Gopi Kaveripakkam

CEO

Chennai, Tamil Nadu, India24 yrs 6 mos experience

Key Highlights

  • 18+ years of experience in cybersecurity frameworks
  • Expertise in embedded device security and penetration testing
  • Proficient in major cybersecurity standards and tools
Stackforce AI infers this person is a Cybersecurity Architect specializing in embedded systems and application security across multiple industries.

Contact

Skills

Core Skills

DevsecopsApplication SecurityCybersecurity Risk ManagementCybersecurity SolutionsRisk ManagementPenetration TestingSecure SdlcSecurity In SdlcNetwork Protocols TestingSystem TestingEmbedded Testing

Other Skills

AWS Well Architect Framework - Security Pillar implementationsApplication Security and Penetration TestingCyber Security Solution and Architect frameworksDASTDevSecOps framework developmentDevSecOps practicesDevSecOps solutions & implementationsEmbedded SecurityEmbedded SystemsIoT/Cloud SecurityLayer2Layer2, Layer3 Protocols TestingLayer2/Layer3 Protocols TestingLayer3 Protocols TestingLinux

About

Having 18+ years of experience in implementing and executing the cyber security frameworks across the organizations. It includes Cybersecurity Requirements / Controls, Cyber Security Risk Management, Risk Assessments, Threat Modelling, Cyber Security Solution and Architecture, Penetration Testing, Secure Coding, Secure product development life cycles / SecDevOps / DevSecOps. These Solutions and Services included for different domains such as Medical, ICS, Fintech/Banking, Automotive, Telecom, E-commerce. Embedded device security implementation and penetration testing for Embedded Linux, Windows, QNX, Android, FreeRTOS. Major Embedded security solutions on Hardware HSM, Secure Boot, Trust of chain, Secure Firmware, Disk Encryption, OS hardening, Embedded application and communication. Embedded interfaces such as Ethernet, BLE, WiFi, GSM, USB, Serial Port UART etc. Expertise in Penetration test execution, DevSecOps/Secure SDLC framework implementations, Security design principles, secure design review, Secure coding, secure code review. These frameworks and approaches are incorporated across the organization in Application development, Network & Protocols based products, IoT/Cloud Embedded based products, BACnet/ Modbus Protocols applications, Wireless/Mobile applications, ICS & Infrastructure based products and L2/L3 protocols-based products. Expertise in Major SAST/DAST tools like Veracode platform, BupSuite, Nessus, IBM AppScan, Fortify etc. Expertise in Penetration testing tools like BurpSuite, Kali Linux Tools, Wireshark etc. Expertise in Manual secure code review for Java, C#, Java Script languages, C/C++ etc. Responsibility to give the trainings/presentations for Development, Testing, Senior Management, Organizations, Customers etc. Developed the automated penetration test framework for web application and integrated in CI/CD pipelines. Implementing the Cyber Security Solutions with Data Science and Machine Learning (ML) Models and solving the current Cyber Security Challenges in the product development life cycles. Expertise in Cybersecurity Standards such as NIST 800-53, NISTIR8228, NIST 800-35, NIST 800-153, NIST 800-97, NIST SP1800-4, NIST 800-121, OWASP TOP10 (web, mobile, cloud, IoT), SANS CWE TOP25 etc. Domain Specific Standards: GDPR, HIPAA, FDA, ISO 14971, TIR 57, ISO 21434, UNECE –WP.29, SAE J3061 Products: Web Application, REST APIs, Database, Embedded connected device, Embedded peripheral device, Embedded standalone devices, IoT/Cloud (AWS, Azure, Google Cloud etc.)

Experience

Einfochips (an arrow company)

Cybersecurity Architect

Mar 2025Present · 1 yr · Chennai, Tamil Nadu, India · Hybrid

Stl digital

Cybersecurity - Senior Solution Architect

Jan 2023Feb 2025 · 2 yrs 1 mo · Chennai, Tamil Nadu, India · Remote

  • Working Security in Presales (RFP/RFI, SOW), Secure Design & Architect Practices, AWS Well Architect Framework - Security Pillar implementations, DevSecOps solutions & implementations, Penetration Testing, Vulnerability Assessments & SOC Operations implementations.
Security in PresalesSecure Design & Architect PracticesAWS Well Architect Framework - Security Pillar implementationsDevSecOps solutions & implementationsPenetration TestingVulnerability Assessments+3

Ericsson digital services

Cybersecurity-Senior Solution Architect

Jul 2021Jan 2023 · 1 yr 6 mos · Chennai, Tamil Nadu, India · Remote

  • Implemented & delivered end to end security activities for the applications or productions across the organization.
  • Such as Security in Presales, Security Requirements, Secure Architecture and Design practices, Threat Model, Risk Assessments, Privacy Impact Assessment (PIA) as per the GDPR, Secure Component Selection Practices, Secure Coding, SAST, SCA, DAST, DevSecOps practices, Penetration Testing, Hardening, Vulnerability Scanning for production systems, Security bug fix & Retest etc.
  • Technologies:
  • Containerized Applications Docker, Kuberneties & Microservices, Cloud & IoT based solutions, 5G Solutions, Embedded Devices, Mobile Applications.
  • Security Standards Followed:
  • Ericsson SRM (internal), OWASP TOP10, SANS CWE TOP25, NIST 800-XX, ISO 27001, ISMS audit, ISO 31000 Risk Assessment, SEI CERT, MISRA, CIS bench mark etc.
  • Security Tools used:
  • Threat Model: Microsoft Threat Model Tool, OWASP Threat Dragon & Manaul Approaches
  • Privacy Impact Assessment (PIA): OneTrust & Trade Compliance
  • SAST: Snyk, Sonarqube, Detectsecret, Dependency Tracker
  • SCA: Dependency Tracker, Blackduck
  • Containerized Scan: Kube hunter, Kube Bench, Trivy, Snyk
  • DevSecOps Stages & Integration: SAST, SCA, DAST, Penetration Test, Vulnerability Scan, Governance Dashboard
  • Penetration Test: Burpsuite, KALI Linux Tools
  • Vulnerability Assessment: Rapid7, Tenable SC, Nessus Professional
  • SOC Operations: SIEM Tools & Monitoring
  • Cloud Security Tools: Amazon Inspect, Security Hub, Amazon Artifact, Cloud Watch & Cloud Trail
  • Organization Security BootCamp Training: Owned Security Bootcamp Training & Practices across the organization
  • Domain: Teleco Security, Medical Domain Security. Automotive Domain Security, Banking & Fintech Security, E-Commerce Security, Office & Industrialized Automations etc.
Security in PresalesSecurity RequirementsSecure Architecture and Design practicesThreat ModelRisk AssessmentsPrivacy Impact Assessment (PIA)+9

Hcl technologies

Cybersecurity-Senior Architect and Subject Matter Expert (SME)

Jul 2019Jul 2021 · 2 yrs · Chennai Area, India

  • Implementing the executing the below mentioned Cyber Security Solutions across the Organization products.
  • 1. Implementing and executing the Cyber Security Risk Management, Risk Assessments, Cyber Security Solution and Architect frameworks,
  • Penetration Testing, Secure Coding, Secure product development life cycles, Security Automation etc. These Solutions and Services included for different products and domains like Medical & IoT devices, Healthcare Applications, ICS with IoT, Embedded with IoT devices, Linux kernels and Chipsets etc.
  • 2. Implementing the Cyber Security Solutions with Data Science and Machine Learning (ML) Models and solving the current Cyber Security Solutions, Challenges in the product development life cycles.
  • 3. Implementing and standardizing the Cybersecurity process and Artifacts across the organization quality management systems.
  • 4. Implementing the End to End Cyber Security Solutions for Embedded firmware, Chipset, Linux kernel, Web Application, Web Services, Protocols Stack, SDK etc.
  • 5. Cyber Security Solutions for major domains such as Medical, Healthcare. ICS, Banking/Fintech, Automotive.
Cyber Security Risk ManagementRisk AssessmentsCyber Security Solution and Architect frameworksPenetration TestingSecure CodingSecure product development life cycles+3

Intellect design arena ltd

Cybersecurity Architect

Dec 2018Jul 2019 · 7 mos · Chennai Area, India

  • Penetration Testing frameworks developments, Penetration Test Execution.
  • Secure SDLC, Secure Sprint, DevSecOps framework development and implementations.
  • Static & Dynamic scanning using Veracode Platform and tools like BurpSuite.
  • Secure Architect Review, Threat and Risk Analysis for applications and AWS infrastructure.
Penetration Testing frameworks developmentsSecure SDLCSecure SprintDevSecOps framework developmentStatic & Dynamic scanningSecure Architect Review+2

Siemens ltd

Penetration Testing, DevSecOps/Secure SDLC/Security in SDLC Engineer

Mar 2012Dec 2018 · 6 yrs 9 mos · Chennai

  • Expertise to design & develop the Penetration test frameworks and conducting the Penetration testing for different technology based products including Application Security, Network Protocols including Layer2/Layer3 Security, IoT/Cloud Security, Embedded Security, BACnet/Modbus Protocols Security, Wireless Security, Mobile Security and Infrastructure Security.
  • Expertise in performing the attacks simulation for external and internal attacker aspects using security tools. Also expertise to use security tools like Burp suite professional, ZAP proxy, Nessus, wireshark and other Kali Linux tools.
  • Expertise in conducting the penetration testing on BLACK BOX, GRAY BOX and WHITE BOX aspects. Expertise in executing the in-depth manual security penetration test, known vulnerability assessment and CVE vulnerabilities. Expertise to test the Security Penetration Test in different platform and framework (including Java, C# .NET, C/C++, Python etc).
  • Expertise to provide the mitigations or countermeasures to prevent the attacks in penetration testing & security in SDLC.
  • Expertise in developing the new technologies, approaches and automations in cyber security domain including penetration testing, DevSecOps/Secure SDLC/Security in SDLC. Expertise to provide the training on Security Penetration Test, DevSecOps and security automations.
  • Expertise in developing the DevSecOps/Security in SDLC/Secure SDLC frameworks for web application, rich application, IoT/Cloud based embedded applications, Mobile/Wireless applications, Network/protocols based applications, ICS applications etc.
  • Expertise in developing the DeVSecOps/security in SDLC/Secure SDLC approaches & automations to get secure requirements, secure design patterns, secure coding guidelines both development & operations phases.
Penetration testing frameworksApplication SecurityNetwork Protocols SecurityIoT/Cloud SecurityEmbedded SecurityPenetration Testing+1

Vmc systems ltd.

Development Engineer

Feb 2010Feb 2012 · 2 yrs · Hyderabad Area, India

  • Network and Protocols Testing
  • Layer2, Layer3 Protocols Testing
  • Wireless and Telecommunication Protocols Testing
  • ADSL2/2++ Routers and Wimax CPEs Protocols Testing
  • Linux, Perl, Python scripting and Automation Development
  • Layer2 protocols like VLAN, STP, RSTP, MSTP, IGMP Snooping, VTP testing
  • Layer3 Protocols like EIGRP, OSPF, BGP testing
  • Layer4 protocols UDP and TCP testing
  • Application Protocols like DHCP, SNMP, SMTP, HTTP, HTTPS, SMB, NTP testing
  • Telecommunication protocols like SIP, RTP, RTCP testing
Network and Protocols TestingLayer2, Layer3 Protocols TestingWireless and Telecommunication Protocols TestingLinux, Perl, Python scriptingNetwork Protocols Testing

Midas communication technologies

Test Engineer

Apr 2005Feb 2010 · 4 yrs 10 mos · Chennai

  • Layer2/Layer3 Protocols Testing
  • Wireless (CorDECT) System Testing
  • System Load and Performance Testing
  • Linux shell scripting
  • UDP socket programming using VC++
Layer2/Layer3 Protocols TestingWireless System TestingSystem Load and Performance TestingLinux shell scriptingSystem Testing

Signals & systems india pvt ltd

Embedded Testing

Jul 2001Mar 2005 · 3 yrs 8 mos · Chennai

  • Micro controller based System Testing.
  • Micro controller interfaces Testing like RS232, RS485, Parallel Port, ISR.
  • SMPS, DC/DC converter Testing and development.
Microcontroller based System TestingMicrocontroller interfaces TestingEmbedded Testing

Education

Birla Institute of Technology and Science, Pilani

Bachelor of Science (BS) — Information Systems

Jan 2006Jan 2009

Goverment Polytechnic

Diploma in Electronics & Communicaton Engineering

Jan 1998Jan 2001

Tiruttani

Stackforce found 100+ more professionals with Devsecops & Application Security

Explore similar profiles based on matching skills and experience