Ravindra Annam

CEO

Frisco, Texas, United States18 yrs 2 mos experience
AI EnabledAI ML Practitioner

Key Highlights

  • Expert in AI Security and Threat Modeling.
  • Proven track record in secure coding practices.
  • Passionate speaker on DevSecOps and AI defense.
Stackforce AI infers this person is a Cybersecurity Architect specializing in AI and Application Security.

Contact

Skills

Core Skills

Ai SecurityThreat ModelingDevsecopsApplication SecurityWeb Application SecurityInformation SecurityWebapplication Development

Other Skills

Product SecurityCloud SecuritySecure CodingApplication Security ArchitectureSecurity RequirementsDASTSASTSCAApplication Security Subject Matter ExpertAI ML LLM securityApplication Security LeaderArchitecture ReviewsPayment Card Industry Data Security Standard (PCI DSS)Vulnerability AssessmentAgile Methodologies

About

AI & Cyber Security Architect | Author | Speaker Currently serving as a Product/AI Security Architect at T-Mobile, I partner with engineering teams to design, build, and scale secure-by-design AI products. With a focus on LLM security (RAG, agents, prompt injection) and Cloud-Native AppSec, I bridge the gap between complex security requirements and rapid innovation. Beyond architecture, I am a passionate Author and Speaker, dedicated to sharing practical insights on DevSecOps, OWASP standards, and the future of AI defense. I help organizations reduce the risk of data leakage and AI abuse while maintaining alignment with business goals. Specialties: 🔹 AI/LLM Security: RAG, Agentic systems, Multi-agent orchestration. 🔹 Threat Modeling: Enterprise-scale secure design reviews. 🔹 AppSec & Cloud: SAST/DAST/SCA, AWS, Azure, and CI/CD security. 🔹 Strategy: S-SDLC, Secure Coding, and Compliance. 📌 Open to: Consulting, Keynote Speaking, and AI Security Advisory. Follow me for practical insights on AI Agent, LLM, and AppSec security.

Experience

18 yrs 2 mos
Total Experience
4 yrs 4 mos
Average Tenure
11 mos
Current Experience

T-mobile

Product /AI /Application Security Architect

Jun 2025 – Present · 11 mos · Frisco, Texas, United States · Hybrid

  • Conducted secure design reviews for AI agents, LLM-based assistants, and multi-agent systems, identifying risks like prompt injection, tool misuse, data exfiltration, and cross-agent task hijacking.
  • Conducted threat modeling and security reviews of AI use cases (e.g., RAG, agentic workflows, model fine-tuning, data labeling )
  • Driving secure coding standards and practices tailored to AI systems (e.g., prompt injection mitigation, output validation, model access controls)
  • Partnered with AI/ML, software engineering, and cloud teams to embed security early in the AI development lifecycle (shift left)
  • Partnered with product and ML teams to define security and safety requirements for LLM-based chatbots ,AI assistants and AI Agents, including context boundary controls, logging, fallback mechanisms, and user intent validation.
  • Contributed to the adoption of GenAI applications with pre-deployment security scanning, output sanitization, API key rotation, and access scoping for tools and models.
  • Collaborate with development teams to design and implement secure product architectures, ensuring compliance with security frameworks and best practices.
  • Conduct comprehensive threat modeling exercises to identify potential security threats and vulnerabilities in applications and systems.
  • Assess risks associated with various attack vectors and develop mitigation strategies to address identified risks.
  • Collaborate with development teams to integrate security controls into the software development lifecycle (SDLC).
  • Integrate security tools like SAST, DAST, and IAST into CI/CD pipelines to ensure continuous security validation.
  • Provide technical guidance, perform code and design reviews, and enforce secure coding practices across teams.
  • Utilized automated scanning tools and manual techniques to identify vulnerabilities in applications, networks, and systems.
  • Reviewed and enforced secure coding practices related to input validation across development teams.
AI SecurityProduct SecurityThreat ModelingApplication SecurityCloud SecurityDevSecOps

Pwc

Product Security /Application Security Architect/Analyst/Consultant/Engineer

Mar 2025 – May 2025 · 2 mos · Fulshear, Texas, United States · On-site

  • Develop and implement security strategies for product development lifecycles.
  • Conduct threat modeling to identify and mitigate potential risks in product designs.
  • Collaborate with development teams to integrate security into software products.
  • Define and enforce secure coding standards and best practices by adding security requirments into Jira business use cases.
  • Review and assess product architectures to ensure compliance with security policies.
  • Conduct security risk assessments and manage product vulnerabilities.
  • Oversee compliance with industry regulations, standards, and certifications.
  • Evaluate and integrate third-party security tools and technologies into products.
  • Perform security reviews of application designs, including APIs and microservices.
  • Create and enforce application security guidelines, policies, and frameworks.
  • Lead and enforce secure software development lifecycle (SSDLC) initiatives.
  • Evaluate and select application security tools, such as SAST, DAST, SCA, Contiaer Security , DevSecOps Cloud and IAST.
  • Collaborate with DevOps teams to ensure secure CI/CD pipeline practices.
  • Deliver training and mentorship on secure coding to developers and engineers.
  • Perform security assessments, including vulnerability scans and penetration testing.
  • Identify and document vulnerabilities, misconfigurations, and compliance gaps.
  • Create detailed reports of security findings and provide recommendations.
  • Support remediation efforts by collaborating with developers and engineers.
  • Stay updated on the latest security threats, exploits, and trends.
  • Implement and maintain application security tools like SAST, DAST, SCA, DevSecOps, Container Security, Cloud Security.
  • Write and enforce secure coding guidelines and standards.
  • Perform code reviews to identify vulnerabilities and ensure secure practices.
  • Design and implement robust authentication and authorization mechanisms.
Application SecurityApplication Security ArchitectureThreat ModelingSecurity RequirementsProduct SecurityDevSecOps+6

Ntt data

Product Security /Application Security Architect/Analyst/Consultant/Engineer

Mar 2024 – Feb 2025 · 11 mos · Sofia City, Bulgaria · Remote

  • Develop and implement security strategies for product development lifecycles.
  • Conduct threat modeling to identify and mitigate potential risks in product designs.
  • Collaborate with development teams to integrate security into software products.
  • Define and enforce secure coding standards and best practices by adding security requirments into Jira business use cases.
  • Review and assess product architectures to ensure compliance with security policies.
  • Conduct security risk assessments and manage product vulnerabilities.
  • Oversee compliance with industry regulations, standards, and certifications.
  • Evaluate and integrate third-party security tools and technologies into products.
  • Perform security reviews of application designs, including APIs and microservices.
  • Create and enforce application security guidelines, policies, and frameworks.
  • Lead and enforce secure software development lifecycle (SSDLC) initiatives.
  • Evaluate and select application security tools, such as SAST, DAST, SCA, Contiaer Security , DevSecOps Cloud and IAST.
  • Collaborate with DevOps teams to ensure secure CI/CD pipeline practices.
  • Deliver training and mentorship on secure coding to developers and engineers.
  • Perform security assessments, including vulnerability scans and penetration testing.
  • Identify and document vulnerabilities, misconfigurations, and compliance gaps.
  • Create detailed reports of security findings and provide recommendations.
  • Support remediation efforts by collaborating with developers and engineers.
  • Stay updated on the latest security threats, exploits, and trends.
  • Implement and maintain application security tools like SAST, DAST, SCA, DevSecOps, Container Security, Cloud Security.
  • Write and enforce secure coding guidelines and standards.
  • Perform code reviews to identify vulnerabilities and ensure secure practices.
  • Design and implement robust authentication and authorization mechanisms.
Application SecurityApplication Security ArchitectureThreat ModelingDevSecOpsSASTDAST+2

Ey

2 roles

Application Security Architect/ Application Security Engineer

Mar 2023 – Mar 2024 · 1 yr · Hyderabad, Telangana, India

  • As Application Security Engineer/Consultant my responsibilities include but not limited to,
  • Design and implement security controls within the software development lifecycle (SDLC).
  • Perform static (SAST) and dynamic (DAST) application security testing.
  • Conduct secure code reviews to identify and mitigate vulnerabilities.
  • Develop and enforce security policies, standards, and best practices.
  • Work with development teams to remediate security flaws in applications.
  • Implement and manage security tools such as SAST, DAST, SCA, and RASP.
  • Research and integrate the latest security technologies and frameworks.
  • Conduct penetration testing and threat modelling for applications.
  • Automate security testing within CI/CD pipelines.
  • Collaborate with compliance teams to ensure regulatory security requirements are met.
  • Analyse and assess security risks in applications and software systems.
  • Monitor applications for security threats and vulnerabilities.
  • Perform security assessments, including penetration testing and code reviews.
  • Track, report, and recommend fixes for identified security weaknesses.
  • Support incident response efforts related to application security breaches.
  • Assist in implementing security policies and guidelines for development teams.
  • Educate developers on secure coding practices and common attack vectors.
  • Evaluate third-party software and open-source components for security risks.
  • Maintain security documentation and compliance reports.
  • Work with security engineers to enhance overall application security posture.

Senior Application Security Architect

Mar 2021 – Feb 2023 · 1 yr 11 mos · Hyderabad, Telangana, India

Web Application SecurityApplication Security Subject Matter ExpertSecurity RequirementsDASTDevSecOpsApplication Security Architecture+4

Majesco

2 roles

Principle Application Security Analyst

Jul 2017 – Mar 2021 · 3 yrs 8 mos · On-site

Architecture ReviewsInformation SecurityApplication Security LeaderPayment Card Industry Data Security Standard (PCI DSS)Vulnerability AssessmentAgile Methodologies

Senior Applicatuon Secuity Analyst

Jun 2013 – Jun 2017 · 4 yrs · On-site

Architecture ReviewsInformation SecurityApplication Security LeaderPayment Card Industry Data Security Standard (PCI DSS)Vulnerability AssessmentAgile Methodologies

Mastek

4 roles

Application Security Engineer

Jul 2012 – Jul 2013 · 1 yr · Mumbai Area, India

Architecture ReviewsInformation SecurityApplication Security LeaderPayment Card Industry Data Security Standard (PCI DSS)Vulnerability AssessmentAgile Methodologies

Web Application Performance Analyst

Promoted

Sep 2010 – Jul 2012 · 1 yr 10 mos · Mumbai Area, India

Architecture ReviewsInformation SecurityApplication Security LeaderPayment Card Industry Data Security Standard (PCI DSS)Vulnerability AssessmentAgile Methodologies

Senior Software Engineer

Promoted

Sep 2008 – Sep 2010 · 2 yrs · Mumbai Area, India

Information SecurityApplication Security LeaderPayment Card Industry Data Security Standard (PCI DSS)Vulnerability AssessmentAgile Methodologies

Software Engineer

Sep 2007 – Sep 2008 · 1 yr · Mumbai Area, India

Webapplication developmentJavaj2eescriptgo.NET

Education

Kakatiya University, Warangal

Master of Computer Applications - MCA

Jun 2001 – Jun 2004

Kakatiya University, Warangal

Bachelor of Science - BS — Mathematics

Jan 1997 – Jan 2000

APRS Enkoor

SSC — Mathematics

Jan 1989 – Jan 1994

Stackforce found 100+ more professionals with Ai Security & Threat Modeling

Explore similar profiles based on matching skills and experience