Ankit Kumar — DevOps Engineer
Senior Security Engineer with 9+ years of experience and hands-on a range of security domains from SecureSDLC, DAST, SAST, SCA, VA/PT, BugBounty, Threat hunting & AWS security. Skilled in WebApplication Security, DevSecOps, Cloud Security, Infra Security, Linux, Amazon Web Services (AWS), and Python (programming language). Cloud Security: Assisting the team in crafting security baselines, encompassing IAM (Identity and Access Management), Logging and Monitoring, Data Protection, Infrastructure Security, and Incident Response. Conducting regular security assessments on AWS services to ensure ongoing protection. DevSecOps: Collaborating with the team to create secure products through activities such as Architecture Reviews and Threat Modelling. Architecting CI/CD pipelines for the automation of secrets scanning, Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) solutions. Implementing automated static analysis for Infrastructure as Code. Vulnerability Assessment (VA) / Penetration Testing: Conducting Penetration Testing external & Internal on applications, including Web Apps and APIs. Vulnerability Assessment of Cloud Infra and Corp Infra Additional Responsibilities: Configuring and setting up SIEM (Security Information and Event Management) solutions. Configuring and deploying Data Loss Prevention (DLP) measures. Assisting the company in achieving ISO 27001 and SOC2 compliance. Tools & Technical Skills: CSPM: Wiz, CloudGuard (Dome9), Prisma Cloud DAST - Dynamic Assessment: Acunetix, Whitehat, HCL AppScan, Burp Suite Pro, HP WebInspect SAST - Source Code Review: CheckMarx SCA - BlackDuck, Github Dependabot RBVM (Risk-Based Vulnerability Management Software) - Kenna Security Mobile Application Security & API testing: DataTheorem Vulnerability Assessment and Policy Compliance: QualysGuard, Nessus, and Tenable IO Issue & Project Tracking Tool: Jira SIEM: Demisto, BlackStratus, ArcSight, Splunk, Arbor, Qradar, and Nagios. IPS/IDS: Alertlogic, F5, Cisco SourceFire IPS Firewalls: PAN (PaloAlto Networks), PacketFilter, Checkpoint URL Filtering: Netsweeper | Email Security: Mimecast, Proof point | EndPoint Detection/NexGen AV: CrowdStrike, CB defense/response
Stackforce AI infers this person is a Cloud Security and DevSecOps expert in the cybersecurity industry.
Location: Bengaluru, Karnataka, India
Experience: 9 yrs 3 mos
Skills
- Aws Security
- Cloud Security
- Devsecops
- Incident Response
- Application Security
- Network Security
Career Highlights
- 9+ years of diverse security engineering experience
- Expertise in AWS security and DevSecOps practices
- Proven track record in vulnerability assessments and incident response
Work Experience
Workato
Senior Security Engineer (1 yr 10 mos)
Bayzat
Senior Security Engineer (3 mos)
CoinSwitch
Cloud Security Engineer (2 yrs)
Nykaa
Senior Security Engineer (1 yr 2 mos)
Cognizant (Prediktive Contractor)
Application Security Analyst (5 mos)
Cvent
Application Security Engineer II (2 yrs)
Orange Business Services
Network Security Engineer (1 yr 9 mos)
GET-SOC (3 mos)
BERRY9 IT SERVICES (B9ITS)
Intern as a Security Analyst (2 mos)
Gurgaon Police Cyber Crime Cell
Intern (1 mo)
Education
MicroMasters Program at Rochester Institute of Technology
Bachelor of Technology (B.Tech.) at Shri Mata Vaishno Devi University