[ INITIALIZING PROFILE... ]

Manikandan
Ravichandran

DevSecOps Engineer with 6+ years securing cloud-native infrastructure at scale. Specializing in container security, SBOM governance, and shifting security left across 500+ microservices. Currently hardening pipelines at PhonePe.

Manikandan Ravichandran
01

ABOUT ME

0 YEARS EXP.
0 MICROSERVICES
0 CVEs TRIAGED
0 SECURITY REGRESSIONS CUT
0 TB REGISTRY SCALE
bash — manikandan@devsec:~$
manikandan@devsec:~$ cat summary.txt
DevSecOps Engineer with 6+ years driving secure development and operations at scale. Lead container security initiatives across 500+ microservices, embedding security early in the SDLC and enforcing guardrails to block vulnerable images. Built scalable, distributed container registries (130TB Harbor setup) fronted by Nexus proxies, serving 2M–5M pulls per DC daily. Expertise: vulnerability detection tooling, GitLab runner governance, SBOM integration, compliance alignment with CSCRF, PCI, and REBIT. manikandan@devsec:~$
02

TECH STACK

Container & Registry
Docker Kubernetes GoHarbor Nexus Trivy Clair
Security Tooling
Wazuh Dependency-Track GitLab SAST SonarQube Pfsense
Cloud & Infrastructure
AWS Azure Bare Metal K8s IAM KMS
CI/CD & Automation
GitLab CI/CD Ansible Go SDKs Bash SBOM
Monitoring & Observability
ELK Stack Prometheus Grafana
Proxy & Networking
Nginx Caddy HAProxy RBAC LDAP
Programming
Python Go JavaScript Java Bash
Compliance
CSCRF PCI DSS REBIT SOC Type 2 CIS Benchmarks
03

WORK EXPERIENCE

DEC 2022 — PRESENT
PhonePe · Bengaluru
Information Security Engineer II
  • Led the container security charter, shifting security left from development to operations — ensured foundational guardrails block vulnerable images from the SDLC.
  • Built custom real-time vulnerability detection tooling for every code push and Docker image build, reducing security regressions by 70%.
  • Scaled a distributed Docker registry (Harbor 130TB) fronted by Nexus proxies across multiple DCs, enabling 2M–5M pulls per DC per day.
  • Enforced non-root container execution across 500+ microservices, eliminating privilege escalation risks with compliance gating in GitLab pipelines.
  • Automated deprecation of 300+ outdated base images across 200+ teams — raised secure image adoption from 18% → 92% in 6 months.
  • Centralized SBOM visibility via Dependency-Track + PostgreSQL: managed 700+ artifacts and triaged 10K+ CVEs by exploitability and runtime exposure.
  • Hardened GitLab CI/CD runners, enforced image provenance checks, secured ~1500 daily CI executions, eliminated non-audited runner usage.
  • Inline Trivy & Clair scanning with calibrated thresholds reduced false positives by 40% and improved SLA from 10 days → 48 hours.
SEP 2021 — DEC 2022
NetBook · Bengaluru
Senior DevSecOps Engineer
  • Led DevOps and managed transition of security responsibilities from development to operations.
  • Designed and oversaw multi-cloud infrastructure architecture.
  • Implemented Kubernetes on bare metal servers, maintaining SOC Type 2 and CIS benchmarks.
  • Automated CI pipelines, configured Caddy with RBAC, set up ELK + Prometheus dashboards, managed Kubernetes secrets via KMS, and built complex IAM policies across multiple clouds.
JUN 2019 — AUG 2021
Curl Analytics & CurlHG · Bengaluru
DevSecOps Engineer
  • Led security ops, deployed endpoint monitoring across Linux, Windows, and macOS, and implemented centralized IDAM via LDAP for Linux workstations.
  • Conducted Docker container hardening, enforced CIS benchmarks for Docker engine — managed a 4-member DevSecOps team and ran technical interviews.
  • Netapp: deployed ML product securely into Netapp storage using Kubernetes.
  • Vakt & Mercuria: application architecture design and container hardening.
APR 2019 — JUN 2019
Steinn Labs LLP · Pune
DevOps Engineer
  • Implemented AWS SaaS Factory and Multi Tenant Architecture.
  • Set up CI/CD pipelines and built secure REST APIs for backend services.
04

EDUCATION

07 / 2018
Bachelor of Engineering
E&TC · Savitribai Phule Pune University
GPA: First Class With Distinction
01 / 2014
Higher Secondary Certificate
CBSE · Army Public School, Kirkee
Score: 80.2%
05

GET IN TOUCH

Let's Build Something Secure

Open to DevSecOps, Cloud Security, and Security Engineering roles.
Let's connect and talk about securing the next generation of infrastructure.