Ramireddy - Devsecops - Piramal
Ramireddy - Devsecops - Piramal
Summary
Having 5.8 years of expertise in DevOps, DevSecOps, and cloud security to support agile application building,
scaling a secure pipeline, developing a secure architecture
Extensive experienced building secure DevOps pipelines using Git, GitHub, Jenkins, and GitHub Actions
Skilled in debugging and maintaining Jenkins build pipelines, including fixing broken builds
Hands-on experience with cloud security testing using Kubernetes-goat and AWS-goat
Proven track record designing secure SDLC architectures and implementing security requirements
Expertise in CI/CD pipeline tools like Jenkins, GitHub Actions and AWS Code Pipeline
Proficient in black box and white box testing methodologies like OWASP, etc
Experienced using SAST tools like SonarQube and Snyk to analyze code and maintain quality gates
Skilled in using DAST tools like Burp Suite and IBM Appscan to find vulnerabilities through simulated attacks
Implemented security best practices like running containers as non-root user, using read-only file systems
Scanned container images for vulnerabilities using tools like Clair, Anchore, Snyk
Enforced security policies and compliance requirements for container deployments
Skills
Development of an architecture for application and implementation of monolithic services, microservices and
cloud-based services
Identifying security weaknesses and recommending remediation actions
Collaborated with development teams to integrate security practices into the software development lifecycle,
ensuring the delivery of secure applications
Completed around 109 DevSecOps application integration in check Marx, white source and burp suite
Developed and enforced security policies, standards, and procedures to maintain compliance with relevant
regulations and industry frameworks (e.g., GDPR, ISO 27001)
Designed and implemented cloud security architectures and solutions, leveraging industry best practices and
standards (e.g., AWS, Azure, GCP)
Conducted code reviews and provided guidance to development teams on secure coding practices and application
security principles
Hands-on Experience LDAP integration of our security tools and TLS/SSL certificate to implement
OnPremisesDevOpsimplementationcoveringsecuritytoolchainintegrationincluding credential scanner, SAST &
SCA, DAST and container image scanners with CI build pipeline such as SonarQube, Chekov, Trivy, and Anchor
Engine to identify vulnerabilities
Reviewed and implemented identity & access including RBAC design per business processes, data encryption &
key management, cloud infrastructure and cloud-native services security and audit configurations reducing the
security risk by 60%.
DevSecOps .
• Performing DAST (Dynamic Analysis Security Testing) & SAST(Source code Analysis Security Testing)
on BNYM(Bank of New York Mellon) related Web Apps and Services
• Performing in delivering VAPT in Web and API endpoints
• hands on experience into security testing of various Application technologies
• working experience on RIA and thick client Applications
• Preparing reports per BNY Policies & standards and distributing to DEV Teams for review meetings and
uploading those report findings to issue tracker/JIRA to Archer for tracking
• Prepared templates for vulnerabilities with proof of concept and SOP’s for automation testing with tools
and check lists for manual testing
• Prepared VMM’s – Vulnerability mitigation methods with source code for development teams reference
• Working experience on tools i.e. IBM App Scan std, Veracode, Burp suite Pro, Soap UI, Postman &
Nmap