Ratnesh Tiwari

DevOps Engineer

India15 yrs 5 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over a decade of experience in cybersecurity.
  • Led security initiatives for major tech companies.
  • Expert in integrating security into development processes.
Stackforce AI infers this person is a Cybersecurity expert specializing in SaaS and Fintech security solutions.

Contact

Skills

Core Skills

Secure Architecture & DesignDevsecopsOffensive SecurityOrganizational Leadership

Other Skills

Secure Coding

About

With over a decade of experience in cybersecurity, I have been helping organizations build secure products.

Experience

15 yrs 5 mos
Total Experience
2 yrs 6 mos
Average Tenure
3 yrs 11 mos
Current Experience

Linkedin

Senior Platform and Product Security Engineer

May 2022Present · 3 yrs 11 mos

  • Led the security strategy and implementation for LinkedIn’s mission-critical Machine Learning (ML) infrastructure, supporting over a billion global members.
  • Designed and implemented enterprise-level security controls across LinkedIn's ML ecosystem, including secure data lakes, distributed training clusters, MLOps pipelines, model registries, and high-throughput serving platforms. This comprehensive approach minimized the attack surface while enabling the secure scaling of thousands of production ML models.
  • Spearheaded multiple Purple Teaming exercises with cross-functional teams, simulating real-world adversarial attacks to rigorously test and validate security controls. Insights from these exercises identified critical infrastructure gaps, driving enhanced detection and mitigation.
  • Led threat modeling and security design reviews for LinkedIn platforms and applications, establishing standardized security requirements that accelerated secure development practices. This approach ensured compliance with evolving privacy regulations while maintaining high operational efficiency.
  • Created and enforced comprehensive security standards and guidelines for cloud environments.
  • Ran the Security Champions program for the AI org, fostering security awareness and building a culture of proactive risk management across engineering teams.
  • Actively participated in internal security conferences and Capture The Flag (CTF) events to stay at the forefront of evolving threats and security innovations.
Secure Architecture & DesignOffensive SecurityDevSecOps

Vmware

2 roles

Lead Security Engineer

Promoted

Sep 2020May 2022 · 1 yr 8 mos

  • Led security team at VMware, overseeing comprehensive security strategy across platforms and applications.
  • Performed end-to-end security reviews including architecture assessments, design reviews, code reviews, penetration testing, and red/purple teaming for complex VMware products. Collaborated to mitigate identified threats and vulnerabilities.
  • Led VMware's DevSecOps initiative, integrating SAST, DAST, OSS, and IaC security into the DevOps pipeline to efficiently identify and mitigate threats at scale.
  • Designed and executed cloud and container security roadmap, securing millions of workloads on AWS, Azure, and Kubernetes through hardening, policy enforcement, drift detection, and control validation.
  • Developed a centralized risk and vulnerability management platform with executive dashboards, automated prioritization, and self-service scanning.
  • Trained hundreds of engineers on security best practices and fostered a culture of security awareness through internal events.
Organizational LeadershipSecure Architecture & DesignOffensive SecuritySecure CodingDevSecOps

Senior Security Engineer

Apr 2018Sep 2020 · 2 yrs 5 mos

Ey

Senior Consultant - Cybersecurity

Jan 2017Apr 2018 · 1 yr 3 mos

  • Advised clients on best practices for securing their products, providing tailored solutions to mitigate vulnerabilities and enhance overall security posture.
  • Conducted comprehensive security assessments, including secure architecture and design reviews, threat modeling, and penetration testing, to identify and address risks in critical applications and platforms.
  • Performed security reviews for IoT systems in industrial automation and transportation, ensuring the security of smart, connected devices and infrastructure.
  • Managed the security hiring process, from defining staffing needs and crafting job descriptions to screening resumes, conducting interviews, and evaluating technical skills.
  • Championed security awareness by developing and delivering comprehensive training programs for development and operations teams on critical security topics, fostering a culture of security-minded practices.
Organizational LeadershipSecure Architecture & DesignOffensive SecuritySecure CodingDevSecOps

Hsbc

Senior Information Security Analyst

Apr 2015Jan 2017 · 1 yr 9 mos

  • Performed threat modeling, penetration testing, and code reviews for various banking applications to identify and mitigate security vulnerabilities.
  • Conducted security assessments for Android and iOS mobile applications to uncover potential risks and weaknesses.
  • Built a vulnerable web application as a learning tool to help developers enhance their application security skills.
  • Delivered security workshops and training sessions to developers, covering advanced topics such as cross-site scripting (XSS), remote code execution (RCE), and threat modeling.
  • Interviewed candidates with security expertise and provided feedback to management to support effective hiring decisions.
Offensive SecuritySecure Coding

Fidelity international

Security Consultant

Mar 2014Apr 2015 · 1 yr 1 mo

  • Perform Threat Modelling, Penetration Testing and Code Review for financial applications.
  • Integrate SAST and DAST into build pipeline.
  • Management and Monitoring of Web Application Firewall(F5 BGP-IP LTM). Involved in virtual patching zero days, firewall rule configuration, attack monitoring and incidence response.
  • Deliver security workshops and training sessions to developers.
Offensive SecuritySecure Coding

Igate global solutions

Senior Engineer

Nov 2010Mar 2014 · 3 yrs 4 mos

  • Perform Vulnerability Assessment and Penetration Testing on hundreds of Banking applications and platforms for wide range of customers.
  • Perform automated and manual Secure Code Review.
  • Exploit writing for identified vulnerabilities.
  • Develop in-house risk & vulnerability management platform.
Offensive SecuritySecure Coding

Education

Birla Institute of Technology and Science, Pilani

Post Graduate - WILP — Artificial Intelligence and Machine Learning

Mar 2023Mar 2024

West Bengal University of Technology, Kolkata

Computer Science and Engineering

Jan 2006Jan 2010

Stackforce found 100+ more professionals with Secure Architecture & Design & Devsecops

Explore similar profiles based on matching skills and experience