Application Developer Security Engineer
Current• Developed EDIManager manager applications using .net Core, Microservices, Asp .Net, Angular, MVC,• Containerized with Docker, Kubernetes, WSL, Compose and Tilt.• Used Terraform to create/update application registration and set permission.• Configure Azure DevOps CI/CD pipelines.• Security Design review Boomi Integration and Oracle Cloud ERP projects. • Write security stories for Boomi Integration project and Oracle ERP projects.• Drafted Enterprise level Data Governance Policies.• Drafted Access review policy for Boomi and Oracle Cloud ERP.• Review and apply Oracle cloud security and Roles and Responsibility. • Implemented SSO, conditional access for Boomi Integration and Oracle ERP.• Responsible for JIT and JEA access for applications.• Done extensive research on EDI File Sandboxing tools. • Threat model existing and new backend applications using MS threat modelling tool. • Analyze threat and create risk register and risk ratings.• Create/Modify Azure pipeline for automated code scanning with Checkmarx.• Use power shell scripts to Auto rotate application secrets.• Responsible for granting admin consent for the application access request.• Define routine periodic review process.• Create POC for DataDog integration for logged collection.• Migrated old applications from old 2012R2 windows server to new windows server.• Performed Webserver hardening task that include removing unused application, disabled old encryption suites, and check and review access to the resource. • Handle technical support security tickets created for application security issues. • Create plan for penetration testing for APIs developed for Oracle ERP integration.