Santhosh Kumar

Santhosh Kumar Email and Phone Number

Principal Security Architect @ OpenText
Dubai, AE
Santhosh Kumar's Location
Dubai, United Arab Emirates, United Arab Emirates
About Santhosh Kumar

Santhosh Kumar is a distinguished information security expert with over 16 years of experience spanning diverse industries. Specializing in comprehensive security architecture design, Santhosh has a proven track record in securing cloud infrastructures, web applications, payment systems, blockchain technologies, data platforms, and core banking solutions.With hands-on expertise in secure SDLC processes, Santhosh excels in creating robust secure architectures and implementing cloud security measures. His proficiency extends to static code analysis, interactive application security testing (IAST), privacy technology integration, vulnerability assessment, and penetration testing, ensuring end-to-end protection for organizations.Santhosh is deeply committed to advancing the field of application security and AI, continually exploring innovative solutions to enhance security protocols. He has successfully collaborated with industry leaders, leveraging his technical acumen to drive impactful security transformations.A dedicated thought leader and mentor, Santhosh actively engages with the professional community, sharing insights and best practices to foster a culture of security excellence. His strategic approach and passion for security make him an invaluable asset to any organization seeking to fortify its defenses in today’s dynamic threat landscape.

Santhosh Kumar's Current Company Details
OpenText

Opentext

View
Principal Security Architect
Dubai, AE
Website:
opentext.com
Employees:
22664
Santhosh Kumar Work Experience Details
  • Opentext
    Principal Security Architect
    Opentext
    Dubai, Ae
  • Opentext
    Application Security Architect
    Opentext Feb 2023 - Present
    Waterloo, On, Ca
  • Iapp - International Association Of Privacy Professionals
    Member
    Iapp - International Association Of Privacy Professionals Sep 2019 - Present
    Portsmouth, Nh, Us
    Offically verified and certified member of International association of privacy professional
  • Micro Focus
    Application Security Architect - Cyberres
    Micro Focus Jul 2020 - Jan 2023
    Newbury, Berkshire, Gb
    Eat, Sleep, Breath Fortify, Devsecops and application security
  • Uae Exchange
    Associate Director- Security Architect
    Uae Exchange Jan 2020 - Jun 2020
    Abu Dhabi, Ae
    A security architect who helps developers and solution architects to design and develop secure applications. In UAE Exchange, my primary role is to build a secure and hybrid cloud deployment posture for supporting its PAAS (Payment as a Service) business.
  • Emirates Nbd
    Security Architect
    Emirates Nbd May 2018 - Dec 2019
    Dubai, United Arab Emirates, Ae
    I am a security architect and devsecops engineer who helps developers and solution architects to design and develop secure applications Key Job Responsibilities • I actively participating in architecture reviews/workshops to implement security features to ensure secure by design• I always approach securing an application based on the sensitivity of the data that is stored or processed• I perform Penetration testing, Static & Manual code analysis, Security Design Reviews, Threat modeling and Open source• I enhance the security of environment where applications are deployed by scanning for vulnerabilities and compliance• I provide right solutions to balance between security and business functionality• My security solutions are always designed considering the user experience and business goals• I develop strong relationship with key business and technology stakeholders in order to influence and drive the security• I have integrated security solutions such as IAST, SAST and DAST in jenkins pipeline• I perform manual penetration testing for all the applications to test business logic issues• I help vendors by providing solutions to fix the issues identified• I implement strong security requirements & controls such as ✓ VA and compliance scan✓ Application security assessment, IAST & Secure code review✓ Configure access to production via PAM (CyberARK) ✓ Ensure data at rest is encrypted (LUKS, Bitlocker and TDE)✓ Configure WAF for critical and highly sensitive apps✓ Ensure 2 factor authentication and DDos protection for public facing systems✓ Ensure credentials are either hashed or encrypted✓ Enhance and integrate DLP for sensitive data containing reports✓ Ensure network zoning as per regional regulations and sensitive data is masked in logs✓ Configure access controls through IAM and implement SSO✓ Encryption of data in transit e.g. TLS 1.2 (HTTPS, LDAPS, Secure JDBC and ODBC)✓ Strong crypto such as SHA3 or AES 256
  • Nordea
    Senior It Developer - Security Testing
    Nordea Jun 2017 - Apr 2018
    Helsinki, Fi
    Responsibility:• Manage and execute Penetration testing of core banking application and infrastructure• Present valid reports to management which helps them make strategic decisions when it comes to security • Security test Nordea collateral management application and infrastructure• Web service API security testing which includes SOAP, REST and XML• Devsecops implementation planning and support to implement tools like Fortify SCA, Gauntlt, BDD-Security and ZAP ATTACK proxy• Stack hardening – Enhance the security of environment where Core Banking application are deployed.• Fuzzing web application with Burp Suite and other mutation fuzzers• Reverse engineering web applications to identify the core security issues• Assist Vendor in providing proper remediation solution• Validate Vendor's security solution to identify potential loopholes• Implement devsecops model of automated security scanning and code scans during releases
  • Temenos
    Senior Specialist - Security Architecture, Assurance And Governance At Temenos
    Temenos May 2015 - Jun 2017
    Lancy, Geneva, Ch
    • Write process and procedure for internal penetration testing, static security code reviews, security design reviews, and open source security analysis.• Handle Temenos customer queries regarding product security• Engagement with pre-sales team to demonstrate security features built into the product to enable security as a differentiator in sales • Leading a team of penetration testers and secure code experts• Perform extensive market research to identify new security products which could aid internal security teams • Actively participating in architecture reviews/workshops to implement security features to ensure secure by design• Develop relationships with key business and technology stakeholders in order to influence and drive the security agenda• Drive Penetration testing, Static and Manual code analysis, Security Design Reviews, Threat modeling and Open source analysis• Stack hardening – Enhance the security of environment where Temenos products are deployed• Security analysis and maintenance of free and open source libraries utilized by products developed in Temenos• Ensure Temenos products are rigorously penetration tested by external penetration testers by engaging with third party security firms on yearly basis• Work with internal development team to set up environments for security assessments and automate security testing both static and dynamic analysis in continuous integration• Identify opportunities to develop and improve existing automation processes in security analysis. • Devised and executed an organization-wide penetration testing for diverse products• Open SAMM (Software Assurance Maturity Model) Implementation• Delivered cutting edge security training for product developers and managers• Evaluated Temenos existing software security practices and built a balanced software security program in well-defined iterations • Effective Application Penetration Testing model combining security best practices from OWASP, SANS and WASC.
  • Inautix Technologies
    Lead Information Security
    Inautix Technologies Nov 2013 - Apr 2015
    Roles / Responsibilities• Architecting Software with Secure Software Concepts• Vulnerability Management• Leading a team of 5 security experts in both secure code review, Security testing & Secure Design review activities • Performing automated code scans and manual analysis of vulnerabilities on monthly basis• Conduct penetration testing on Web, Mobile (Android & iPhone) applications• Perform secure architecture analysis for applications • Training development teams on secure design & secure coding practices • Conducting Security Forums to discuss the issues and concerns on application security with development teams • Provide metrics scorecard which ensures timely delivery, track and monitor issues to closureAccomplishments • Architect software applications with Secure by Design • Assist and recommend solutions to development teams for remediating complex security issues• Performed joint triage and actively follow-up with application teams to remediate code review findings • Tailored Secure coding Maturity Model (SCML) and published it across organization which assures prioritization of issues that are to be addressed. This also ensures psychological acceptability design principle• Conducted knowledge sharing sessions within the team and forums for developers at a firm wide level to increase awareness • Demonstrate skills on Design reviews enforcing Secure Design principles • Instigated Secure Coding Forum across organization to discuss and create awareness. • Proactively design and develop simple application to automate the code review and security testing reports.
  • Banca Sella
    Senior Informaion Security Executive
    Banca Sella Jun 2012 - Nov 2013
    Biella, (Bi), It
    • Secure Code review on projects / application developed by Banca Sella• Installation & management of Fortify SSC & SCA• Developing tools for automation of code review process• Defining the Strategy & Test Plan for Penetration testing the web & Mobile applications Developed by Banca Sella• Run & Analyze the security test (Manual & Automated) and notify security issues and suggest countermeasures for security improvements• Penetration Testing web application as per OWASP & PCI DSS standards
  • Temenos
    Application Security Enginner
    Temenos Mar 2010 - Jun 2012
    Lancy, Geneva, Ch
    Roles:• Designing and implementing Threat modelling• Defining the Strategy & Test Plan for Penetration testing • Run & Analyze the security test (Manual & Automated) and pinpoint the security issues and suggest countermeasures for security improvements• Penetration Testing web application according to OWASP & PCI DSS standards • Provided suggestions regarding security, which helped for the betterment of the product• Successful completion of Penetration testing on Web applications developed by TEMENOS
  • Sutherland Global Services
    Technical Support Executive
    Sutherland Global Services Aug 2007 - Feb 2010
    Pittsford (Rochester), Ny, Us
    Roles• Trouble shooting problems with Symantec Products faced by customer• Provide solutions and perform virus removal activities in customer PC

Santhosh Kumar Skills

Firewalls Test Data Management Computer Forensics Information Security Secure Code Review Database Security Requirements Analysis Ids Linux Cissp Amazon Web Services Cybersecurity Itil Web Applications Networking Troubleshooting Penetration Testing Security Architecture Design Computer Security Application Security Tcp/ip Vulnerability Management Application Security Assessments Virtualization Web Application Security Java Xml Network Security Testing Information Security Management Security Audits Iso 27001 Cryptography Sql Vulnerability Assessment Malware Analysis Software Development Security Unix Pci Dss

Santhosh Kumar Education Details

  • University Of Madras
    University Of Madras
    Computer Science

Frequently Asked Questions about Santhosh Kumar

What company does Santhosh Kumar work for?

Santhosh Kumar works for Opentext

What is Santhosh Kumar's role at the current company?

Santhosh Kumar's current role is Principal Security Architect.

What schools did Santhosh Kumar attend?

Santhosh Kumar attended University Of Madras.

What skills is Santhosh Kumar known for?

Santhosh Kumar has skills like Firewalls, Test Data Management, Computer Forensics, Information Security, Secure Code Review, Database Security, Requirements Analysis, Ids, Linux, Cissp, Amazon Web Services, Cybersecurity.

Who are Santhosh Kumar's colleagues?

Santhosh Kumar's colleagues are Swarna Dash, Karthik S, Janakirami Reddy, Elite Shiboo, Adam Schlachter, William Weiner, Aniruddha Ananthapadmanabha.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.