Krishna Prasad
Verified Expert in Engineering
Cloud Security Architect and Developer
Krishna is a full-stack security engineer and cloud security architect with 15 years of experience in the IT sector and 10+ years of experience in multi-cloud security, DevSecOps, and security architecture domains. Krishna is ready to handle any number of issues and give solutions that get results.
Portfolio
Experience
Availability
Preferred Environment
Security Architecture, Application Security, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Vulnerability Management, ISO 27001, DevSecOps, SOC 2, Cloud Security, OWASP Top 10, CISO
The most amazing...
...multi-cloud security design and reviews I’ve completed were well received by satisfied clients.
Work Experience
Cloud Security Architect
WorkSpan
- Designed and implemented AWS IAM Identity Center, integrating Google single sign-on (SSO) across multiple AWS accounts.
- Implemented Vanta, a SOC2 automation and reporting tool. Promoted awareness and adoption of the tool and platform among site reliability engineering (SRE) and cross-functional teams.
- Owned the AWS Foundational Technical Review (FTR) engagements for the WorkSpan product hosted on AWS Marketplace.
- Executed internal pen testing activities to identify the security issues and weaknesses on WorkSpan's co-sell application platform.
- Drafted security standards and controls collaborating closely with cross-functional teams to enforce these measures across cloud systems, applications, and data stores. Implemented a shared security responsibility model and Shift Left mindset.
- Participated in compliance initiatives as needed for achieving and maintaining continuous compliance to protect customer and sensitive data.
- Researched and executed POCs on new tools and processes that provide security automation to enforce continuous infrastructure and app development lifecycle security.
- Drafted security incident response playbooks and contributed to the development/improvements of information security policies.
- Conducted the security incident investigations and designed the security incident response automation flows.
- Spearheaded the evaluation program for static application security testing (SAST) tools, providing valuable insights and recommendations to both the engineering and executive teams.
Cloud Security Architect
SSENSE
- Delivered security architectures for cloud native and distributed systems. Ran applications on microservices and serverless based environments hosted on AWS Cloud.
- Used Jira as a project tracking tool. Used SonarQube, Security Hub, and Guardduty for several static application and security testing (SAST) and CSPM tools. Used AWS for security.
- Carried out the opportunity of building cloud security competency and practice with needed skills in the security domain.
- Delivered security standards and technical controls implementation for ongoing customer data protection initiatives. Assisted various teams in adapting them.
- Built a cloud security roadmap with goals matching cross-functional teams and organizational objectives. Continued to work on the ambitious goals of the cloud security team.
- Drafted security standards and controls. Worked with cross-functional teams to enforce them across cloud systems, applications, and data stores with a shared security responsibility model and "shift left" mindset.
- Executed threat modeling activities to identify the security. Generated security architectural requirements for software development and product teams for remediation.
- Proposed and enforced the implementation of security controls at every layer of architecture and applications. Set up a thorough defense strategy.
- Participated in compliance initiatives as needed to achieve and maintain continuous compliance. Protected the customer's sensitive data. Promoted strong identity and access (IAM) policies and practices.
- Worked closely with the data engineering teams. Built secure data applications and data pipelines. Adapted industry-standard data governance practices with the principle of least privilege, encryption, auditing, and monitoring controls in place.
Information Security/Cloud Security Operations (Principal)
Ingram Micro
- Performed architectural reviews of hybrid cloud infrastructure and applications. Validated architecture, design and data flow diagrams for the company’s cloud business unit.
- Used Jira, Azure, and AWS as native cloud security posture management tools. Utilized Azure Sentinel as a SIEM and SonarQube as an SAST.
- Led auditing, monitoring, and improving the security posture of cloud enterprise workloads. Developed CSPM and CWPP programs and worked with cross-functional teams to enforce them.
- Worked with different engineering leads and managers for adoption and improvements in matured DevSecOps processes. Built pipelines for security testing automation methodologies like SAST, dynamic application security testing (DAST), and SCA.
- Mentored juniors and first security-incident responders during proof-of-concept (PoC) activities, incident investigations, and escalations. Developed security metrics, reports, KRIs, and KPIs for management and executive teams as needed.
- Performed vendor risk assessments for the different CSPs and third-party application vendors. Maintained a risk register with a risk score. Maintained practices as a cloud security team Agile practitioner.
- Researched trends, best practices, and tools in the different domains of the security industry. Developed security solutions for technical and reference architectures.
- Aligned and translated business requirements into secure solutions. Reviewed technical architectures of applications and products to ensure they met modern security standards. Promoted zero-trust architectures.
- Researched security industry trends and best practices to share with the organization through presentations. Hosted security training and awareness programs.
- Collaborated with solution architects within the organization. Used Microsoft, AWS, and other multi-sided platforms (MSPs) and cloud vendors.
Senior Security Engineer
Zapr Media Labs
- Orchestrated the delivery of DevSecOps, big data apps, and cloud security aspects for the organization. Defined the organization’s IT security policies.
- Used Jira as a project tracking tool. Used AWS native security tools like Trusted Advisor, ConnectWise, SonarQube, Jenkins, and CI/CD pipelines.
- Evaluated the current security posture, cloud environment, and on-premise data center. Conducted immediate and quarterly audits. Published the recommended missing best practices and security controls.
- Organized and carried out vulnerability scans for web, mobile, APIs and other cloud hosted solutions.
- Managed validation, authentication, authorization methods, and data flow. Enforced best practices with encryption in place.
- Evaluated DevOps workflows, tools, methods, and components of CI/CD pipelines. Supervised them in adapting a shared security responsibility model.
- Facilitated recognizing, adopting, and integrating industry-leading security practices in the security engineering unit of the organization. Participated in the investigation and reporting of security incidents and events.
- Developed and maintained documentation and diagrams outlining data flows, endpoints, ports, protocols, and incident response plans.
- Deployed hardened base Amazon machine images (AMI). Hardened web server and application server configurations as per respective benchmarks.
Senior Software Engineer
EPAM Systems
- Consulted technical personnel. Managed client requirements on industry-best practices. Discussed, persuaded, and agreed on the most innovative approaches applicable in the customer landscape.
- Worked closely with the management and development organizational units. Secured enterprise-level software applications and solutions that met or exceeded client demands with an eye for the most efficient and cost-effective solutions.
- Supported the organization’s offshore unit. Improved the end-to-end stability and security posture of environments and tools.
- Led technology research, solution budgeting, feasibility, and evaluation. Spearheaded proof of concepts (PoC) to make imperative decisions. Trained the development teams on secure software development lifecycle (SDLC) practices.
- Contributed as part of an interview panel. Reviewed DevOps Profiles in the market for the requirements and initial screening. Mentored junior engineers on the company culture, solutions, and tools.
- Conducted internal audits. Led IT and cloud security policy reviews. Identified, fixed, and presented compliance related improvements to senior management.
Senior Software Engineer
Progress
- Led all DevOps Operations. Deployed, automated, maintained, and troubleshot. Tuned multi-tier and distributed cloud-based application components hosted on AWS.
- Troubleshot issues in real-time across the whole stack. Conducted audit trails and account access reviews. Worked on compliance assignments related to SOC 2.
- Facilitated and provided support (for internal and external parties). Ensured cyber security incident management and response for the alerts and events triggered by SIEM, and IDS/IPS solutions.
- Worked closely with the other teams to assess risk and provide recommendations for improving our security posture.
- Served as the point of contact and escalation for all cloud security operations center events for the offshore unit in Hyderabad.
- Assisted lower-level software engineers and new recruits to the team. Educated them about the security knowledge, tools, and processes.
- Kept up to date with knowledge of current standard system security practices.
Experience
Deployment and Configuration of AWS Native Security Tools
Deployed Azure Native Cloud Security Tools
Static Analysis Process Integration into CI/CD Pipelines
Skills
Libraries/APIs
Java Security, OpenID
Tools
Jenkins, AWS SDK, Terraform, SonarQube, Puppet, Chef
Paradigms
DevSecOps, Management, DevOps, Security Software Development, Penetration Testing, Fuzz Testing, Microservices Architecture, DDoS, HIPAA Compliance
Platforms
Amazon Web Services (AWS), Linux, Google Cloud Platform (GCP), Azure, Docker, AWS IoT, Vanta
Industry Expertise
Cybersecurity, Network Security
Storage
Database Security, Data Lakes
Other
Vulnerability Management, SOC 2, Cloud Security, Web Security, OWASP Top 10, Security Operations Centers (SOC), Software, SIEM, Architecture, Data Protection, Authentication, Security, Vulnerability Identification, APIs, Cloud, IT Security, Ethical Hacking, Risk Management, SecOps, Vulnerability Assessment, PCI, NIST, Software Development Lifecycle (SDLC), Identity & Access Management (IAM), Asset Management, Security Design, Security Audits, Cloud Computing, Monitoring, SSL, Load Balancers, Information Security, System-on-a-Chip (SoC), Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Group Policy, Governance, Data Governance, Security Engineering, Infrastructure Security, Cloud Infrastructure, Application Security, Static Application Security Testing (SAST), ISO 27001, Security Architecture, Big Data Architecture, CI/CD Pipelines, Veracode, Qualys, IT Management, Big Data, Full-stack, Mobile Security, Configuration Management, Risk Assessment, Secure Access Service Edge (SASE), Artificial Intelligence (AI), Dynamic Application Security Testing (DAST), GDPR, Secure Software Development Lifecycle (SSDLC), OAuth, AWS DevOps, CISO, Compliance, Code Review
Languages
Python, Java, Go
Frameworks
OAuth 2
Education
Master's Degree in Bioinformatics
Bharathidasan University - Tiruchirappalli, India
How to Work with Toptal
Toptal matches you directly with global industry experts from our network in hours—not weeks or months.
Share your needs
Choose your talent
Start your risk-free talent trial
Top talent is in high demand.
Start hiring