Vandan R.

DevOps Manager

Bengaluru, Karnataka, India3 yrs 2 mos experience

Key Highlights

  • 25 years of survival on a dangerous planet.
  • Expert in cloud security and automation.
  • Proven track record in vulnerability management.
Stackforce AI infers this person is a Cloud Security Engineer with expertise in SaaS and Infrastructure Automation.

Contact

Skills

Core Skills

Cloud SecurityKubernetesInfrastructure AutomationSecurity EngineeringProgrammingAutomation

Other Skills

Google Cloud Platform (GCP)PythonTerraformLinuxBurp SuitePalo Alto XDRGo (Programming Language)CybersecurityGitAmazon Web Services (AWS)ContainerizationComputer ScienceCommunicationdockerPython (Programming Language)

About

Please checkout the experience section if you want to know about my experience. Please checkout the skills section if you want to know about my skills. My achievement is surviving for 25 years straight on an inhabited planet with dangers such as volcanoes and sparkling water.

Experience

Mobile premier league (mpl)

Security Engineer

Feb 2024Aug 2025 · 1 yr 6 mos · Bengaluru, Karnataka, India · On-site

  • Collaborated cross team to roll out various K8s security mech-
  • anisms such as:
  • 1. Distroless golden images
  • 2. Least privilege RBAC
  • 3. (Calico) Network policies
  • 4. Workload identity
  • 5. Real-time admission controller monitoring
  • 6. Seccomp profiles
  • 7. Cluster level misconfigs such as public access, vul-
  • nerable open ports and default service accounts
  • Worked with SRE and developers to architect and im-
  • plement general Cloud security including:
  • 1. Fine grained IAM for developers and workloads
  • 2. Private service connect
  • 3. Cloud bucket best practices
  • 4. Implementing alternatives to Service account keys
  • 5. Secret management
  • 6. Organization policies for best practice enforcement
  • 7. VM golden images hardened using Packer and Jenk-
  • ins
  • 8. cloud functions for slack alerting
  • 9. Utilizing Prisma cloud for remediating container and
  • cloud vulnerabilities
  • 10. Database access management and strategies
  • 11. Implementing Cloud Armor (web application firewall policies)
  • Developed MITM proxy scripts for in-game websocket
  • pentesting and other quality of life automations using
  • python.
  • Performed external/internal asset monitoring and inci-
  • dent response using Cortex XDR
  • Deployed and maintained tools for monitoring and vul-
  • nerability management on K8s such as defectdojo, ELK
  • stack etc.
  • Performed Phishing campaigns with a success rate of
  • 13% including full account takeovers (bypassing 2FA
  • mechanism).
  • Worked with compliance auditors to ensure smooth delivery of proofs.
  • Performed technical POCs and price negotiations (~68% reduction) for on-boarding tools.
  • Tools:
  • Prisma Cloud CSPM
  • GKE
  • GCP
  • Python
  • Terraform
  • Linux
  • Burp Suite
  • Palo Alto XDR
Google Cloud Platform (GCP)KubernetesPythonTerraformLinuxBurp Suite+2

Oportun

Security Engineer

Oct 2022Feb 2024 · 1 yr 4 mos · India · Remote

  • As part of the Security Architecture team:
  • Coding up services (using Go) and Deploying them using Kubernetes
  • Acted as on-call for own services
  • Managing infrastructure using Terraform (AWS, Signal Sciences, GitHub...)
  • Helped create and deploy custom technical architecture.
  • Maintained the SOAR platform (playbooks, integrations, custom Python actions, IAM, POC)
  • Metrics collection and monitoring
  • Achievements:
  • Found 100+ hard-coded secrets in git repositories
  • Saved hours of manual work during tool migration
  • Automated security alert validation and alerting
  • Helped save $$$ by developing custom in-house solutions
Go (Programming Language)TerraformSecurity EngineeringCybersecurityGitCloud Security+4

Google summer of code

Mentee

May 2022Sep 2022 · 4 mos

  • Working on a project under the OWASP
  • Foundation, Core rule set team.
  • An open source project to automate the
  • process of testing exploit PoCs against mod-
  • security web application firewall running
  • rules from Core rule set.
  • (Also, It's CI/CD friendly!)
Computer ScienceProgrammingCommunicationdockerGitAutomation+7

Seclogic inc

Associate Cloud developer

Dec 2021Jul 2022 · 7 mos · Noida, Uttar Pradesh, India

  • Worked on customer facing cloud security SaaS product
  • Analysed, Audited and Remediated cloud compliance rules for AWS
  • manually as well as automatically using Python
  • Created an automation for testing Terraform scripts and AWS Lambda
  • functions.
  • Automated Infrastructure deployment using Terraform.
  • Automated the entire process of Client onboarding in GCP using
  • deployment manager.
  • Worked on services such as ECS, ECR, EC2, S3, IAM etc.
  • Utilized Python and Bash to automate tedious tasks
Computer ScienceTerraformProgrammingInfrastructure as code (IaC)CommunicationAutomation+9

Cybernx technologies private limited

SOC Analyst intern

Jun 2021Sep 2021 · 3 mos

  • Performed Monitoring of large client infrastructures
  • Handling Detection alerts and helping the clients remediate security
  • issues.
  • Worked with ELK Stack (as a SIEM), Arcsight and OSquery.
  • created dashboards in Kibana for infrastructure monitoring
  • Performed Threat Hunting using Elastic Search.
  • Created detection rules for malicious activities and Ransomwares
  • such as Lockbit and Ryuk.
Computer ScienceCommunicationElastic Stack (ELK)Computer EngineeringEnglish

Tensecure

Intern

Sep 2020May 2021 · 8 mos

  • Performed VAPT on Web applications and successfully exploited
  • critical vulnerabilities such as SMTP takeover, MySQL injection,
  • Misconfigured CORS, OTP bypass etc.
  • Studied The Mitre Att&ck Framework and OWASP top 10.
Computer SciencePython (Programming Language)Computer Engineering

Iipc gtbit

ML mentor

Aug 2019Dec 2019 · 4 mos · New Delhi Area, India

Computer Science

Education

Guru Gobind Singh Indraprastha University

Bachelor of Technology - BTech — Information Technology

Aug 2018Jul 2022

Stackforce found 100+ more professionals with Cloud Security & Kubernetes

Explore similar profiles based on matching skills and experience