Skip to content
RK

Ramya Kanderi

Senior Application Security & DevSecOps Engineer

TX 75025, USA

๐ŸŸขAping In

Senior Application Security & DevSecOps Engineer with 8+ years of experience securing enterprise-scale cloud-native platforms across Fortune 500 organizations including AT&T, Cisco, Nokia, and Pact Pharma. Expertise in Application Security, DevSecOps, Kubernetes Security, Cloud Security, and Generative AI/LLM Security across AWS and Azure environments.

Skills

CI/CD Pipeline Security9/10
Cloud Security (AWS & Azure)9/10
DevSecOps9/10
Application Security9/10
IAM & Secrets Management8/10
Infrastructure as Code (8/10)Zero Trust Architecture (8/10)Docker & Kubernetes (8/10)Generative AI / LLM Security (8/10)HashiCorp Vault (8/10)Terraform (8/10)Threat Modeling (8/10)Vulnerability Management (8/10)Kubernetes Security (8/10)Python (8/10)SAST/DAST/SCA (8/10)Splunk / SIEM (8/10)Java (7/10)Azure OpenAI / LangChain (7/10)Penetration Testing (7/10)

Work Experience

Senior Application Security & DevSecOps Engineer

Pact Pharma

Oct 2025 โ€” Present

Led enterprise Application Security initiatives across 15+ cloud-native applications, reducing critical security risks by 65%. Built secure CI/CD pipelines integrating SAST, DAST, SCA, and policy enforcement gates. Implemented Kubernetes runtime security using Falco, RBAC, and Trivy. Designed secure Generative AI workflows using Azure OpenAI and LangChain. Improved incident response efficiency by 50% using Splunk, Azure Sentinel, and automated SIEM workflows.

Senior Specialist Software Engineer โ€“ DevSecOps & Cloud Security

AT&T

Mar 2022 โ€” Sept 2025

Performed enterprise security assessments across 300+ applications. Designed secure CI/CD pipelines with automated security testing. Hardened Kubernetes clusters using CIS benchmarks and RBAC. Built AI-powered threat detection solutions aligned with MITRE ATT&CK. Managed secrets for 100+ microservices using HashiCorp Vault and CyberArk PAM.

Security Software Engineer โ€“ DevSecOps & Cloud

Cisco

Jan 2020 โ€” Feb 2022

Integrated security controls into SDLC for enterprise Java and Python applications aligned with OWASP standards. Built CI/CD pipelines with automated security scanning. Automated AWS infrastructure security using Terraform and Ansible. Improved deployment efficiency by 40% through DevSecOps automation initiatives.

Security Software Engineer โ€“ DevSecOps

Nokia

Sept 2017 โ€” Dec 2019

Developed secure telecom applications with embedded security controls. Conducted vulnerability assessments and CVE analysis using CVSS methodologies. Implemented network security controls including WAF, DDoS mitigation, and segmentation. Built automation scripts for infrastructure hardening and compliance validation.

Education

Sri Venkateswara University

Bachelor ยท Computer Science

2010 โ€“ 2013