PR

Prabhu Raj

Principal Software Engineer - Application & Cloud Security at American Heart Association (via Impelsys)

India

Work Experience

  • Principal Software Engineer - Application & Cloud Security

    American Heart Association (via Impelsys)

    Dec 2025 - Present -3 months

    India

    • Job Details:Driving end-to-end adherence to PCI-DSS 4.0.1, GDPR, ISO 27001, and NIST by coordinating internal audits and representing the organization in external assessments. Strengthening application security through continuous SAST, DAST, SCA, and license-compliance scans aligned with OWASP Top 10 and CVSS scoring. Architecting and deploying EDR, XDR, SIEM, IAM, SOAR, and TLS controls to deliver layered defense across hybrid environments. Managing secure AWS workloads by configuring WAF, CloudFront, and blue-green deployments to minimize downtime and attack surface. Embedding automated security gates into CI/CD pipelines with AWS Code Build & Code Deploy and instrumenting continuous monitoring with New Relic and AWS CloudWatch. Orchestrating threat modeling, leading incident detection and response, and hardening infrastructure to shorten vulnerability exposure and recovery time. Mentoring junior engineers and elevating security maturity by refining internal policies, standards, and best practices. Developing dashboards and KPIs to track vulnerability trends, compliance status, and incident-response effectiveness, enabling data-driven decision-making. Liaising with product owners, DevOps, and legal teams to align security objectives with business goals and regulatory requirements. Conducting post-incident reviews and implementing lessons learned to enhance processes, tools, and security posture over time.
  • Technical Lead

    Hobbyking

    Sep 2025 - Mar 2025 -6 months

    Hong Kong

    • Job Details:Led vulnerability mitigation and performance tuning across multiple e-commerce platforms, enhancing overall system resilience. Implemented recurring security updates and validated applications against OWASP Top 10 vulnerabilities to reduce risk. Managed cloud compliance programs and monitored infrastructure using SIEM tools for proactive threat detection. Configured WAF policies, CI/CD pipelines, and patching workflows; maintained robust logging, monitoring, and disaster recovery mechanisms.
  • Technical Lead - Application Security

    BSI LTB

    Jul 2025 - Dec 2025 -5 months

    India

    • Job Details:Spearheaded a five-member security engineering team, delivering hardened application builds while elevating system performance. Drove remediation efforts by integrating SAST, DAST, and license-audit workflows, resolving critical issues before production deployment. Orchestrated cloud-security initiatives, periodic OWASP Top 10 validations, and penetration testing to maintain proactive defense posture. Ensured GDPR and ISO 27001 (ISMS) compliance by enforcing control policies, managing WAF configurations, and maintaining disaster-recovery frameworks. Commanded incident response activities and championed secure coding practices to reduce vulnerability recurrence and strengthen audit readiness.
  • Senior Engineer – Ecommerce Application Development

    Brady Corporation

    Aug 2014 - Aug 2015 -11 months

    • Education

      • Bachelor's Degree in Consultancy Management

        Birla Institute of Technology & Science (BITS)

        Jan 2025 - Jan 2025 - 0 Months

      • Bachelor's Degree in Information Systems

        Birla Institute of Technology & Science (BITS)

        Jan 2025 - Jan 2025 - 0 Months

      • Diploma in Engineering

        Alagappa Polytechnic College

        Jan 1998 - Jan 2025 - 27 yr

      Skills

      View More

      Languages

      • English

        Fluent
      • Hindi

        Fluent
      • Tamil

        Fluent
      Share this Profile