Hemanth Kamepalli
Senior Application Security Engineer @Citadel
Signup · Get unlimited contacts
WORK HISTORY
Senior Application Security Engineer @Citadel
Miami, FL, US
Financial Services — Real-Time Trading & Portfolio Analytics Platform• Led 100+ high-risk exposure remediations — end-to-end application security assessments mapped to OWASP Top 10 and OWASP ASVS Level 2 in a SOC 2-compliant environment.• Cut mean-time-to-detect (MTTD) by 60% — deployed SAST (Checkmarx, Semgrep) and SCA (Snyk) into Jenkins and GitHub Actions with shift-left security gates on every pull request.• Reduced attack surface before a line was coded — championed STRIDE-based threat modeling for trading components and market-data APIs at the design phase.• Uncovered flaws automated scanners missed — manual secure code reviews across JavaScript, TypeScript, and Node.js exposing broken access controls and data-exposure risks.• Hardened AWS infrastructure (S3, CloudFront, IAM, GuardDuty) — enforced least-privilege entitlements, encryption at rest and in transit, and continuous misconfiguration monitoring.
EDUCATION
KKR&KSR Institute of Technology & Sciences, VINJANAMPADU Village (CC-JR)
Bachelors Of Technology in Electronics and Communication Engineering , Masters of Information Technology Management|
Lindsey Wilson University
Masters of Information Technology Management
ABOUT HEMANTH KAMEPALLI
I am with 5 years of experience securing web applications, APIs, and CI/CD pipelines at Citadel (financial services) and HealthEdge (healthcare SaaS).I specialize in SAST, DAST, SCA, threat modeling (STRIDE), penetration testing, and DevSecOps automation — closing 100+ high-risk exposures, cutting MTTD by 60%, and achieving HIPAA and SOC 2 compliance at scale: SAST, DAST, SCA & manual secure code review Threat modeling — STRIDE, PASTA DevSecOps pipeline automation (Jenkins, GitHub Actions, GitLab CI) AWS cloud security — IAM, GuardDuty, Security Hub, WAF, KMS Compliance — HIPAA, SOC 2, OWASP Top 10, OWASP ASVS, NIST SSDF :→ Closed 100+ high-risk exposures at Citadel (SOC 2-compliant trading platform)→ Surfaced 150+ weaknesses in HIPAA-regulated PHI/PII system at HealthEdge→ Reduced MTTD by 60% using automated SAST/SCA gates in CI/CD→ Reduced AWS misconfigurations by 40% over 3 years at HCL Technologies :Burp Suite Pro · OWASP ZAP · Checkmarx · Semgrep · SonarQube · Snyk · Trivy · DefectDojo · Jenkins · GitHub Actions · AWS GuardDuty :Application Security Engineer · Senior Application Security Engineer · DevSecOps Engineer · Product Security Engineer · Security Engineer(US-based · Remote · Open to relocation from Louisville, KY)\'!If you\'re hiring for Application Security, DevSecOps, or Penetration Testing roles — or just want to connect with someone passionate about AppSec — feel free to reach out! h••••••••@gmail.com +1 (502) happy to connect with fellow security professionals, recruiters, and hiring managers. Let\'s build something secure together!
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.