Sundarigari Manoj

DevOps Engineer

Bengaluru, Karnataka, India11 yrs 11 mos experience
Highly Stable

Key Highlights

  • Over 12 years of experience in security testing.
  • Expertise in both web and mobile security.
  • Strong background in compliance and risk management.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in security testing and risk management.

Contact

Skills

Core Skills

Security TestingSecurity ManagementWeb Application SecurityRisk ManagementVulnerability AssessmentsPenetration TestingData SecurityMonitoringStatic Application Security TestingDynamic Application Security Testing

Other Skills

Application Programming Interfaces (API)Application SecurityApplication Security ArchitectureApplication Security Standard TestingAuthenticationBlack DuckBurp SuiteCloud SecurityCode ReviewComplianceCryptographyCybersecurityDDoS attack mitigationEclipseEnd point security

About

12+ years of experience on Security Testing of Web, Network and Mobile. Web application Security Testing and Security Architecture - SAST and DAST Application Threat Modeling using STRIDE/DREAD/CVSS/Attack Tree Enterprise Network Security- Internal and External IP Scanning End point security and management Mobile security (iOS/Android), Engineering Design Reviews, Security Architect. Security Management - Secure Policies, Standards and Procedures with proper change management, Incident management and Risk Management process. Compliance - ISO-27001, GDPR, PCIDSS, HIPPA , OWASP Top 10, SANS Top 25 Tools: Web Vulnerability Scanners (DAST): IBM App scan Standard, HP Web Inspect, Acunetix, Nessus, Burpsuite, ZAP Network Vulnerability Scanners (DAST): Qualys, Nessus Static Code Scanners: IBM App scan Source, Veracode, Coverity, Fortify, Black Duck, Snyk End Point Security and Management: Mcafee Virus Scan Enterprise, IPS, IDS, DLP, Browser Protection, SIEM, Cloud ePO, Mcafee Agent, SIEM Penetration Testing: Metasploit, nmap, Wireshark, Hydra, netcat, Burpsuite Proxy, Kali Linux experience in Software Automation, Performance Testing, Build deployments, Test Setup, DevOps, Virtualization. Tools: Automation: Selenium Webdriver (C# / Java), SQL 2008/2012, SOAP UI, Postman, WCF Test Services, MS Test, TestNG, Maven, Log4j and ApachePOI. CD/CI Pipelines. Performance: New Relic, Xperf, Perfmon, SQL profiler, VSTS WebTests

Experience

Microsoft

Senior Security Engineer

Apr 2024Present · 1 yr 11 mos · India

  • I drive proactive security measures by simulating real-world attacks to identify and mitigate potential threats. My role blends strategic planning, hands-on execution, and close collaboration with security teams to ensure our defenses are robust and adaptive.
  • Key Responsibilities:
  • Experience on Security Testing of Web, Network and Mobile.
  • Web application Security Testing and Security Architecture - SAST and DAST
  • Application Threat Modeling using STRIDE/DREAD/CVSS/Attack Tree
  • Enterprise Network Security- Internal and External IP Scanning
  • End point security and management
  • Mobile security
  • Security Management - Secure Policies, Standards and Procedures with proper change management, Incident management and Risk Management process.
  • Compliance - ISO-27001, GDPR, PCIDSS, HIPPA , OWASP Top 10, SANS Top 25
  • Tools:
  • Web Vulnerability Scanners (DAST): IBM App scan Standard, HP Web Inspect, Acunetix, Nessus, Burpsuite, ZAP
  • Network Vulnerability Scanners (DAST): Akamai WAF, Qualys, Nessus, TruffleHog. Paloalto, load balance, Arista Switches
  • Static Code Scanners: Fortify, IBM App scan Source, Veracode, Coverity, Black Duck Hub.
  • End Point Security and Management: Mcafee Virus Scan Enterprise, IPS, IDS, DLP, Browser Protection, SIEM, Cloud ePO, Mcafee Agent, SIEM
  • Penetration Testing: Metasploit, nmap, Wireshark, Hydra, netcat, Burpsuite Proxy, Kali Linux
  • experience in Software Automation, Performance Testing, Build deployments, Test Setup, DevOps, Virtualization.
  • API Security, Cloud Security: CI/CD pipelines using Jenkins and Artificial intelligence (AI) Scans, LLM (prompt injections).
Security TestingWeb application Security TestingSecurity ArchitectureThreat ModelingNetwork SecurityEnd point security+3

Uber

Security Engineer II

Mar 2022Mar 2024 · 2 yrs · Bengaluru, Karnataka, India

  • Experience on Security Testing of Web, Network and Mobile.
  • Web application Security Testing and Security Architecture - SAST and DAST
  • Application Threat Modeling using STRIDE/DREAD/CVSS/Attack Tree
  • Enterprise Network Security- Internal and External IP Scanning
  • End point security and management
  • Mobile security
  • Security Management - Secure Policies, Standards and Procedures with proper change management, Incident management and Risk Management process.
  • Compliance - ISO-27001, GDPR, PCIDSS, HIPPA , OWASP Top 10, SANS Top 25
  • Tools:
  • Web Vulnerability Scanners (DAST): IBM App scan Standard, HP Web Inspect, Acunetix, Nessus, Burpsuite, ZAP
  • Network Vulnerability Scanners (DAST): Qualys, Nessus, TruffleHog - API KEYS.
  • Static Code Scanners: Fortify, IBM App scan Source, Veracode, Coverity
  • End Point Security and Management: Mcafee Virus Scan Enterprise, IPS, IDS, DLP, Browser Protection, SIEM, Cloud ePO, Mcafee Agent, SIEM
  • Penetration Testing: Metasploit, nmap, Wireshark, Hydra, netcat, Burpsuite Proxy, Kali Linux
  • experience in Software Automation, Performance Testing, Build deployments, Test Setup, DevOps, Virtualization.
  • API Security, Cloud Security: CI/CD pipelines using Jenkins.
  • Tools:
  • Automation: Selenium Webdriver (C# / Java), SQL 2008/2012, SOAP UI, Postman, WCF Test Services, MS Test, TestNG, Maven, Log4j and ApachePOI.
  • Performance: New Relic, Xperf, Perfmon, SQL profiler, VSTS WebTests
Security TestingWeb application Security TestingSecurity ArchitectureThreat ModelingNetwork SecurityEnd point security+3

Amazon

3 roles

Sr. Prod Compliance Associate

Promoted

Jan 2018Mar 2022 · 4 yrs 2 mos

  • Web Application Security, Penetration Testing, Code Review, Threat Modellingand AWS Cloud Security,Risk Management, OWASPTop 10, Burp suite, Nmap, Metasploit.
  • Actively monitoring security components to ensure that confidentiality, integrity,and availability of all information assets are ensured.
  • McAfee ePolicy Orchestrator, Virus Scanner, Drive Encryption, Data Loss Prevention, TIE, File and Removable media Protection, Endpoint Security (ENS), Nessus, Symantec Message Labs, Barracuda IPS/IDS, Splunk Enterprise, Sparta, Qualys Enterprise, and SIEM Enterprise
  • AWS Cloud Infrastructure -Configure and fine tune cloud infrastructure systems
  • Ubuntu, Kali, RHEVLinux Administrator as anIntermediateLevel
  • Experienced and workingon ticketing systems like Incident Management, Problem management and ITIL Process with tools based on Service-Now, HPSM, Remedy tool and ITSS Ticket Management✓Experienced in Administering, monitoring,and maintaining LINUX & Windows IT infrastructure.
Web Application SecurityPenetration TestingCode ReviewThreat ModelingRisk ManagementCompliance+1

Prod Compliance Associate

Promoted

Jan 2016Apr 2018 · 2 yrs 3 mos

  • Performed vulnerability assessments and penetration testing on web application and providing comprehensive report with recommendations.
  • Ability to work as part of a team and to build strong relationships with relevant individual
  • Interact with customers in a collaborative, consultative manner to deliver results, provide feedback and remediation recommendations on findings.
  • Performed Application Security Standard Testing (ASST) on internal applications.
  • Good exposure to Security Testing on DAST and started working on SAST.
  • Have experience in SQL Injection, XSS (Cross site scripting) attacks and major hacking protection techniques.
  • Hands on experience in working with penetration testing tools like Burp suite, Web Inspect, ZAP , sqlmap.
  • Analyze application security vulnerabilities found through testing and collaborate with development and other internal technical teams to provide mitigation steps to reduce the risk.
  • Ability to apply experience and expertise to problem solving in a complex technical environment.
  • Preparing vulnerability assessment report and manual verification of testing results.
  • Re-validation of vulnerabilities after developer closing them and providing go or no go from application security perspectives
Vulnerability AssessmentsPenetration TestingApplication Security Standard TestingSQL InjectionXSS attacks

Catalog Assistant

Feb 2014Dec 2015 · 1 yr 10 mos

  • DDoS attack: UDP/ICMP Flood, SYN Flood,HTTP Get Flood, TCP Connection Attack, TCPFlag-based Attacks.
  • DataSecurity: McAfee Data Loss Prevention, RSA Data Loss Prevention Suite, Websense's Content Protection Suite, Guardium, PKI, RSA Secure ID, DLP, digital signature.
  • Monitoring:AWS CloudWatch,AWS Config,BMC Patrol, Manage Engine, and Bluecoat.
  • Honeypots: Database Honeypots (Elastic honey), Web honeypots (Glastopf, Shadow Daemon, Google Hack Honeypot), Service Honeypots (Kippo, troje), Deployment (Dionaea, honeypotpi).
  • Microsoft technologies: -Microsoft Identity Manager (MIM), AD, LDAP, Windows PKI, SharePoint, WSUS and SQL Server.✓Cryptography: Encryption Algorithms, Digital Signature, Deploying PKI.✓SIEM: MacAfee ESM (Nitro), RSA Envision and Splunk
  • Malware Analysis: Process Explorer, Process Monitor.✓Virtualization: VMWARE, VMWARE ESXI and ORACLE VIRTUAL BOX.✓Process Skills: InformationSecurityManagement System, BCP/DR Planning.
DDoS attack mitigationData SecurityMonitoringCryptographyMalware Analysis

Pi techniques pvt. ltd.

Web desinger

Aug 2013Feb 2014 · 6 mos · Hyderabad, Telangana, India

  • Static Application Security Testing (SAST):•Experience in performing automated Static Application Security Testing and Secure Code Review•Performed manual code reviews.•Evaluated security vulnerabilities and prepared customized Vulnerability Assessment Reports along with Recommendations.•Develop secure code practices and provide Remediation Assistance to development teams.•Good hands on Static scanning tools -IBM APPScan Source Code Edition, SecureAssist.
  • Dynamic Application Security Testing (DAST):•Experience in performing automated Dynamic Application Security Testing.•Assessment of web applications for security vulnerabilities and design flaws.•Performed manual validation of Security Vulnerabilities.•Evaluated security vulnerabilities and prepared customized Vulnerability Assessment Report along with Recommendations.•Good hands on various dynamic scanning tools like WebInspect, HP AMP Tool, HP Toolkit, IBM APPScan etc.
Static Application Security TestingDynamic Application Security TestingVulnerability Assessment Reports

Education

Jawaharlal Nehru Technological University Kakinada (JNTUK)

Master of Technology - MTech — Cybersecurity

Apr 2025Present

Visvesvaraya Technological University

Bachelor of Engineering (B.E.) — Electronics and Communications Engineering

Jan 2013Present

Stackforce found 100+ more professionals with Security Testing & Security Management

Explore similar profiles based on matching skills and experience