SYS_ACTIVE // KHUSHI SHAH

I build products that make complicated systems easier to use, trust, and act on.

From AI intelligence tools to security workflows and operational systems, I like finding the real bottleneck, deciding what matters first, and building the version that makes someone's work meaningfully easier.

Featured work

Each case study is a decision map: how a complex system was made clearer to use, trust, and act on.

OPERATIONAL SYSTEMS

Spotlight Security

From scattered security signals to a usable path to action.

Security Product Engineering — brought together host, firewall, and customer context into prioritized findings with an actionable remediation path.

DISPARATE TOOL SIGNALSCLEAR PRIORITYACTIONABLE REMEDIATION
READ CASE STUDY →
HOST AGENTSFIREWALL CONFIGNETWORK CONTEXTNORMALIZE + DETECTPRIORITIZED FINDINGACTION + FOLLOW-THROUGH

AI WORKFLOW DESIGN

RiskLink

Designing and Engineering a voice-led cyber-risk assessment workflow.

AI Product Engineering — shaped a voice-based intake that turns conversation into structured risk reports for cyber insurance providers

NATURAL LANGUAGE INPUTRISK MAPPINGHUMAN HANDOFF
READ CASE STUDY →
"Tell me about your...""Can you clarify...""One more thing..."JSON OUTPUTGENERATED REPORTTEAM FOLLOW-UP →

RESEARCH TO PRODUCT DIRECTION

Friend / Foe

Designing for confidence when seconds matter.

Research to product — turned field observation into decision-support direction for high-stakes, time-critical calls.

FRAGMENTED INFORMATIONCONFIDENCEDECISION SUPPORT
READ CASE STUDY →
FIELD RESEARCH // JMRCDECISION LATENCY // OBSERVEDEVIDENCE_01

Security work doesn't stop at the product.

Research, teaching, community outreach, and field work — the parts of my career that don't fit in a case study but shape how I build.

012026 – Present

Verified by the Kids

Facebook Community Initiative · Online

Founded a community initiative teaching parents practical cyber safety — translating security know-how into guidance families can actually use.

  • Launched a community-facing page focused on parent cyber safety education
  • Share practical tips on online threats, privacy, and safer digital habits for families
02June 2025

H4D Success Story: Friend or Foe

Hacking for Defense (H4D) · United States

Project on reducing friendly fire in armored warfare published on the official H4D success stories site.

  • Selected into the Defense Innovation Scholar Fellowship–Cohort (DISF-C)
  • Recognition as a featured H4D success story
03May 2024

Poster Publication at USENIX 2024

USENIX SOUPS · Philadelphia, PA

Poster on privacy preferences in multi-user smart personal assistant settings.

  • Presented multi-institutional privacy research on SPAs
  • Surveyed 90+ participants and evaluated leading SPAs
04November 2024

Military Innovation Research Project

JMRC / Lean Innovation Lab · Poland & Germany

On-site research with JMRC as part of CMU's Lean Innovation Lab, evaluating operational technology in real-world military training.

  • Worked with military teams and participated in simulator drills
  • Collaborated with international forces for technology evaluation
05April 2025

Alumni Talk at Ahmedabad University

Ahmedabad University · India

Speaker on college-to-career stories and reflections with prospective students.

  • Spoke on career decisions, education paths, and student life
  • Engaged with audience on life beyond the classroom

What I care about

03 PRINCIPLES // METHOD

The questions I return to when building products people need to trust and act on.

01

Find the real workflow problem

OBSERVATION > ASSUMPTION

QUESTIONS AT THIS STAGE

  • Where does the work actually break down?
  • What are we assuming that we haven't observed?
  • Who feels the friction most acutely?
02

Build the useful first version

VELOCITY // RELIABILITY

QUESTIONS AT THIS STAGE

  • What is the smallest version that changes someone's day?
  • What must be reliable on day one?
  • What can wait without losing the point?
03

Make complex systems understandable

VISIBILITY // MAPPING

QUESTIONS AT THIS STAGE

  • What is invisible that should be mapped?
  • Where do people lose the thread?
  • What does clear enough to act look like?
04

Design for trust and failure states

SECURITY // HUMAN RESILIENCE

QUESTIONS AT THIS STAGE

  • What happens when this fails?
  • How does someone know they can trust the output?
  • What recovery path exists for the human in the loop?

I like building with people who care about what happens after the feature ships.