Ravichandra V
Application Security Engineer | SOC Expert | Security & Automation | AppSec & DevSecOps (SAST, DAST, SCA, RASP) | Cloud Security | IaC Security (Terraform) | Open to C2C Roles Across the US
- Role
- Senior Application Security Engineer at Truist
- Location
- Cape Girardeau, MO, US
- LinkedIn followers
- 500 followers
About Ravichandra V
With over 9 years of experience, I specialize in securing complex web, mobile, and cloud-native applications across financial services, healthcare, government, and tech sectors. My work is rooted in a deep understanding of secure SDLC, cloud security architecture (AWS, Azure, GCP), and integrating security into CI/CD pipelines using tools like Jenkins, GitHub Actions, and Azure DevOps.I\'m proficient in industry-leading tools such as Snyk, Fortify, Checkmarx, OWASP ZAP, Burp Suite, Metasploit, and experienced in threat modeling, secure code reviews, fuzz testing, and designing custom IDS/IPS signatures. I’ve led penetration testing engagements aligned with OWASP Top 10, integrated STRIDE, MITRE ATT & CK, and OWASP SAMM into enterprise programs, and ensured compliance with standards like HIPAA, PCI-DSS, FedRAMP, ISO 27001, and SOC 2.Cloud-savvy and DevSecOps-driven, I architect secure, scalable environments using Kubernetes, Helm, and AWS services like IAM, S3, EC2, and CloudWatch. I also actively manage OIDC, OAuth 2.0, and Azure Key Vault for secure identity and access management.I’m passionate about building secure software by collaborating closely with developers, mentoring junior engineers, and contributing to a culture of continuous improvement. Whether it’s building automation, conducting fuzz tests, or guiding security governance, I deliver security at scale.
Experience
Senior Application Security Engineer
Jul 2022 — Present · Pittsburgh, PA, US
Conducted root cause analysis (RCA) on identified security vulnerabilities discovered through SAST, DAST, IAST, and manual testing to ensure long-term remediation and prevent recurrence.• Performed dynamic application security testing (DAST) using Fortify WebInspect to identify real-time vulnerabilities in web applications.• Extensive expertise in Dynamic Application Security Testing (DAST), utilizing automated tools to perform scans on running applications and identify vulnerabilities in the runtime environment.• Conducted manual verification of Veracode findings to eliminate false positives and ensured accurate reporting of exploitable vulnerabilities.• Conducted thorough security assessments using tools like Checkmarx, IBM App-Scan, Nessus, Burp Suite, OWASP ZAP, and Metasploit.• Generated comprehensive reports using tools such as Fortify, Burp Suite, OWASP ZAP, Nessus, and Checkmarx, integrating manual testing insights and scanner findings.• Led secure code review sessions based on Veracode scan results, focusing on OWASP Top 10 vulnerabilities including SQL Injection, XSS, and insecure deserialization.• Conducted black-box, gray-box, and white-box penetration tests on web, mobile, and API-based applications, identifying critical vulnerabilities and security misconfigurations.• Developed custom fuzz testing tools and scripts to automate the identification of security flaws.• Collaborated with development teams to integrate fuzz testing into the software development lifecycle (SDLC).• Built custom Splunk dashboards and queries to monitor application-layer threats, authentication anomalies, and API activity for real-time visibility into security incidents.• Leveraged automation tools and scripts to streamline security processes, improving efficiency and reducing manual effort.• Designed and implemented secure CI/CD pipelines using Jenkins, GitLab CI, and GitHub Actions, integrating automated security scans and policy checks.
Education
JNTUH College of Engineering
Bachelor of Technology - BTech
2010 — 2014
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.