NutanixMember Of Technical Staff - 4 (DevSecOps & Application Security)
Feb. 2021India- Developed, maintained, and integrated tools and scanners to support the DevSecOps pipeline; conducted multiple PoCs with security tools, evaluated their fit for Nutanix through key metrics, and built custom scripts to optimize their adoption.
- Integrated Qualys, Rapid7, and Tenable with automated, API-driven pipelines, enabling continuous vulnerability scanning for both core and non-core products using Python and AWS.
- Significantly contributed to developing and maintaining the vulnerability database and advisory system, designing robust API endpoints using AWS API Gateway, Lambda, and DocumentDB for efficient enterprise integration and threat intelligence delivery.
- Designing Restful APIs using Python FastAPI framework.
- Architected and maintained Nutanix Security Release Advisories, delivering 100+ critical updates annually to thousands of enterprises—boosting risk visibility, compliance, and security response.
- Onboarding new products to DevSecOps pipeline.
- Automated DAST scanning and onboarded 20+ applications, enabling consistent detection of OWASP Top 10 and other critical web application vulnerabilities.
- Participated in security reviews using Black Duck (SCA), guiding teams on secure package upgrades and integrating Black Duck and Veracode scans into CI pipelines to ensure continuous compliance and reduce open-source vulnerabilities.