S

Santhosh Kumar Janagam

CEO

Hyderabad, Telangana, India15 yrs 7 mos experience
AI ML PractitionerAI Enabled

Key Highlights

  • Expert in AI/ML security and threat modeling.
  • Proven track record in secure product architecture.
  • Strong leadership in embedding security in development.
Stackforce AI infers this person is a Cybersecurity Architect specializing in AI security within the Healthcare sector.

Contact

Skills

Core Skills

Product SecurityAi SecurityApi SecurityAi Safety And GovernanceApplication SecuritySecure Software Design

Other Skills

Product Security StrategySecure SDLCSecurity Architecture DesignAgentic AI SecurityCCSPCloud SecurityCybersecurity for AI SystemsRetrieval-Augmented Generation (RAG)Application Security AssessmentsPrompt EngineeringThreat ModelingGenerative AI (GenAI)DevSecOpsApplication Security ArchitectureAzure Security

About

In an era defined by AI transformation, securing autonomous systems and AI-driven workflows has become mission-critical. My work sits at the intersection of AI security architecture, application security, and enterprise risk, helping teams innovate safely while building AI-powered systems that meet regulatory requirements and earn stakeholder trust. I began my career in e-commerce, building and securing applications in fast-moving environments where security issues surface quickly and at scale. That experience shaped how I approach security today: practical, embedded, and aligned with how engineers and product teams work. Over time, I've expanded that foundation across the secure SDLC, partnering with developers, architects, product, privacy, and compliance teams to bring security into design from concept through deployment. My role has focused on security architecture and product security strategy—defining secure-by-default patterns, frameworks, and guardrails teams can reuse across enterprise and cloud-native platforms. I regularly lead threat modeling across all seven layers, architecture reviews, and security assessments for complex applications, APIs, and distributed systems, using frameworks such as MAESTRO, STRIDE, DREAD, PASTA, and OCTAVE to translate emerging threats into actionable controls and rollout plans. I've driven adoption of modern API protection, identity-aware patterns (OAuth2, OIDC, mTLS), DevSecOps practices, and policy-as-code approaches, embedding automated controls into CI/CD pipelines. My technical depth spans cloud security (AWS/Azure), Kubernetes, microservices governance, and zero-trust architectures. Recently, I've focused intensively on AI/ML security—securing LLM applications, addressing agentic AI risks including prompt injection and insecure code generation, implementing Model Context Protocol (MCP) security patterns, and building data protection frameworks aligned with emerging AI regulations and assurance standards. I excel at mentoring architects and security professionals, producing consumable technical documentation (security requirements, design patterns, reference architectures), and influencing cross-functional teams through clear communication. I'm most effective combining hands-on architectural depth with strategic leadership to deliver secure, compliant AI solutions. Specialties: AI/ML Security, LLM Security, Security Architecture, Threat Modeling, API Security, Cloud Security, Zero Trust, DevSecOps, CISSP, CSSLP, CCSP.

Experience

Evernorth health services

Cyber Security Senior Advisor

Nov 2025Present · 5 mos · Hyderabad, Telangana, India · Hybrid

  • Shape and drive the long-term product, application, and agentic AI security vision for major healthcare technology initiatives, aligning architecture with regulatory, privacy, and patient data protection requirements.
  • Partner closely with engineering, product, enterprise architecture, data science, and privacy teams to embed secure-by-design and AI-aware security practices early in product and platform design.
  • Lead the security strategy and maturity roadmap for the enterprise product security program, integrating Application Security Posture Management (ASPM), automated risk prioritization, and continuous assurance.
  • Guide teams in building secure, scalable, modern cloud-native architectures, including agentic AI systems, addressing model I/O abuse, prompt injection, and Agent-to-Agent (A2A), Agent-to-Process (A2P), and multi-agent orchestration trust boundaries.
  • Conduct architecture-level threat modeling, design reviews, security assessments, and vulnerability analysis to ensure risk-aware product delivery and measurable reduction of high-risk findings.
  • Define and integrate automated AppSec and AI security controls into CI/CD pipelines (SAST, DAST, SCA, IaC, policy-as-code), improving coverage, efficiency, and reliability while minimizing developer friction.
  • Lead benchmarking and assessment of AI-powered code remediation and AI-assisted (“vibing”) coding tools, establishing guardrails for data protection, access control, auditability, and IP safety.
  • Support product and AI security incident response, translating lessons learned into platform-level controls to improve long-term resilience.
  • Manage and mentor security team members across the HIH region, strengthening technical depth, architectural thinking, and security culture.
  • Stay ahead of emerging threats, agentic AI patterns, and industry trends, incorporating insights into strategic security planning and architecture evolution.
Product SecurityProduct Security StrategySecure SDLCSecurity Architecture DesignAI SecurityAgentic AI Security

Wells fargo

5 roles

Vice President - Lead Information Security - Software Security Group

Promoted

Oct 2023Nov 2025 · 2 yrs 1 mo

  • Directed secure design reviews for AI agents and LLM-powered assistants, proactively identifying and mitigating emerging threats such as prompt injection, tool misuse, and cross-agent task hijacking.
  • Led comprehensive threat modeling for advanced AI use cases, including RAG pipelines, agentic workflows, and model fine-tuning to ensure data privacy and system integrity.
  • Developed comprehensive Security Architecture Design Patterns and cloud-secure blueprints, aligning group security requirements with regulatory mandates and industry best practices.
  • Established strategies to address risks associated with AI-generated code, integrating security into automated workflows to identify vulnerabilities that evade traditional analysis methods.
  • Spearheaded the development of secure coding standards for AI systems, focusing on critical safeguards like output validation, robust model access controls, and prompt injection defenses.
  • Championed a "Shift Left" approach by partnering with ML and Cloud engineering teams to embed security controls early in the AI development lifecycle.
  • Collaborated with Product and ML stakeholders to define safety requirements for enterprise chatbots, including context boundary controls, intent validation, and fallback mechanisms.
  • Conducted deep-dive research and documentation for new technology acquisitions, ensuring all emerging tech meets strict security posture requirements and organizational standards.
  • Contributed to the Security Architecture risk evaluation process, proposing tactical and strategic remediation plans backed by thorough cost/risk benefit analyses.
  • Advocated for secure-by-design practices across technical delivery teams, overseeing third-party deliverables and ensuring compliance with ISO 27000 and ITIL frameworks.
  • Represented the organization in internal and external security matters, promoting security initiatives while staying abreast of global regulatory trends and industry shifts.
API SecurityAI Safety and GovernanceCCSPCloud SecurityCybersecurity for AI SystemsRetrieval-Augmented Generation (RAG)+9

Information Security Engineer V

Promoted

Mar 2020Aug 2022 · 2 yrs 5 mos

  • Perform Security code review using automated and manual.
  • Perform Security Architecture and Low-Level Application Security Design review involving CIA triad, IAAA.
  • Collaborate with business units and perform threat modelling on new and existing products and features to help guide security activities, suggesting preferred implementation patterns and identifying areas of security risk for scrutiny.
  • Perform risk analysis using Qualitative and Quantitative based approach.
  • Maintaining a current awareness of trends, threats, and regulations (ex. PCI, GDPR) that impact related development processes and standards.
  • Designing and deploying application security tools and processes to support OWASP Top 10 alignment of critical central Secure Software Development Lifecycle controls.
  • Collaborating with internal and external development teams (Java, .Net, C#, etc.) to integrate security tools, standards, and processes into the product life cycle.
  • Providing application security expertise to support the incident response and architecture review processes.
  • Actively participate in Agile Scrum Methodology.
  • Develop the application dashboard using rest with angular.
  • Ensure the applications are in compliance with Organization Policies, Standards and Regulations such as SOX, GLB Act, NIST, PCI-DSS, ISO/IEC, and GDPR.
  • Mentor junior engineers and help level-up their deep understanding of Application Security.
  • Provide insight into the latest application security vulnerabilities and exploits
  • Conduct manual security assessments against web applications and APIs across a variety of technology stacks.
API SecurityNISTProduct SecurityCISSPApplication Security AssessmentsData Privacy+11

Information Security Engineer IV

Dec 2016Feb 2020 · 3 yrs 2 mos

  • Proficient in secure coding practices with deep expertise in identifying and remediating vulnerabilities aligned with OWASP Top 10 and SANS 25.
  • Conduct detailed security source code reviews across multiple languages and frameworks including JavaScript, Java, .NET, Node.js, Angular, and SPA-supporting technologies.
  • Provide secure coding guidance and remediation support to development teams across the organization.
  • Evaluate, deploy, and manage both commercial and open-source application security testing tools at enterprise scale.
  • Conduct automated code and application scans, understanding the strengths and limitations of tools across diverse platforms.
  • Provide strategic recommendations for Web Application and API Protection (WAAP) tooling, helping secure modern web and API assets.
MicroservicesNISTData PrivacyRisk ManagementCSSLP

Senior AVP - Senior Systems Architect - Application Security | Threat Modeling

Promoted

Sep 2014Feb 2024 · 9 yrs 5 mos

  • Led engaging threat modeling workshops across product, infrastructure, and data science teams—uncovering design risks early and embedding secure-by-default thinking into development.
  • Designed and implemented security architectures across Azure, and AI/ML platforms, building strong, scalable foundations aligned with evolving business needs.
  • Conducted secure code reviews in .NET, Java and Python, working closely with developers to identify vulnerabilities and improve secure coding practices.
  • Translated regulatory requirements into actionable, audit-ready controls supporting Three Lines of Defense and enterprise governance models.
  • Defined and tracked Key Risk Indicators (KRIs), performing root cause analyses to proactively resolve recurring issues and strengthen operational resilience.
  • Acted as a trusted advisor to engineers, product teams, and executives during security reviews and incidents, helping drive informed and timely decisions.
  • Provided technical guidance to internal teams, vendors, and partners, aligning security practices with software development lifecycles and DevSecOps pipelines.
  • Championed secure SDLC adoption by integrating tooling, training teams, and embedding best practices across workflows.
  • Supported the secure adoption of emerging technologies—AI/ML, microservices, and serverless—by shaping architectural decisions and risk mitigation strategies.
  • Conducted deep risk assessments of AI pipelines, addressing ethical use, data privacy, and misuse prevention with proactive strategies.
  • Developed and enforced governance policies for responsible AI, aligned with NIST, ISO, and internal ethical standards.
  • Delivered executive-level updates on GenAI risks, threat trends, and mitigation approaches, helping leadership align on strategic priorities.
  • Mentored peers and early-career professionals, fostering a culture of continuous learning and shared security ownership.
API SecurityAI Safety and GovernanceNISTApplication SecurityCCSPGovernance, Risk Management, and Compliance (GRC)+16

Information Security Engineer - III | Security Automation & Engineering

Sep 2014Nov 2016 · 2 yrs 2 mos

  • Performed Security Code Review for various lines of business.
  • Designed and developed Security Code Review dashboard.
  • Developed reporting tools for Security Code Review.
  • Implemented SSRS reports for delivering metrics to Leadership Team.
Risk Management

Kantar tns

Software Engineer

Aug 2013Sep 2014 · 1 yr 1 mo · Hyderabad Area, India · On-site

  • Designed and developed secure applications using the Microsoft .NET stack (C#, ASP.NET, MVC), embedding security controls directly into application logic.
  • Implemented authentication, authorization, MFA, and cryptographic protections (encryption and hashing) to secure sensitive data and privileged workflows.
  • Conducted attack surface analysis, secure code reviews, static analysis, and white-box penetration testing across applications and APIs.
  • Identified, assessed, and prioritized vulnerabilities using CWE, CVEs, and CVSS, working with engineering teams to drive timely remediation.
  • Deployed and secured applications in cloud environments, addressing application and infrastructure risks while mentoring developers on secure coding practices.
API SecurityMicroservicesSecure Software DesignScrumRESTC#+1

T-mobile

Web and eCommerce Development - Senior Security Engineer @ HCL Tech

Dec 2010Aug 2013 · 2 yrs 8 mos · Noida Area, India

  • Bridged the gap between business and technical teams by coordinating with stakeholders to develop comprehensive Requirements Traceability Matrices (RTM) for functional and non-functional security requirements.
  • Hardened application integrity by implementing delay signing on source code to prevent unauthorized tampering and ensured secure deployments.
  • Led end-to-end vulnerability management, including performing penetration testing in pre-production environments and conducting deep-dive root cause analyses on security bugs.
  • Eliminated OWASP Top 10 risks by performing rigorous source code analysis and manual peer reviews on enterprise-level applications.
  • Architected robust access and data protection models, implementing Role-Based Access Control (RBAC) and managing complex cryptographic operations (encryption, hashing, and key management).
  • Enhanced web service security by implementing WS-Security protocols and assisting the Security Architect in designing secure Service-Oriented Architectures (SOA).
  • Ensured operational resilience through active participation in Business Continuity Planning (BCP), managing secure database backups, and conducting post-mortem analyses on critical production incidents.
  • Maintained rigorous compliance and documentation standards, aligning development workflows with ITIL and ISO 27000 frameworks.
  • Drove proactive risk discovery by developing use/misuse cases and identifying undocumented features during the testing lifecycle.
  • Environment: Frameworks/Tech: .NET (C#, ASP.NET), WCF, REST, Web Services, SharePoint Server. Frontend: JSON, jQuery, JavaScript, XML. Database/OS: SQL Server. Tools: JIRA, HP Quality Centre, AccuRev, StarTeam (Version Control), IBM Core Metrics.
API SecurityMicroservices

Hcl technologies

Software Engineer

Sep 2010Aug 2013 · 2 yrs 11 mos · New Delhi Area, India

  • Partnered with a diverse portfolio of international clients to deliver high-performance applications tailored for global markets.
  • Demonstrated versatility across the SDLC, navigating both the structured requirements of Waterfall and the fast-paced, iterative nature of Agile environments.
  • Strengthened e-commerce platforms by designing and implementing custom security frameworks to protect sensitive user data and ensure secure transactions.
MicroservicesApplication SecurityCryptographyAngularJSSecure CodingC#

Education

Jawaharlal Nehru Technological University

Engineer's Degree — Computer Science

Indian Institute of Technology, Guwahati

Certificate in Applied Generative AI — Applied Generative AI

Mar 2025Jun 2025

Stackforce found 100+ more professionals with Product Security & Ai Security

Explore similar profiles based on matching skills and experience