Karthik Reddy
DevSecOps Manager @ OpenText
About
DevSecOps professional with extensive experience in automating and optimizing app security, performing seamless migrations, and supporting mission-critical deployments of cloud-native and on-premises applications. Demonstrated agility in implementing CI/CD/CM/CS for enterprise-level applications across various industries, including e-commerce, banking (trading), and pharmaceuticals. Skilled in fostering a collaborative environment, effectively engaging with vendors, stakeholders, and product owners globally to explore and leverage new technologies for optimal productivity. Skills Expertise in:- Cloud: AWS, Azure, Azure DevOps VCS & SCM: Git, SVN, GitHub, GitLab, CodeCommit, Bitbucket CI tools: Jenkins, Bamboo, GitLab, GitHub Actions, Travis-CI, Code Pipeline, CM tools: Ansible, Terraform Build Tools: Maven, Ant, Gradle Source Code Analysis: SonarQube, SonarLint, PumaScan, Software Composition Analysis: SNYK, Sonatype Nexus, Synopsys Blackduck SAST: MicroFocus FortifySCA & SSC, CheckmarX, Veracode, Synopsys Coverity, MobSf DAST: OWASP ZAP, BurpSuite, Webinspect, Acunetix, HCL Appscan, Android Debugger IAST: CheckmarX IAST, Synopsys Seeker, Contrast Security IAST, Acunetix IAST RASP: Imperva RASP, Contrast Security RASP, Datadog ASM WAF: CloudFront WAF Threat Detection, CSPM, CWPP: SentinelOne EDR, SentinelOne XDR, MDFC Mobile Hardening & Security: Microsoft Intune, Zimperium Repo/Artifact Management: Nexus, Jfrog Container Orchestration: Docker, Docker Swarm, K8s, OpenShift Container Vulnerability Assessment & Security: Qualys Container Security, Sonatype Lifecycle, Sysdig Monitoring: Splunk, Nagios, NewRelic, Grafana Log Management: ELK Stack, SPLUNK, ArcSight Database: MySQL, MariaDB Work & Forum Management: Jira & Confluence, Scrum, Kanban, Azure Boards Competencies: Shell scripting, PowerShell, Python I'm excited to work with an organization that can extensively use my capabilities in DevSecOps.
-
United Arab Emirates
Information Technology & Services
Dynamic application security testing, Api security, Fortify Software Security Center, Fortify, Fcli, DevSecOps, Static Analysis, Dast, Vulnerability Management, Configuration Management, Gitlab, Incident Response, Security Incident Response, Cybersecurity Incident Response, Cloud Security, Network Forensics, Ethical Hacking, Security Information and Event Management (SIEM), Vulnerability Assessment, Penetration Testing
Experience

DevSecOps Manager
→ Managing a group of 6 peoples in infosec and working closely with CISO and Business units to conduct Risk Assessments, DevSecOps Implementation and analysis of in-house security tech stacks. → Finding security gaps in cloud environment, IAM, DLP & onboarding new tools/vendors. Migrated On-Premises AppSec & CI/CD Infrastructure to GCP cloud. → Implemented DevSecOps process & Security Stacks like Code Quality Analysis, SCA – Sonatype Nexus Lifecycle, SAST - FortifySCA, DAST - WebInspect, IAST – Contrast Security, RASP – Imperva & vulnerability management tool – FortifySSC. → Implemented AI/ML Security Assessments on ML Models, track down the Open-Source Security Components using Nexus Lifecycle, NB-Defense, Rebuff and ModelScan – AI/ML and saved $1.6 billion in potential losses. → Implemented GCP DevOps to automate the Security stacks. → Developed and customized Docker files to integrate DevSecOps security stacks, automating the deployment through CI/CD pipelines and managing the hosting of these stacks within an OpenShift environment. → Handling Internal & External stakeholders on Delivery Management (Application & Cloud Security). Also, responsible for hand-on training on DevSecOps tools, Process. → Recognition with the 'DevSecOps Trailblaze of the Year' award from Sonatype’s Elevate Awards

Information Security Senior Software Engineer (DevSecOps)
Dubai, United Arab Emirates
Lead a group of 9 members in the InfoSec - DevSecOps team and was Responsible for continuous End-to-End Security Integrations, Deployments, Releases, Monitoring, and Feedback. ⇢ Collaborated with client product specialists to analyze and document business requirements and data specifications for enhancing the DevSecOps Process and handle Idea Sheet, FRI/RFP, VMO, and POC to Onboard the tools to utilize in Alshaya's Environment. Evaluated and recommended a standard software toolset for team members to enhance productivity. A representative from infosec for all the Digital Transformation Initiatives and handling project management of 63 initiatives. ⇢ Coordinated project activities across multiple departments (QA, Development, Customer Support, and Documentation) across multiple geographical locations (Mena, Russia, and India). Created dedicated development, QA, UAT, and staging environments. Implemented DevSecOps framework and follows the same to all projects, Created pipelines to integrate the security tools and follows the ShiftLeft process from planning, Coding phase, and analyzing security vulnerabilities at the early stage to mitigate them. ⇢ Implemented, and integrated the security tools into the CI/CD pipeline of GitLab Using SonarQube, Snyk, Sonarlint, Fortify-SCA, CheckmarX, WebInspect, Appscan, Contrast Security IAST + RASP, Datadog ASM, for tracking used JIRA, configured the End-to-End pipeline for all projects to automate the process. Provided troubleshooting in the event of any errors and unpredicted behavior. ⇢ Perform Internal, External vulnerability assessments to scan the Internal Servers, and cloud servers (AWS, Azure, Aquia, and Oracle) and Analyzed Technologies and Applications using tenable.io, tenable.sc, Qualys to identify weaknesses and provide solutions to improve Security. Using ArcSight for Continuous Monitoring, Incident Response, and Log Management.

Senior DevSecOps Engineer
Lead a group of 4 members in the InfoSec - DevSecOps team and was Responsible for continuous End-to-End Security Integrations, Deployments, Releases, Monitoring, and Feedback. ⇢ For the cybersecurity ratings, compliance control, and Probable finance loss used Blackite for Continuous Automated Red Teaming (CART) and Attack Surface Management (ASM) used Firecompass. ⇢ Working with NewRelic for APM (Application Performance Management), and Datadog ASM for including all applications and cloud/on-premise services, ArcSight for Log Management to monitor all the logs of Servers, Applications & Cloud Native Services, and POS. For “End-Point Detection & Prevention” – XDR using SentinelOne, Microsoft Defender for Cloud. For Mobile Security Using Zimperium, and Intune for Hardening. ⇢ Perform the penetration testing of mobile (Android and iOS) applications, specifically, APK reverse engineering, traffic analysis, manipulation, and dynamic runtime analysis. ⇢ Installation/upgrade of the ArcSight solution components and formation of content-specific queries, templates, reports, rules, alerts, dashboards, and workflows. Integrate data and event feeds with ArcSight solution. Troubleshoot log source integration issues on servers and active directory, Analyze and resolve complex and Real-time monitoring. ⇢ Working on tasks associated with being the Software Build Approver that required running various tests and an associated pre-build check on submitted problem resolution items. Consistently improved the quality of the product by proactively raising and fixing the issues/bugs, rigorously. Involved in the migration process from on-premise to Azure Cloud.

DEVSECOPS Engineer
Bengaluru Area, India
✔Implemented Cloud Native DevOps (AWS) and Managed GitHub repositories, and permissions, including branching and tagging/Versioning. ✔Create and maintain fully automated CI/CD pipelines for code Build and Deployment using Jenkins and AWS to reduce human effort and speed up production processes ✔Install, Configure tools needed for DevOps and Worked on the configuration part of Jenkins Jobs, Nodes, and plugins to integrate ✔Coordinating with developers and testers for Github and SonarQube-related issues ✔Built and deployed Docker containers to break up the monolithic app into micro-services, improving developer workflow, increasing scalability, and optimizing speed ✔Actively Manage, Improve, Docker Containers and Monitoring Successfully with Kubernetes, scaling and using AWS EC2 instances ✔Successfully integrated Security tools like OWASP ZAP, Burpsuite, SonarQube, Checkmarx and analyzed reports ✔Integrating Security Practices in CI/CD pipeline for achieving secure deployment of applications ✔Creating a pipeline for different Java, Python, and C# applications ✔If the build or Deployment fails, a Roll-Back plan is followed to make the previous changes reflect ✔Deploy, configure, and manage test runtime environments ✔Troubleshooting and resolving issues in DEV, UAT, and Test Environment ✔Handling different AWS services like Infrastructure as Code (Cloud Formation), VPC, ElasticBeanStalk, lambda, SNS, S3, etc. ✔Monitoring and Visualization of the Application’s metrics and graphs using ELK Stack, Nagios, Splunk, etc. ✔Implements and maintains Splunk platform infrastructure, configuration, and integration with external systems. Undertakes day-to-day operational and user support. Scopes project requirements and executes new projects as well as data and user onboarding. Assist users on Splunk platform system-related issues. ✔Supporting Onsite deployment at onsite from off-shore ✔Managing Windows, Linux, and PowerShell or Unix shell

QA SECURITY ENGINEER
Bengaluru Area, India
✔Worked on Creating Azure Automation Accounts, Certificates, and Users in Active Directory. ✔Creating Azure PowerShell Runbook scripts to automate the complete process for the VMs. ✔Resizing the VMs for Vertical & Horizontal Scaling using PowerShell scripts. ✔After successfully resizing the VM and the admin will get the output status through an email notification about the VM’s working status. ✔Handling Application Deployments into Azure EKS. Scanning the Docker file using Fortify, Anchore for Image/Container security, and “Kube Hunter” for Kubernetes security. ✔Creating schedules to trigger the RunBooks periodically. ✔Performing application security, penetration testing, and vulnerability assessment with tools such as Nmap, Wireshark, Nessus, OWASP ZAP, Metasploit, Burp Suite, etc ✔Performed host, network, and web application penetration tests ✔Prepare audit reports that identify technical and procedural findings with the help of the Tenable Nessus tool ✔Performed network security analysis and risk management for designated systems ✔Analyze vulnerability test reports and suggest remediation/mitigation plans. Includes the ability to prioritize process and reporting enhancements ✔Discovered and communicated two reflective cross-site scripting vulnerabilities and two unprotected directories while performing an external web security assessment ✔Experience with Unix and Windows platforms ✔Strong work ethic and ability to effectively multi-task in a fast-paced support environment ✔Knowledge of PCI-DSS, Risk Assessment, ISO-27001, ISO-27005, and ISO-27034

Jr. QA Security Engineer
Bengaluru Area, India
Perform Application Security Assessments on more than 150 applications Perform Automated Source Code Review with HP-Fortify and eliminate false positives. Conducted infrastructure scans/tests on Networks and Servers using Nessus. Preparing reports for the application security assessments with vulnerability explanation, risk analysis, and remediation process.
Karthik Reddy's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.



