Post Job Free
Sign in

Appsec Engineer, Application security engineer, Cybersecurity Analyst

Location:
Frisco, TX
Posted:
September 03, 2026

Contact this candidate

Resume:

Raghu Veera

SUMMARY

Application Security Professional with 10+ years of experience designing and implementing enterprise Application Security (AppSec) programs across web, API, cloud, and enterprise applications. Extensive expertise in Secure SDLC (SSDLC), Threat Modeling (STRIDE, PASTA), Secure Coding, DevSecOps, CI/CD Security, Security Architecture Reviews, SAST/DAST integration, API Security, Vulnerability Management, and Security Governance. Proven success partnering with software engineering teams to perform secure code reviews, developer enablement, security awareness, vulnerability remediation, and application risk assessments. Experienced in integrating security controls into CI/CD pipelines, developing security metrics and dashboards, supporting compliance initiatives, and driving secure software development practices across enterprise environments.

Core Competencies: Application Security, Secure SDLC, Threat Modeling, Secure Coding, Security Architecture Review, Developer Enablement, DevSecOps, CI/CD Security, Security Governance, Vulnerability Management, OWASP Top 10, OWASP API Top 10, SAST, DAST, API Security, Cloud Security, Security Metrics, Compliance Reporting

EDUCATION

The University of Texas at Dallas

Master of Science, Information Technology and Management

Certificate in Cybersecurity Systems

Internal Auditing Education Partnership Certificate

SRM University, Chennai, India

Bachelor of Technology, Computer Science Engineering,

Technical Skills

Programming

Python, C, C++, .NET, SQL, Bash, PowerShell

Operating Systems

Windows, Kali Linux

Application Security Tools

Acunetix, MobSF, Qualys, Burp Suite, Wireshark, OWASP ZAP, Nessus, Metasploit, Checkmarx, Synk, Postman, SQLMap, Nmap, JD-GUI, Apktool

SIEM / SOAR

Wazuh, Splunk, Cortex XSOAR

IAM

Okta, CyberArk

Data Visualization

Looker, PowerBI, MS Visio

Database

MSSQL,MySQL, OracleDB, PostgreSQL

Cloud

Azure, AWS

Frameworks & Standards

NIST, ISO27001, PCI-DSS, HIPAA, HITRUST, GDPR, Security Governance, Risk Management, CVSS

Software & Documentation

Jenkins, JIRA, ServiceNow, Genymotion, Github, MS Word, MS Excel, MS PowerPoint

PROFESSIONAL EXPERIENCE

Ameri Health Caritas, Newtown Square, USA March 2025 - Present

Application Security Engineer

Implements Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) to identify and remediate security issues

Performed API security assessments on REST and GraphQL services using tools like Postman and Burp Suite, identifying vulnerabilities such as broken authentication, IDOR, and improper rate limiting.

Validated API security against OWASP API Top 10, ensuring robust protection against common threats like injection, mass assignment, and excessive data exposure.

Design threat models like STRIDE, DREAD and PASTA to various applications based on business requirements.

Facilitated collaborative threat modeling workshops with application owners, architects, and developers to identify security risks during the application design phase.

Partnered with engineering teams to launch a Healthcare Security Champions Program, providing secure coding guidance and serving as the AppSec point of contact

Collaborates with teams to remediate vulnerabilities, reducing production environment risks by 50%.

Identified and analyzed critical vulnerabilities using MITRE ATT&CK & CVSS, reducing false positives by 30%.

Leads workshops on secure coding practices, reducing post-release vulnerabilities by 50%.

Partnered closely with software development teams throughout the Secure SDLC to improve secure design practices and accelerate vulnerability remediation.

Configured and managed Checkmarx SAST scans, triaged findings, and collaborated with developers to remediate security vulnerabilities.

Executed phishing and OSINT campaigns, improving employee security awareness by 60%.

Organized regular Application Security Community of Practice meetings to discuss OWASP Top 10, API security, and recent vulnerability trends.

Works directly with the compliance team to identify application security vulnerabilities tied to specific compliance mandates.

Served as a trusted Application Security advisor to engineering teams by providing security consultation during design, development, testing, and deployment phases.

Managing all pre-deployment web application security assessment functions such as static code reviews and dynamic analysis.

Led cross-functional initiatives to enhance Secure SDLC practices, eliminating entire classes of vulnerabilities in 25% of applications.

Collaborated with engineering teams to develop automated security dashboards, improving compliance reporting efficiency by 30%.

Promoted secure development practices through developer enablement sessions, secure coding guidance, and knowledge-sharing initiatives.

Designed and implemented a risk-based vulnerability management program, aligning with NIST 800-40 to improve risk visibility across 90% of assets.

Developed automated vulnerability tracking pipelines, integrating with CI/CD workflows, which reduced remediation time by 40%.

Integrated automated security validation into CI/CD workflows to improve application security posture and reduce manual review effort.

Performs post-remediation validations through rescans and manual source code reviews to determine the effectiveness of remediation actions

Continuously update application risk postures and communicate the same to application owners and senior management.

Learning to perform security assessments of AI systems, focusing on model behavior, input validation, and misuse scenarios.

Exploring use of tools like Burp Suite to test AI-integrated web applications and APIs for vulnerabilities.

Classifies vulnerabilities using CVSSv3.1, reducing resolution time for high-severity issues by 40%.

Performed Software Composition Analysis (SCA) to identify vulnerable open-source dependencies and prioritize remediation using CVSS.

Participating in internal knowledge-sharing sessions on AI security, covering risks like prompt injection, model poisoning, and data leakage.

Delivers actionable penetration testing reports with mitigation strategies for stakeholders.

Led red team attack simulations using C2 frameworks, improving threat detection by 30%.

Automated reconnaissance and exploitation using Python, increasing red team efficiency by 50%.

Secures cloud-hosted apps by simulating adversarial threats and aligning with security benchmarks.

Reviews scan results to determine the validity of reported issues, excluding false positives through suppressions and providing feedback and remediation guidance on false positive challenges by developers

Documents, assigns, tracks and maintains identified application security vulnerabilities utilizing the organization's vulnerability management system.

Supported security governance initiatives by tracking remediation metrics, vulnerability trends, compliance reporting, and application security KPIs.

Leveraged big data analytics to identify vulnerability trends, driving a 15% improvement in security posture through targeted mitigation strategies.

Performs network penetration tests using Nmap and Nessus, identifying and remediating critical risks.

University of Alabama, Birmingham, USA January 2024 - February 2025

Cyber Security Analyst

Configured and maintained Splunk SIEM, reducing false positives by 30% and improving threat detection speed by 40% through optimized log correlation and alert tuning.

Investigated and responded to over 100+ SOC security incidents, including malware, phishing, and unauthorized access, contributing to a 25% decrease in average incident response time.

Monitored and analyzed Splunk dashboards and SIEM alerts to detect anomalies, improving incident detection response times by 30%.

Created and optimized Splunk queries (SPL) and dashboards to track security incidents, reducing investigation time by 40%.

Configured Splunk alerts and correlation searches, enabling proactive threat detection and real-time security monitoring.

Defined software testing requirements and executed performance testing to certify code quality and reliability.

Integrated multi-source threat feeds into Cortex XSOAR TIM, enabling automated threat enrichment and scoring.

Conducted advanced log analysis and threat hunting in Splunk, identifying suspicious patterns and potential breaches, resulting in the early detection of 15+ high-risk threats.

Collaborated with incident response teams on containment and eradication efforts, enabling full recovery from incidents 50% faster and preventing lateral movement in critical systems.

Developed and fine-tuned detection rules for MITRE ATT&CK coverage, increasing rule accuracy and detection rates by 35% across endpoint and network logs.

Supported Splunk-based security automation efforts, reducing manual analysis time by 20 hours per month through alert-based workflows and scripted responses.

Documented incidents and post-incident reports, improving collaboration and leading to a 30% faster resolution rate and clean audits for three consecutive quarters.

Assisted in configuring and integrating endpoint detection and response (EDR) tools with SIEM for comprehensive visibility, enabling early containment of endpoint-based threats.

Participated in phishing simulation campaigns and subsequent analysis, helping reduce employee click-through rates by 40% through targeted awareness training.

Conducted regular technical risk assessments to identify system vulnerabilities, delivering actionable reports and remediation plans that reduced critical findings by 20% over two quarters.

Led deep-dive investigations into email gateway alerts, identifying and blocking spear-phishing attempts targeting senior leadership, preventing potential credential compromise.

Supported security tool upgrades and policy tuning, enhancing system logging fidelity and reducing alert fatigue across SOC by 25%.

Collaborated with GRC and IT teams to align security operations with compliance standards (HIPAA, NIST), supporting internal readiness for security audits.

Analyzed data exfiltration attempts using Splunk and NetFlow data, enabling firewall and DLP rule enhancements that mitigated recurring outbound anomalies.

Created internal documentation and SOPs for alert triage, onboarding, and incident handling procedures, accelerating new analyst ramp-up time by 30%.

Actively participated in on-call escalation scenarios, resolving high-priority incidents within SLA and minimizing business disruption during off-hours.

Continuously tested and evaluated emerging threat intelligence feeds, integrating relevant indicators of compromise (IOCs) into existing SIEM correlation rules for enhanced threat coverage.

Performed IOC and IOA-based threat hunting across SIEM platforms to uncover indicators of lateral movement, persistence, and C2 communication, enhancing detection across the modern attack chain.

Electronic Transaction Consultants, Dallas, USA May 2023 - August 2023

Data Analyst Intern

Demonstrated “Tolling System Traffic Data Analysis” and identified key drivers affecting Toll Tag Project.

Presented traffic data findings and detailed view reports in Looker to senior management.

Boosted UX by 25% with revamped summary, focused, and detailed view dashboards.

Led the team in analyzing 25+ parameters improving customer satisfaction by 50%.

Streamlined data modeling and reporting with Looker, reducing manual effort and enhancing efficiency.

Enabled self-service analytics in Looker, empowering stakeholders with instant data access.

Leveraged Looker’s cloud-based integration to provide up-to-date traffic insights without delays.

Improved collaboration with Looker’s version control and role-based data access.

Used Looker’s advanced visualization tools to present actionable insights more effectively than Jaspersoft.

Andhra Pradesh Technology Services Ltd, Andhra Pradesh, India July 2015 - August 2022

Sr Security Analyst

Analyzed 100+ Web App Security Assessments ensuring 90% of the recommendations were implemented.

Conducted 10+ Mobile App Security Assessments, the client implemented 85% of the recommendations.

Educated 40+ students in Cybersecurity contributing to national recognition by CERT-In.

Collaborated with 5+ developers across 50+ organizations to fix vulnerabilities reducing data breaches by 50 %.

Utilized Application and Network Security testing to develop the project scope.

Employed Burp Suite, Kali Linux, and Nmap to meticulously identify issues based on OWASP guidelines, mitigating false positives from tools like Acunetix and Nessus.

Performed red team activities on various web and mobile applications to reduce basic end-user security issues to 80%.

Integrated cybersecurity controls into industrial and embedded systems running Windows and Linux.

Integrated security testing into CI/CD pipelines, enabling early detection of vulnerabilities during development stages.

Embedded automated security controls into development pipelines enabling continuous security validation.

Collaborated with firmware, hardware, and software teams to embed security across the product lifecycle.

Worked closely with application development teams to embed security requirements into software development lifecycle activities.

Conducted manual web application penetration testing beyond automated scans, identifying complex vulnerabilities such as business logic flaws and chained exploits.

Performed secure application design reviews and provided remediation recommendations aligned with enterprise security standards.

Performed secure architecture reviews for web applications, recommending design improvements aligned with OWASP ASVS standards.

Implemented Windows and Linux OS hardening baselines to reduce product attack surface.

Built and deployed security scripts and configurations to improve system visibility and automation.

Performed threat modeling and security risk assessments for embedded product platforms.

Integrated cybersecurity tools to support system integration, data correlation, and automation.

Applied offensive and defensive security techniques to identify and remediate product vulnerabilities.

Ensured alignment with security standards, regulatory, and export control requirements.

Provided feasible solutions and recommendations based on the application’s criticality through CVE and CWE to avoid service interruption.

Identified various sensitive information and disclosures on applications as a part of red team activity and reported to concerned clients preventing data leakage.

Reviewed various security assessment reports performed by my team and recommended necessary changes to reduce security issues by 25%.

Orchestrated a company-wide security training that increased employee awareness and reduced click-through rates on simulated phishing emails by 50%.

Conducted enterprise-wide security assessments, identifying high-risk vulnerabilities and collaborating with stakeholders to remediate 95% of critical issues.

Developed custom security automation scripts to streamline vulnerability detection, reducing manual effort by 60%.

Performed UI and REST API testing using tools like Advanced Rest Client, ensuring seamless functionality of JSON, SQL, and HTTP-based services.

Leveraged OSINT and proprietary threat intelligence platforms to identify and track emerging APT activities and infrastructure targeting critical enterprise assets.

Created detailed threat actor profiles and adversary emulation plans to support threat-informed defense initiatives aligned with the MITRE ATT&CK and Cyber Kill Chain frameworks

Spearheaded cross-functional projects to integrate D3FEND and NIST SP 800-53 controls into the threat modeling lifecycle, aligning intelligence outputs with enterprise compliance and risk frameworks.

Reduced unauthorized access risk by 40% by implementing IAM standards and role-based access controls (RBAC).

Strengthened authentication security by deploying MFA across enterprise systems, reducing account compromise incidents.

Administered Linux and Windows systems, performing log analysis, service monitoring, and system-level troubleshooting to support telemetry pipelines.

Monitored pipeline performance using key metrics such as throughput, latency, and data health, implementing alerting for ingestion gaps and delays.

Supported enterprise-scale logging and security telemetry platforms, ensuring reliable ingestion and availability of high-volume log data across distributed environments.

Improved audit compliance through regular access reviews and timely privilege remediation.

PROJECTS

Internal Audit January 2024 - May 2024

Facilitated with Dallas IIA Chapter to identify key risk areas impacting security and perform risk assessments.

Engaged in client meetings to get an overview of the issues to enhance organization structure and security.

Developed a proposal that outlined improvements to 25% in mitigating future security threats.

Governance, Risk Management and Compliance August 2023 - December 2023

Worked on the Current and Proposed ERM framework for Toshiba Corporation.

Identified the key factors affecting the corporate governance of Toshiba Corporation.

Recommended hybrid approach with COSO, ISO31000 and NIST frameworks, boosting revenue by 25%

Cloud Computing August 2022 - December 2022

Optimized compute costs using EC2 Spot and Reserved Instances, cutting expenses by 50%.

Improved database efficiency with RDS read replicas, boosting query performance by 30%.

Reduced costs by 60% with serverless architecture using AWS Lambda and API Gateway.

Decreased load times by 40% with Amazon CloudFront for global content delivery.

Cut storage costs by 40% using S3 Intelligent-Tiering and lifecycle policies.

Certifications:

ISC2 Certified in Cybersecurity

IBM Certified Cybersecurity Professional

Certified Threat Intelligence & Governance Analyst

Cyber Security and Artificial Intelligence Risk Course

Certified Cybersecurity Educator Professional

Microsoft & Google Cloud Cybersecurity Analyst

Cisco Cybersecurity Fundamentals

AWS Security Fundamentals

Cybersecurity – Palo Alto Networks

Network Security – Palo Alto Networks

Cloud Security - Palo Alto Networks

Security Operations (SOC) - Palo Alto Networks

Splunk Fundamentals

Qualys Certified Specialist - Vulnerability Management,

Pentesting - IT Masters,

API Security Architect - API Academy,

Ethical Hacking Essentials - EC Council

Digital Forensic Investigations - uCertify.

Areas of Expertise:

Application Security

Secure SDLC

Threat Modeling

Secure Coding

DevSecOps

CI/CD Security

API Security

Security Architecture

Developer Enablement

Vulnerability Management



Contact this candidate