams, and Watchtower for AI-driven threat intelligence.
- AttackIQ raised a $44M Series C in 2021 with participation from Salesforce Ventures.
- Writes on AttackIQ’s blog on detection engineering, including work on AI agent-driven detection engineering as a response to SOC alert overload and rule decay.
Professional Journey
Sharma’s career began in the part of the security industry that is furthest from marketing and closest to the operating system. At Websense he was a principal engineer and software architect working on the Client Policy Manager, the component that enforces policy on the endpoint itself. At Guidance Software he worked on the EnCase suite, the forensic tooling that became the standard for digital investigation and evidence handling. At Resolution 1 Security he worked on the R1 Endpoint Solution. In each case the work was at kernel level — the code that has to be correct, because it runs with privileges where being wrong is not a bug report but an outage or a breach.
That experience shapes the problem AttackIQ was founded to address. An industry that sells controls has no natural incentive to measure them, and the customer is left assuming that a product configured two years ago still detects what it claimed to detect. AttackIQ’s answer is continuous validation: emulate real adversary techniques against the deployed stack, on a schedule, and produce evidence rather than assurance. The MITRE ATT&CK framework supplies the vocabulary — a shared catalogue of what attackers actually do — and the platform reports coverage against it.
As Chief Architect, Sharma owns the design of a system with an unusual constraint: it must behave like an attacker convincingly enough for the test to be meaningful, while being safe enough to run against production estates belonging to banks, governments and healthcare providers. The product line has grown outward from that core into on-demand testing (Flex), a fully managed service (Ready), enterprise deployment, a command centre for standardising validation across teams, and Watchtower, which applies AI to localised threat intelligence.
His recent writing has followed the same thread into the security operations centre, arguing that detection content decays as threats evolve and institutional knowledge leaves, and that agent-driven detection engineering is a way to fight that entropy rather than simply generate more alerts for analysts already handling thousands a day.
Education
R.E.C. Bhopal, India (now MANIT Bhopal)
Computer Science and Engineering
AttackIQ’s biography states only that he “has a degree in Computer Science and Engineering from R.E.C Bhopal India”; the level of the degree is not specified in any source and is not asserted here.
