Pravin R Ponnusamy
Senior Application Security Engineer @Zepz
Signup · Get unlimited contacts
WORK HISTORY
Senior Application Security Engineer @Zepz
GB
web and mobile application security- AI security threat modelling - Shifting the security to the left by adding security scanning solutions at scale in GitHub workflows- writing policy-as-code for ensuring secure application being developed and deployed in micro services - Manage edge security cloudflare WAF of the org and deploy the configuration changes using terraform- Handling security incident and contributing from appsec- Enabling security for development team using standard process and frameworks- Managing bug bounty program - Aws security review for containers and infrastructure- Security automation for security metrics and to simply manual efforts
EDUCATION
Amrita Vishwa Vidyapeetham
Bachelor's degree, Computer Engineering
University of Hertfordshire
Master's degree, Cyber security
ABOUT PRAVIN R PONNUSAMY
Performed Threat Modelling the application architecture using attack patterns and Data-Flow diagram for web and mobile applications to identify potential security gaps and threat landscape- Designed security architecture for web and mobile application using OWASP application security verification standard(ASVS)- Performed secure code review in build-release for Java,C#,Python, PHP,Typescript applications as part of SAST - Carried out DAST/penetration testing tasks for live or staging applications on ad-hoc requests and identified multiple critical issues such as account take-over, logging sensitive details and more- Automated tooling for DevSecOps process using python, bash, docker and Jenkins groovy scripting- Ensured applications are built and onboarded on containers safely- security posture management for web, mobile applications- Delivered security OKRs timely in fast phased security team- Designed and delivered security presentation for engineering teamSkills-Secure SDLC,Threat Modeling, Secure Code review, Python security automation, DevSecOps, Public Key Cryptography, Container security-STRIDE, OWASP Secure coding, SANS, OWASP Top 10 vulnerabilities, Agile, water fall, CI/CD-Manual source code review for Python Flask, Php, NodeJs/Express, HTML, JavaScript, Java and ASP.net-Secure code review, business logic flaws, authentication/authorization flaws, OWASP Top 10 and SANS, SAST, DAST-Integrating Trufflehog, safety, Fortify,synk, nuclei, clair, trivy, OWASP Zap, nmap, sslyze in CI/CD pipeline, integrating customized tools-Python, bash-BurpSuite, HP Fortify, IBM Appscan, PostMan, Metasploit, OWASP Zap, Nmap, SqlMap, Trufflehog
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.