SRINIVASA RAO ELLURI
*****, ****** **** ** ***** Point, Texas 76258 940-***-**** ******************@*****.*** Summary
Certified security project manager and IT architect with a proven record in driving security initiatives and IT projects in telecom, banking, and enterprise environments. Expert in cloud security, vulnerability management, and compliance (ISO 27001, GDPR, PCI DSS, NIST). Skilled in team leadership, vendor management, and security architecture. Proficient in AWS, Azure, and Telco. Certified: CEH, ITIL, ALM, AWS Solution Architect – Associate. Skills
• Cloud Security
• Incident Response & Cyber threat hunting
• Threat Modeling & Threat detection
• Security Framework Implementation
• Vulnerability management & Penetration testing
• Source code analysis
• Regulatory compliance
• Leadership
• Proposal & SOWs
• Structural quality gate services
• Application bench marking
• Non-functional testing
• Performance testing
• Usability testing
• Application bench marking
• Technical debt evaluation
• Test data management
• .Net development
Experience
Project Lead – Security Testing & Governance 04/2025 to Till Date Satcon Inc Texas, US
• Manage end-to-end security projects, breaking down complex tasks, assigning responsibilities, and overseeing changes to scope, schedule, and budget with meticulous documentation and stakeholder approval.
• Define and enforce cloud security policies, collaborating with cross-functional teams to monitor usage, pinpoint risks, and optimize operations.
• Develop and implemented robust mitigation strategies to minimize project impact and ensure business continuity.
• Ensure project deliverables met all defined quality standards and regulatory requirements, applying telecom industry best practices in project management and security.
Project Manager – Security Testing & Governance 08/2017 to 04/2025 Virgin Media O2 Reading, UK
• Cloud Security Governance: Led large-scale cloud transformation projects, ensuring regulatory compliance (Telecom Security Act - TSA)
• Security Testing: Defined project scope, objectives, and deliverables for security testing and governance initiatives
• Application Security: Implemented code inspections and vulnerability scans (OWASP, NIST, SANS), reducing defects and strengthening security
• Penetration Testing: Established comprehensive frameworks, methodologies, and automation strategies across the enterprise
• Disaster Recovery: Designed and implemented robust DR solutions, including simulation approaches and backup strategies
• Automation: Automated disaster recovery execution, reducing execution time by 40%
• Incident Management: Managed cross-functional incident triage, RCA, and SLA-driven escalations
• Security Operations: Streamlined security operations through monitoring tool integration, automation, and SIEM solutions
• Collaboration: Fostered strong cross-functional collaboration with DevOps, IT, risk, and legal teams
• Cybersecurity Planning: Developed and implemented robust cybersecurity plans, achieving 99% data security rate
• Security Transformation: Executed comprehensive security transformation project, reducing security incidents by 30%
• Team Development: Trained team members in cybersecurity through hands-on security training sessions
• Threat Detection: Proactively reviewed audit logs and detected suspicious activities
• Security Improvement: Researched and adopted new security tools, policies, and practices, improving customer satisfaction and reducing operational overhead
Security Auditor 10/2014 to 08/2017
UBS Bank Zurich, Singapore & Bangalore India
• Global Security Initiative: Led implementation of Evidence-Based Testing across 100+ UBS locations worldwide
• Security Audits: Conducted 150+ security audits and compliance assessments (GDPR, PCI DSS)
• Regulatory Compliance: Collaborated with 3 audit teams to resolve regulatory issues and ensure continuous compliance
• Vendor Transition: Successfully managed vendor transition from Swisscom, including team training
• Security Awareness: Led development and deployment of enterprise-wide information security awareness program for 9,000+ global users
• Risk Mitigation: Advised 15+ clients on global risk mitigation strategies and business ventures
• Architecture Remediation: Collaborated with developers and security teams on architecture flaw remediation and performance tuning
• GDPR Compliance: Implemented and ensured compliance, reducing data privacy incidents by 30% Security Architect 03/2011 to 10/2014
Lloyds Bank, UK Hyderabad, India
• Cloud-Native Security: Developed and implemented secure architectures tailored to business risk profiles
• Vulnerability Management: Conducted weekly reviews and coordinated remediation efforts with DevOps teams
• Security Benchmarking: Created performance and security benchmarks, mapping flaws to architectural weaknesses
• Compliance Frameworks: Implemented custom checklists and frameworks for end-to-end security coverage
• Application Security: Facilitated design walkthroughs to improve system robustness and maintainability
• Penetration Testing: Led resource identification, testing efforts estimation, and budgeting for penetration testing and source code analysis
• Security Assessments: Performed black box and white box penetration tests on web applications
• Security Governance: Implemented a new framework, improving compliance adherence by 40% Senior Manager 07/2010 to 03/2011
Cadenza Solutions Mumbai, India
• Application Optimization: Analyzed source code, implementing improvements that increased system performance by 30% and enhanced security controls
• SIEM Management: Managed ArcSight SIEM platform lifecycle, enhancing enterprise-wide security posture
• Data Integration: Integrated diverse data sources and event feeds with ArcSight, ensuring comprehensive security monitoring
• Documentation: Developed and maintained comprehensive documentation of ArcSight infrastructure and configurations
• Collaboration: Collaborated with security teams, IT personnel, and management to ensure security best practices and streamline incident response
• Subject Matter Expertise: Provided technical guidance and support on SIEM best practices to internal teams and external customers
• Automation: Developed and deployed automated scripts to evaluate DLP and Antivirus software effectiveness, improving security control testing
IT Specialist – Client: Crisil India - Security Pen Testing & Source code analysis Services 09/2009 to 06/2010 3i Infotech Mumbai, India
• Client Engagement Management: Managed full lifecycle of client engagements, from proposal to test execution and pain point gathering
• Code Analysis: Led structural code quality and security analysis using tools like CAST AIP, Web Inspect, Fortify, and SonarQube
• Security Optimization: Boosted productivity by 45% through source code analysis and optimized security incident detection and response
• Stakeholder Communication: Facilitated client and stakeholder communication through daily status reporting and technical meetings
• Issue Resolution: Timely and professionally addressed and resolved project escalations Software Engineer 04/2009 to 08/2009
3i Infotech - Anti-Money Laundering Product/AML – Software Source code analysis Chennai, India
• Code Reviews & Audits: Participated in comprehensive code reviews, security audits, and deployment readiness assessments for high-quality software delivery
• Code Analysis: Analyzed applications using SonarQube to identify and address code quality and security vulnerabilities
• Performance Optimization: Optimized application performance through tuning of views, indexes, and stored procedures
• Vulnerability Remediation: Collaborated with developers to remediate security vulnerabilities, strengthening application security posture
Consultant 12/2007 to 03/2009
3i Infotech - NCR - Bespoke Fuel Management System - Security Assessment Hyderabad, India
• System Development: Architected and developed core modules for Back Office Systems (BOS) and Fuel Management Systems, enhancing operational efficiency
• Code Reviews: Conducted comprehensive source code reviews and architecture validations, improving code quality and system integrity
• Performance Optimization: Optimized application performance through strategic tuning of database views, indexes, and stored procedures
• Security Implementation: Implemented robust security best practices, including encryption of SQL connection strings and sensitive data fields
• Client Collaboration: Collaborated with clients to ensure functional alignment with evolving business needs, driving successful project outcomes
Education
Master's Degree: Master of Computer Applications (MCA) Indira Gandhi National Open University India
Diploma: Advanced Software Technology (DAST)
CMC Ltd.
Certifications
• AWS Certified Solutions Architect – Associate – (Validation number: 8f7eb5c4087344699e50ef5c401929d1; Expiration Date: April 30, 2028)
• Certified Ethical Hacker (Expired) – (Pursing with CISSP)
• ITIL Foundation – (Effective from: 16 Dec 2022- Certificate number: GR671463471SE)
• ALM certified – (HP LearnerID: PL71783078; Registration: 247249236) Awards & Recognition
• Dell silver medal winner
• VMO2 SMIP hero award
• Ubs client appreciation award
• NTT DATA UK town hall award
• VMO2 CISO appreciation
• NTT DATA India bronze medal