Karthik Reddy

Karthik Reddy

DevSecOps Manager @ OpenText

About

DevSecOps professional with extensive experience in automating and optimizing app security, performing seamless migrations, and supporting mission-critical deployments of cloud-native and on-premises applications. Demonstrated agility in implementing CI/CD/CM/CS for enterprise-level applications across various industries, including e-commerce, banking (trading), and pharmaceuticals. Skilled in fostering a collaborative environment, effectively engaging with vendors, stakeholders, and product owners globally to explore and leverage new technologies for optimal productivity. Skills Expertise in:- Cloud: AWS, Azure, Azure DevOps VCS & SCM: Git, SVN, GitHub, GitLab, CodeCommit, Bitbucket CI tools: Jenkins, Bamboo, GitLab, GitHub Actions, Travis-CI, Code Pipeline, CM tools: Ansible, Terraform Build Tools: Maven, Ant, Gradle Source Code Analysis: SonarQube, SonarLint, PumaScan, Software Composition Analysis: SNYK, Sonatype Nexus, Synopsys Blackduck SAST: MicroFocus FortifySCA & SSC, CheckmarX, Veracode, Synopsys Coverity, MobSf DAST: OWASP ZAP, BurpSuite, Webinspect, Acunetix, HCL Appscan, Android Debugger IAST: CheckmarX IAST, Synopsys Seeker, Contrast Security IAST, Acunetix IAST RASP: Imperva RASP, Contrast Security RASP, Datadog ASM WAF: CloudFront WAF Threat Detection, CSPM, CWPP: SentinelOne EDR, SentinelOne XDR, MDFC Mobile Hardening & Security: Microsoft Intune, Zimperium Repo/Artifact Management: Nexus, Jfrog Container Orchestration: Docker, Docker Swarm, K8s, OpenShift Container Vulnerability Assessment & Security: Qualys Container Security, Sonatype Lifecycle, Sysdig Monitoring: Splunk, Nagios, NewRelic, Grafana Log Management: ELK Stack, SPLUNK, ArcSight Database: MySQL, MariaDB Work & Forum Management: Jira & Confluence, Scrum, Kanban, Azure Boards Competencies: Shell scripting, PowerShell, Python I'm excited to work with an organization that can extensively use my capabilities in DevSecOps.

Country

-

City

United Arab Emirates

Industry

Information Technology & Services

Skill

Dynamic application security testing, Api security, Fortify Software Security Center, Fortify, Fcli, DevSecOps, Static Analysis, Dast, Vulnerability Management, Configuration Management, Gitlab, Incident Response, Security Incident Response, Cybersecurity Incident Response, Cloud Security, Network Forensics, Ethical Hacking, Security Information and Event Management (SIEM), Vulnerability Assessment, Penetration Testing

Experience

OpenText

DevSecOps Manager

OpenText

LinkedIn
2023-5 - Present · 3 yrs 5 mos

→ Managing a group of 6 peoples in infosec and working closely with CISO and Business units to conduct Risk Assessments, DevSecOps Implementation and analysis of in-house security tech stacks. → Finding security gaps in cloud environment, IAM, DLP & onboarding new tools/vendors. Migrated On-Premises AppSec & CI/CD Infrastructure to GCP cloud. → Implemented DevSecOps process & Security Stacks like Code Quality Analysis, SCA – Sonatype Nexus Lifecycle, SAST - FortifySCA, DAST - WebInspect, IAST – Contrast Security, RASP – Imperva & vulnerability management tool – FortifySSC. → Implemented AI/ML Security Assessments on ML Models, track down the Open-Source Security Components using Nexus Lifecycle, NB-Defense, Rebuff and ModelScan – AI/ML and saved $1.6 billion in potential losses. → Implemented GCP DevOps to automate the Security stacks. → Developed and customized Docker files to integrate DevSecOps security stacks, automating the deployment through CI/CD pipelines and managing the hosting of these stacks within an OpenShift environment. → Handling Internal & External stakeholders on Delivery Management (Application & Cloud Security). Also, responsible for hand-on training on DevSecOps tools, Process. → Recognition with the 'DevSecOps Trailblaze of the Year' award from Sonatype’s Elevate Awards

Alshaya Group

Lead DevSecOps

Alshaya Group

LinkedIn
2021-7 - 2023-5 · 1 yr 11 mos

Dubai, United Arab Emirates

Alshaya Group

Information Security Senior Software Engineer (DevSecOps)

Alshaya Group

LinkedIn
2022-4 - 2023-2 · 11 mos

Dubai, United Arab Emirates

Lead a group of 9 members in the InfoSec - DevSecOps team and was Responsible for continuous End-to-End Security Integrations, Deployments, Releases, Monitoring, and Feedback. ⇢ Collaborated with client product specialists to analyze and document business requirements and data specifications for enhancing the DevSecOps Process and handle Idea Sheet, FRI/RFP, VMO, and POC to Onboard the tools to utilize in Alshaya's Environment. Evaluated and recommended a standard software toolset for team members to enhance productivity. A representative from infosec for all the Digital Transformation Initiatives and handling project management of 63 initiatives. ⇢ Coordinated project activities across multiple departments (QA, Development, Customer Support, and Documentation) across multiple geographical locations (Mena, Russia, and India). Created dedicated development, QA, UAT, and staging environments. Implemented DevSecOps framework and follows the same to all projects, Created pipelines to integrate the security tools and follows the ShiftLeft process from planning, Coding phase, and analyzing security vulnerabilities at the early stage to mitigate them. ⇢ Implemented, and integrated the security tools into the CI/CD pipeline of GitLab Using SonarQube, Snyk, Sonarlint, Fortify-SCA, CheckmarX, WebInspect, Appscan, Contrast Security IAST + RASP, Datadog ASM, for tracking used JIRA, configured the End-to-End pipeline for all projects to automate the process. Provided troubleshooting in the event of any errors and unpredicted behavior. ⇢ Perform Internal, External vulnerability assessments to scan the Internal Servers, and cloud servers (AWS, Azure, Aquia, and Oracle) and Analyzed Technologies and Applications using tenable.io, tenable.sc, Qualys to identify weaknesses and provide solutions to improve Security. Using ArcSight for Continuous Monitoring, Incident Response, and Log Management.

Alshaya Group

Senior DevSecOps Engineer

Alshaya Group

LinkedIn
2021-7 - 2023-2 · 1 yr 8 mos

Lead a group of 4 members in the InfoSec - DevSecOps team and was Responsible for continuous End-to-End Security Integrations, Deployments, Releases, Monitoring, and Feedback. ⇢ For the cybersecurity ratings, compliance control, and Probable finance loss used Blackite for Continuous Automated Red Teaming (CART) and Attack Surface Management (ASM) used Firecompass. ⇢ Working with NewRelic for APM (Application Performance Management), and Datadog ASM for including all applications and cloud/on-premise services, ArcSight for Log Management to monitor all the logs of Servers, Applications & Cloud Native Services, and POS. For “End-Point Detection & Prevention” – XDR using SentinelOne, Microsoft Defender for Cloud. For Mobile Security Using Zimperium, and Intune for Hardening. ⇢ Perform the penetration testing of mobile (Android and iOS) applications, specifically, APK reverse engineering, traffic analysis, manipulation, and dynamic runtime analysis. ⇢ Installation/upgrade of the ArcSight solution components and formation of content-specific queries, templates, reports, rules, alerts, dashboards, and workflows. Integrate data and event feeds with ArcSight solution. Troubleshoot log source integration issues on servers and active directory, Analyze and resolve complex and Real-time monitoring. ⇢ Working on tasks associated with being the Software Build Approver that required running various tests and an associated pre-build check on submitted problem resolution items. Consistently improved the quality of the product by proactively raising and fixing the issues/bugs, rigorously. Involved in the migration process from on-premise to Azure Cloud.

Sun Technologies

DEVSECOPS Engineer

Sun Technologies

LinkedIn
2018-8 - 2021-7 · 3 yrs

Bengaluru Area, India

✔Implemented Cloud Native DevOps (AWS) and Managed GitHub repositories, and permissions, including branching and tagging/Versioning. ✔Create and maintain fully automated CI/CD pipelines for code Build and Deployment using Jenkins and AWS to reduce human effort and speed up production processes ✔Install, Configure tools needed for DevOps and Worked on the configuration part of Jenkins Jobs, Nodes, and plugins to integrate ✔Coordinating with developers and testers for Github and SonarQube-related issues  ✔Built and deployed Docker containers to break up the monolithic app into micro-services, improving developer workflow, increasing scalability, and optimizing speed ✔Actively Manage, Improve, Docker Containers and Monitoring Successfully with Kubernetes, scaling and using AWS EC2 instances ✔Successfully integrated Security tools like OWASP ZAP, Burpsuite, SonarQube, Checkmarx and analyzed reports ✔Integrating Security Practices in CI/CD pipeline for achieving secure deployment of applications ✔Creating a pipeline for different Java, Python, and C# applications ✔If the build or Deployment fails, a Roll-Back plan is followed to make the previous changes reflect ✔Deploy, configure, and manage test runtime environments ✔Troubleshooting and resolving issues in DEV, UAT, and Test Environment ✔Handling different AWS services like Infrastructure as Code (Cloud Formation), VPC, ElasticBeanStalk, lambda, SNS, S3, etc. ✔Monitoring and Visualization of the Application’s metrics and graphs using ELK Stack, Nagios, Splunk, etc. ✔Implements and maintains Splunk platform infrastructure, configuration, and integration with external systems. Undertakes day-to-day operational and user support. Scopes project requirements and executes new projects as well as data and user onboarding. Assist users on Splunk platform system-related issues. ✔Supporting Onsite deployment at onsite from off-shore  ✔Managing Windows, Linux, and PowerShell or Unix shell

Sun Technologies

QA SECURITY ENGINEER

Sun Technologies

LinkedIn
2018-5 - 2018-7 · 3 mos

Bengaluru Area, India

✔Worked on Creating Azure Automation Accounts, Certificates, and Users in Active Directory. ✔Creating Azure PowerShell Runbook scripts to automate the complete process for the VMs. ✔Resizing the VMs for Vertical & Horizontal Scaling using PowerShell scripts. ✔After successfully resizing the VM and the admin will get the output status through an email notification about the VM’s working status. ✔Handling Application Deployments into Azure EKS. Scanning the Docker file using Fortify, Anchore for Image/Container security, and “Kube Hunter” for Kubernetes security. ✔Creating schedules to trigger the RunBooks periodically. ✔Performing application security, penetration testing, and vulnerability assessment with tools such as Nmap, Wireshark, Nessus, OWASP ZAP, Metasploit, Burp Suite, etc ✔Performed host, network, and web application penetration tests ✔Prepare audit reports that identify technical and procedural findings with the help of the Tenable Nessus tool ✔Performed network security analysis and risk management for designated systems ✔Analyze vulnerability test reports and suggest remediation/mitigation plans. Includes the ability to prioritize process and reporting enhancements ✔Discovered and communicated two reflective cross-site scripting vulnerabilities and two unprotected directories while performing an external web security assessment ✔Experience with Unix and Windows platforms ✔Strong work ethic and ability to effectively multi-task in a fast-paced support environment ✔Knowledge of PCI-DSS, Risk Assessment, ISO-27001, ISO-27005, and ISO-27034

ObjectWin Technology

Jr. QA Security Engineer

ObjectWin Technology

LinkedIn
2016-6 - 2018-4 · 1 yr 11 mos

Bengaluru Area, India

 Perform Application Security Assessments on more than 150 applications  Perform Automated Source Code Review with HP-Fortify and eliminate false positives.  Conducted infrastructure scans/tests on Networks and Servers using Nessus.  Preparing reports for the application security assessments with vulnerability explanation, risk analysis, and remediation process.

Education

Birla Institute of Technology and Science, Pilani

Birla Institute of Technology and Science, Pilani

LinkedIn

Data Science and Engineering

2020 - 2022 · 2 yrs
Sreenivasa Inst. of Technology & Management Studies, Thimmasamudram, Chittoor

Sreenivasa Inst. of Technology & Management Studies, Thimmasamudram, Chittoor

LinkedIn

ELECTRONICS AND COMMUNICATION ENGINEERING (ECE)

2012 - 2016 · 4 yrs

Karthik Reddy's Contact Information

Email

******@***.com

Phone

(**) *** ****

Find the Right Leads
Find Verified Contact Data

Try with: Jensen Huang @ nvidia.com Click to autofill
LeadContact awards, five-star ratings, and GDPR compliance badges

What LeadContact does well

Find verified emails, phone numbers, and decision-makers with 98% accuracy.

Find Leads

Find Leads

Find the right people by company, role, industry, location, and more.

925M+ professional profiles

Find Leads
Find Emails

Find Emails

Access verified email addresses for your target contacts.

657M+ emails

Find Emails
Find Phone Numbers

Find Phone Numbers

Get cross-validated phone data from multiple top sources.

239M+ phone numbers

Find Phone Numbers

More Accurate. Lower Cost.

Find contact data in 1 tool with 98% accuracy

LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.

LeadContact Logo
Competitor Tools

All these = $289 per month

Great conversations start with the right contact.

It’s time to find yours.