Adipradeep Kumar Mummadisetty

CTO

Bengaluru, Karnataka, India19 yrs experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Expert in integrating security into development processes.
  • Proven track record in managing security incidents and audits.
  • Strong leadership in application security and team management.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in Fintech and Application Security.

Contact

Skills

Core Skills

CybersecurityDevsecopsApplication SecurityProgram ManagementIt Strategy

Other Skills

AWS SecurityAgile MethodologiesCloud SecurityEJBEthical HackingInformation SecurityInformation TechnologyJSFJSPJavaNetwork SecurityOWASPOraclePenetration TestingProduct Security

About

From the moment I started my career in cybersecurity, I have been deeply fascinated by the field. Over the years, I have encountered and navigated numerous challenges—ranging from addressing complex technical issues to effectively managing and leading a team. These challenges have pushed me to continuously learn, adapt, and refine my skills. I'm eager to contribute my expertise and experience to a challenging and rewarding role like this.

Experience

Envestnet | yodlee india | tcs

Head of Product Security

Nov 2022Present · 3 yrs 4 mos · Bengaluru, Karnataka, India · On-site

  • Implementing and maintaining corporate security policies entails establishing guidelines to safeguard an organization's sensitive information from unauthorized access, disclosure, disruption, or destruction. This involves creating/updating policies covering areas like access control, incident response, and data protection.
  • Collaborating with application development teams to integrate a Secure SDLC ensures security is embedded in the development process across the organization. This aids in early identification and mitigation of potential security risks.
  • Handling Security Incidents and Client response involves managing security incidents, communicating with clients about resolutions, and ensuring follow-up actions.
  • Influencing decision-making processes at all levels of the organization involves closely working with management to ensure security is a key consideration in business decisions.
  • Facilitated PCI and SOC2 Annual audits, providing evidence and interviews with auditors, ensuring organizational compliance with industry standards and regulations.
  • Providing security certification support for AWS migration involves working with IT teams to meet security requirements during the migration to Amazon Web Services.
  • Implementing DevSecOps and automated VAPT involves integrating security into the software development process and automating vulnerability testing for timely identification and remediation.
  • Integrating security tools like DAST, SAST, Web Application Firewall, and Open Source Vulnerability Management tools enhances the security program's performance, identifying vulnerabilities early in the development life cycle.
  • Supporting Annual External Penetration tests involves working with third-party vendors to thoroughly test the organization's systems for vulnerabilities.
  • Managing scope, budget, and staff for the product security program involves overseeing planning, execution, and budgeting, as well as managing the team responsible for implementation.
CybersecurityDevSecOps

Envestnet | yodlee india

3 roles

Senior Product Security Manager

Promoted

Sep 2019Nov 2022 · 3 yrs 2 mos

  • Working with multiple application development teams of Envestnet Yodlee and other business units to integrate Secure SDLC program in development process.
  • Managing Application security team from Bangalore.
  • Managed to transform the unorganised work to organised work by adopting Agile scrum methodology.
  • Worked on Vulnerability management, improved existing process and able to close vulnerabilities as per the SLA.
  • Improved the processes and usage of integrated CI tools into development life cycle.
  • Expertise in reviewing the Application architecture and code reviews.
  • Worked with release management team to define the scope of the application security teams responsibilites and prioritising product backlogs.
  • Reviewed AWS architecture for onpremise to AWS migration project.
  • Evaluated multiple security tools which suites Envestnet business needs.
  • Implemented WAF for Envestnet applications.
  • Supported incident response for zero day vulnerabilities.
  • Worked with Infosec team and part of Audit interviews such as SOC2, PCI and Client audits.
  • provided support to External pentest performed by third party vendors and Client Pentests.
CybersecurityProgram ManagementOWASPInformation TechnologyProduct SecurityCloud Security+11

Principal Application Security Specialist

Promoted

Apr 2017Sep 2019 · 2 yrs 5 mos

  • Worked with multiple application development teams of Envestnet Yodlee, Envestnet Tamarac, Envestnet FolioDx to integrate Secure SDLC program in the development process.
  • Expertise in reviewing the Application architecture and code reviews.
  • Evaluated multiple DAST tools and SCA tools that suites Envestnet business needs.
  • Integrated CI tools into the CICD process of multiple business units and ensure the process is followed.
  • Supported incident response for zero-day vulnerabilities.
  • Worked with various teams to provide Audit related evidence such as SOC2, PCI, and Client audits.
Program ManagementOWASPInformation TechnologyProduct SecurityApplication SecurityIT Strategy+7

Senior Application Security Specialist

Feb 2016Mar 2017 · 1 yr 1 mo

Bnp paribas india solutions private limited

Technical lead

Apr 2014Feb 2016 · 1 yr 10 mos · Chennai, Tamil Nadu, India

  • Project Name: STARR(System of Tax reclaim & Relief) Apr ’14 – till date
  • Client BNP Paribas
  • Environment Java 6,JSP, Struts 2,Tomcat 5, WTX, Crystal reports,
  • Sweetdev UI framework, Oracle 10g
  • Project Description:
  • Tax reclaim:
  • When an income (dividend, interest payment) is credited to an investor
  • Payment is taxed at source by the tax authorities issuing country.
  • Foreign investors are also taxed by their local tax authorities.
  • To avoid or reduce this double taxation, many tax authorities have defined
  • bilateral Double Taxation Agreements (DTA) reducing the tax rate applied making
  • cross-border investment more attractive.
  • In the tax reclaim procedure, income paid to the foreign investor is first fully
  • taxed, i.e. not taking into account the DTA.
  • Providing tax reclaim forms to the tax authorities of the investment country to
  • claim the difference amount as per DTA.
  • Tax relief at source:
  • Only French market
  • BP2S Paris acts as paying agent, income is paid with reduced tax rate applied at
  • source.
  • Role: Designation & Description
  • As a Technical Lead, Involved in development , Reviews and Interacting
  • with Business Analyst for requirements.
Program ManagementInformation TechnologyIT StrategyAgile Methodologies

Tata consultancy services

Information Technology Consultant

Dec 2012Apr 2014 · 1 yr 4 mos · Chennai, Tamil Nadu, India

  • Project Name: ENP Dec ’12 – till date
  • Client PruHealth
  • Environment Java,EJB3.0,JSF2.0,JBoss , JPA1.0, Webservices
  • Project Description:
  • The Eve on New Platform project is providing the PruHealth business with a suite of system solutions to support ongoing business requirements based around the Heal and Papillon systems. A key driver behind this is to remove PruHealth’s dependence on solutions that are owned and operated by Standard Life and allow PruHealth to exit the TSA agreement with Standard Life. Therefore there is a requirement to replace the functionality provided by the Standard Life owned systems and rewrite the Heal policy admin system.
  • Role: Designation & Description
  • As a senior software developer, Involved in development.
  • Team Size
  • 20
  • Responsibilities:
  •  Acting as a scrum master for the interfaces team.
  •  Preparing the HLD and LLD for the given requirements.
  •  Providing the estimations and task breakdown for the requirements.
  •  Preparing the Unit test plan and Unit Test cases.
  •  Implementing the code as per the design.
  •  Interacting with the third party Interfaces for the integrations.
  •  Involved in the status update meetings with management.
  •  Facilitating the internal show and tell.
  •  Facilitating the KSS with in the team.
Program ManagementInformation TechnologyIT StrategyAgile Methodologies

Hexaware technologies

Senior Software Engineer

Jan 2011Nov 2012 · 1 yr 10 mos · Chennai, Tamil Nadu, India

  • Project Name: MepI
  • Client DBSystel
  • Environment Java,EJB3.0,JSF2.0,JBoss , JPA1.0
  • Project Description:
  • MEP-IT is the People management services with skill, Demand, Disposition, Recruitment Management. MEP IT Administrator Perform HR Import activities with scheduled time. Employee can create a Profile based on the Basis data such as e.g., competences, expertise, countries, and languages. In addition the organizational allocation of an employee to his Organization unit is also performed. The manager checks the profile and can approve the changes or decline them. In demand Management service Contract created by Consumer, It can be used by Employees and send it to Disponent for approval. In disposition the Disponent Can Allocate the employee and reject the employee profiles. Dispositon depicts the interrelationship between the various statuses of a service contract. Recruitment tightly coupled with demand and disposition. Each stakeholder has its own rights and role to perform their role.
  • Role: Designation & Description
  • As a senior software doveloper, Involved in development.
  •  Involved in the requirement analysis and creating the required artifacts.
  •  Involving in dev and preparing the unit test cases.
  •  Involved in bug fix analysis and tracking the issues
  •  Participating in the discussion with the clients for clarifications.
  •  Involved in the live deployment of the application.
  •  KT sessions to team members on application functionality.
  •  Involved in the Development and bug fixing.
  •  Owned Basis Data module and delivered without any defects.
  •  Peer code reviews are done and guided the team to resolve the issues.
  •  Global Exception handler is implemented in JSF frame work to handle Exceptions.
  •  Developed Custom JSF components to meet the customer requirement.
  •  Written PL/SQL queries for the Reporting module to generate the reports based on the inputs provided by the user.
  •  Developed custom component to move the error messages from properties files to Database.
Information Technology

Cognizant

Associate

Jun 2010Dec 2010 · 6 mos · Chennai, Tamil Nadu, India

  • Project Name: Comet Jun ’10 – Dec ’10
  • Client Comet
  • Environment Java, J2EE (Servlet/JSP/EJB, Struts 1.1, DB2, Endeca navigational search engine. WCS, AIX.
  • Project Description:
  • The Client offers a unique all-round shopping experience with a range of services including home delivery, full installation of products such as televisions and computers, take back facilities for large products, and comprehensive after sales service. Client needs support for all eCommerce applications and few critical processes to be monitored which updates data on daily basis. The web application also interacts with lot of third parties where these interfaces need to be monitored regularly. It also includes in handling minor enhancements for the applications we support.
  • Role: Designation & Description
  • As a Associate, Involved in Production support.
  • Team Size
  • 5
  • Responsibilities:
  •  Providing support for all ecommerce applications.
  •  Monitoring key stand alone applications which update the databases with latest data.
  •  Involving in bug-fix.
  •  Reports progress and issues to the lead/ Manager in a timely manner.
  •  Understanding architecture of the system and involving in providing services based on the business requests.
  •  Handling CR’s & enhancements.
Information Technology

Polaris software ltd

Associate Consultant

Nov 2006May 2010 · 3 yrs 6 mos · Chennai, Tamil Nadu, India

  • Project Name: R&TA Mailback Nov’06 – May'10
  • Client Deutsche Investor Private Limited
  • Environment Solaris-10, Weblogic-8.1, Oracle-9, Java, J2EE (Servlet/JSP/EJB), Struts-1.0
  • Project Description:
  • Deutsche bank plans to provide Internet services to its R&TA system end users namely Investors, Distributors and AMC representatives for Reports Mailback Facility. To serve this end , Deutsche bank requires ‘Mailback service ‘ to be built to service its Internet users. This system would send a mail hand off to Deutsche bank upon request from the user over the internet, & in turn use the information in the mail hand off to generate the user requested Report from the R&TA intranet system & mail them to the appropriate end user. Broadly the Mail Back Services consist of User Online Registration., User Authorization & Profile Capture at BackOffice, Reports Subscription/Un subscription, Forgot Password, Denial of Service Attack, SMTP Mail Service, audit Reporting, Enquiries, Customer Communication reports, Online transactions.
  • Role: Designation & Description
  • As a senior developer, Involved in Development and Production support.
  • Team Size
  • 7
  • Responsibilities:
  •  Involved in Requirement/Impact analysis and creating the necessary
  • artifacts based on the guidelines.
  •  Writes application code to meet expected quality standards , identifies
  • and creating unit test cases.
  •  Participates in technical walkthroughs/ code reviews of other team
  • members.
  •  Reports progress and issues to the lead/ Manager in a timely manner.
  •  Creating, maintaining and updating the design documentation for the modules.
  • Interacting with Clients for support them in UAT testing and Production
  • issues/outages.
Information Technology

Education

Sri Venkateswara University

Master of Computer Applications - MCA — Computer Science

May 2003Apr 2006

Sri Venkateswara University

Bachelor of computer applications — Computer Science

May 2000Apr 2003

Stackforce found 100+ more professionals with Cybersecurity & Devsecops

Explore similar profiles based on matching skills and experience