Krishna Prasad, SecOps Developer in Toronto, ON, Canada
Krishna Prasad

SecOps Developer in Toronto, ON, Canada

Member since December 13, 2022
Krishna is a full-stack security engineer and cloud security architect. He has 13+ years of experience in the IT sector and over ten years of experience in cloud security, DevSecOps, and security architecture domains. Krishna is ready to handle any number of issues and give solutions that get results.
Krishna is now available for hire

Portfolio

  • SSENSE
    Cloud Security, Amazon Web Services (AWS), Security, Application Security...
  • Ingram Micro
    Dynamic Application Security Testing (DAST), Security...
  • Zapr Media Labs
    Security, Application Security, Amazon Web Services (AWS)...

Experience

  • Static Application Security Testing (SAST) 10 years
  • SecOps 10 years
  • Vulnerability Management 10 years
  • Dynamic Application Security Testing (DAST) 10 years
  • Cloud Security 10 years
  • DevSecOps 10 years
  • Software Development Lifecycle (SDLC) 9 years
  • Security Architecture 7 years

Location

Toronto, ON, Canada

Availability

Full-time

Preferred Environment

Security Architecture, Application Security, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Vulnerability Management, ISO 27001, GDPR, DevSecOps, SOC 2, Cloud Security, C, OWASP Top 10

The most amazing...

...multi-cloud security design and reviews I’ve completed were well received by satisfied clients.

Employment

  • Cloud Security Architect

    2021 - 2022
    SSENSE
    • Delivered security architectures for cloud native and distributed systems. Ran applications on microservices and serverless based environments hosted on AWS Cloud.
    • Used Jira as a project tracking tool. Used SonarQube, Security Hub, and Guardduty for several static application and security testing (SAST) and CSPM tools. Used AWS for security.
    • Carried out the opportunity of building cloud security competency and practice with needed skills in the security domain.
    • Delivered security standards and technical controls implementation for ongoing customer data protection initiatives. Assisted various teams in adapting them.
    • Built a cloud security roadmap with goals matching cross-functional teams and organizational objectives. Continued to work on the ambitious goals of the cloud security team.
    • Drafted security standards and controls. Worked with cross-functional teams to enforce them across cloud systems, applications, and data stores with a shared security responsibility model and "shift left" mindset.
    • Executed threat modeling activities to identify the security. Generated security architectural requirements for software development and product teams for remediation.
    • Proposed and enforced the implementation of security controls at every layer of architecture and applications. Set up a thorough defense strategy.
    • Participated in compliance initiatives as needed to achieve and maintain continuous compliance. Protected the customer's sensitive data. Promoted strong identity and access (IAM) policies and practices.
    • Worked closely with the data engineering teams. Built secure data applications and data pipelines. Adapted industry-standard data governance practices with the principle of least privilege, encryption, auditing, and monitoring controls in place.
    Technologies: Cloud Security, Amazon Web Services (AWS), Security, Application Security, Microservices Architecture, Static Application Security Testing (SAST), Secure SDLC, GDPR, Web Security, APIs, Full-stack, Security Architecture, Dynamic Application Security Testing (DAST), Vulnerability Management, DevSecOps, SOC 2, Management, Big Data Architecture, Big Data, DevOps, CI/CD Pipelines, OWASP Top 10, Security Operations Centers (SOC), SIEM, Tenable, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset Management
  • Information Security/Cloud Security Operations (Principal)

    2018 - 2021
    Ingram Micro
    • Performed architectural reviews of hybrid cloud infrastructure and applications. Validated architecture, design and data flow diagrams for the company’s cloud business unit.
    • Used Jira, Azure, and AWS as native cloud security posture management tools. Utilized Azure Sentinel as a SIEM and SonarQube as an SAST.
    • Led auditing, monitoring, and improving the security posture of cloud enterprise workloads. Developed CSPM and CWPP programs and worked with cross-functional teams to enforce them.
    • Worked with different engineering leads and managers for adoption and improvements in matured DevSecOps processes. Built pipelines for security testing automation methodologies like SAST, dynamic application security testing (DAST), and SCA.
    • Mentored juniors and first security-incident responders during proof-of-concept (PoC) activities, incident investigations, and escalations. Developed security metrics, reports, KRIs, and KPIs for management and executive teams as needed.
    • Performed vendor risk assessments for the different CSPs and third-party application vendors. Maintained a risk register with a risk score. Maintained practices as a cloud security team Agile practitioner.
    • Researched trends, best practices, and tools in the different domains of the security industry. Developed security solutions for technical and reference architectures.
    • Aligned and translated business requirements into secure solutions. Reviewed technical architectures of applications and products to ensure they met modern security standards. Promoted zero-trust architectures.
    • Researched security industry trends and best practices to share with the organization through presentations. Hosted security training and awareness programs.
    • Collaborated with solution architects within the organization. Used Microsoft, AWS, and other multi-sided platforms (MSPs) and cloud vendors.
    Technologies: Dynamic Application Security Testing (DAST), Security, Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), Application Security, Static Application Security Testing (SAST), Full-stack, Security Architecture, Vulnerability Management, ISO 27001, GDPR, DevSecOps, SOC 2, Cloud Security, Management, Microservices Architecture, Secure SDLC, Web Security, APIs, Big Data Architecture, Big Data, DevOps, CI/CD Pipelines, OWASP Top 10, Security Operations Centers (SOC), SIEM, Tenable, Qualys, Veracode, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset Management
  • Senior Security Engineer

    2018 - 2018
    Zapr Media Labs
    • Orchestrated the delivery of DevSecOps, big data apps, and cloud security aspects for the organization. Defined the organization’s IT security policies.
    • Used Jira as a project tracking tool. Used AWS native security tools like Trusted Advisor, ConnectWise, SonarQube, Jenkins, and CI/CD pipelines.
    • Evaluated the current security posture, cloud environment, and on-premise data center. Conducted immediate and quarterly audits. Published the recommended missing best practices and security controls.
    • Organized and carried out vulnerability scans for web, mobile, APIs and other cloud hosted solutions.
    • Managed validation, authentication, authorization methods, and data flow. Enforced best practices with encryption in place.
    • Evaluated DevOps workflows, tools, methods, and components of CI/CD pipelines. Supervised them in adapting a shared security responsibility model.
    • Facilitated recognizing, adopting, and integrating industry-leading security practices in the security engineering unit of the organization. Participated in the investigation and reporting of security incidents and events.
    • Developed and maintained documentation and diagrams outlining data flows, endpoints, ports, protocols, and incident response plans.
    • Deployed hardened base Amazon machine images (AMI). Hardened web server and application server configurations as per respective benchmarks.
    Technologies: Security, Application Security, Amazon Web Services (AWS), Static Application Security Testing (SAST), Cloud Security, Full-stack, Big Data Architecture, Big Data, Security Architecture, Dynamic Application Security Testing (DAST), Vulnerability Management, DevSecOps, SOC 2, C, Management, Microservices Architecture, Secure SDLC, Web Security, APIs, DevOps, CI/CD Pipelines, OWASP Top 10, Security Operations Centers (SOC), Java, SIEM, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset Management
  • Senior Software Engineer

    2017 - 2018
    EPAM Systems
    • Consulted technical personnel. Managed client requirements on industry-best practices. Discussed, persuaded, and agreed on the most innovative approaches applicable in the customer landscape.
    • Worked closely with the management and development organizational units. Secured enterprise-level software applications and solutions that met or exceeded client demands with an eye for the most efficient and cost-effective solutions.
    • Supported the organization’s offshore unit. Improved the end-to-end stability and security posture of environments and tools.
    • Led technology research, solution budgeting, feasibility, and evaluation. Spearheaded proof of concepts (PoC) to make imperative decisions. Trained the development teams on secure software development lifecycle (SDLC) practices.
    • Contributed as part of an interview panel. Reviewed DevOps Profiles in the market for the requirements and initial screening. Mentored junior engineers on the company culture, solutions, and tools.
    • Conducted internal audits. Led IT and cloud security policy reviews. Identified, fixed, and presented compliance related improvements to senior management.
    Technologies: DevOps, DevSecOps, Secure SDLC, CI/CD Pipelines, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Amazon Web Services (AWS), Azure, Cloud Security, Security, Security Architecture, Application Security, Vulnerability Management, ISO 27001, GDPR, SOC 2, C, Management, Microservices Architecture, Web Security, APIs, Full-stack, OWASP Top 10, Security Operations Centers (SOC), Java, SIEM, Tenable, Qualys, Veracode, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset Management
  • Senior Software Engineer

    2013 - 2017
    Progress
    • Led all DevOps Operations. Deployed, automated, maintained, and troubleshot. Tuned multi-tier and distributed cloud-based application components hosted on AWS.
    • Troubleshot issues in real-time across the whole stack. Conducted audit trails and account access reviews. Worked on compliance assignments related to SOC 2.
    • Facilitated and provided support (for internal and external parties). Ensured cyber security incident management and response for the alerts and events triggered by SIEM, and IDS/IPS solutions.
    • Worked closely with the other teams to assess risk and provide recommendations for improving our security posture.
    • Served as the point of contact and escalation for all cloud security operations center events for the offshore unit in Hyderabad.
    • Assisted lower-level software engineers and new recruits to the team. Educated them about the security knowledge, tools, and processes.
    • Kept up to date with knowledge of current standard system security practices.
    Technologies: DevOps, DevSecOps, Cloud Security, Security Operations Centers (SOC), Security, Software Development Lifecycle (SDLC), Static Application Security Testing (SAST), Veracode, Qualys, Tenable, SIEM, Java, OWASP Top 10, CI/CD Pipelines, APIs, Web Security, Secure SDLC, Amazon Web Services (AWS), Management, SOC 2, Vulnerability Management, Dynamic Application Security Testing (DAST), Application Security, SecOps, Cybersecurity, IT Security, Asset Management

Experience

  • Deployment and Configuration of AWS Native Security Tools

    Completed PoCs on the latest versions of AWS native security tools like Security Hub and GuardDuty. I deployed them to production environments and configured and fine-tuned the false positives and deployment automation around them.

  • Deployed Azure Native Cloud Security Tools

    Deployed and configured Azure native cloud security tools like Microsoft Azure Security Center and Azure Sentinel. These baselines are for cloud security posture management and cloud workload protection. I fine-tuned the alerts and documented the project implementation

  • Static Analysis Process Integration into CI/CD Pipelines

    Deployed and configured static code. I used analysis tools and introduced secure SDLC concepts into development CI/CD pipelines. I automated the process and documented the setup. I also executed a few demos for the development teams

Skills

  • Tools

    Jenkins, AWS SDK, SonarQube, Puppet, Chef
  • Paradigms

    DevSecOps, Management, DevOps, Security Software Development, Penetration Testing, Microservices Architecture, HIPAA Compliance
  • Platforms

    Amazon Web Services (AWS), Linux, Azure, Google Cloud Platform (GCP)
  • Industry Expertise

    Security, Cybersecurity, IT Security
  • Other

    Vulnerability Management, SOC 2, Cloud Security, Web Security, OWASP Top 10, Security Operations Centers (SOC), Tenable, SIEM, Architecture, Data Protection, Authentication, Vulnerability Identification, APIs, Cloud, Ethical Hacking, Risk Management, SecOps, Vulnerability Assessment, PCI, NIST, Software Development Lifecycle (SDLC), Identity & Access Management (IAM), Asset Management, Security Design, Security Audits, Cloud Computing, Monitoring, SSL, Load Balancers, Application Security, Static Application Security Testing (SAST), ISO 27001, Security Architecture, Big Data Architecture, CI/CD Pipelines, Veracode, Qualys, IT Management, Big Data, Full-stack, Mobile Security, Dynamic Application Security Testing (DAST), GDPR, Secure SDLC, OAuth, AWS DevOps
  • Languages

    Java, Python
  • Frameworks

    OAuth 2
  • Libraries/APIs

    OpenID

Education

  • Master's Degree in Bioinformatics
    2006 - 2008
    Bharathidasan University - Tiruchirappalli, India

To view more profiles

Join Toptal
Share it with others