Speed, security and reliability are the same conversation.
Every playbook says security slows delivery and reliability costs speed. I've spent more than twenty years proving the playbooks wrong, and I write about how. If you're being asked to choose, let's discuss before you do.
Start here
All articles →Outcomes from six years leading a global DevSecOps, cybersecurity and IT operations organisation. The stories behind each number are in the articles.
Topics
Tools I've built
All tools →MTTR / MTTA / MTTI Calculator
Paste incident timestamps and get response metrics with SLA compliance by priority.
Open tool →ISO 27001 Readiness Check
A 20-question self-assessment mapped to the 2022 Annex A themes.
Open tool →DevSecOps Maturity Mapper
Score eight pipeline stages and get a prioritised improvement roadmap.
Open tool →Let's talk.
Building a security function, modernising a pipeline, or working out how much of the AI hype to believe? I'm happy to compare notes.
Writing
Articles
Real lessons from leading DevSecOps, cybersecurity, AI governance and IT operations at global scale. No vendor pitches, no theory without a scar behind it.
Free to use
Tools
Practical calculators and templates distilled from real DevSecOps and IT operations work. Everything runs in your browser. Nothing you type leaves your machine.
MTTR / MTTA / MTTI Calculator
Paste incident data (CSV) and get mean and median time to identify, acknowledge and resolve, plus SLA compliance by priority and the worst offenders.
Open tool →ISO 27001 Readiness Checklist
Twenty questions across the organisational, people, physical and technological themes of ISO/IEC 27001:2022 Annex A. Get a readiness score and the gaps to close first.
Open tool →CI/CD Pipeline Health Scorecard
Rate your pipeline across speed, reliability, security, test coverage, observability and rollback. See a radar chart and where to invest next.
Open tool →Incident Postmortem Template
A structured, blameless postmortem builder. Fill in the timeline, impact, contributing factors and actions, then export clean Markdown for your wiki.
Open tool →Follow-the-Sun Shift Planner
Pick your regions and shift windows, then see 24-hour coverage, handover overlaps and gaps on a single timeline in UTC.
Open tool →DevSecOps Maturity Mapper
Assess eight stages from plan to monitor on a five-level scale, get an overall maturity level and a prioritised roadmap of the next moves.
Open tool →
About
Prasanna V Malode
DevSecOps · Cybersecurity · IT Operations · Bengaluru, India
For me, technology leadership isn't about maintaining systems. It's about enabling a business to move faster, stay safe, and operate with confidence. I head global DevSecOps, cybersecurity and IT service operations for a telecom-software company: a 20-person team across three time zones, running follow-the-sun for more than 1,000 engineers and business stakeholders, with an annual budget of about $4M.
On that belief I built the company's information-security function from nothing to ISO 27001 with zero major audit findings, halved recurring incidents through ITIL-aligned service management, nearly doubled release frequency through CI/CD modernisation, and led one of the earlier enterprise-wide GenAI integrations spanning developer workflows, automated code review, QA and security operations. Before leading, I spent a decade in release and configuration engineering at Oracle and EMC, which is where I learned that most reliability problems are organisational problems wearing a technical costume.
That DevOps experience spans five product domains: telecom and networking software, healthcare, enterprise pricing, data storage, and conversational bot platforms. The tools changed at every step. The failure patterns did not, which is why most of what I write transfers.
Beyond the numbers, what energises me is people: building high-performing teams, mentoring the next generation of leaders, and creating environments where ownership and clarity are the default. I write here because the useful lessons rarely make it into vendor decks, and writing them down forces me to be honest about what actually worked.
Selected outcomes
Zero to ISO 27001, zero major findings
Built the InfoSec function from scratch: DLP, enterprise controls, vulnerability management with Nessus, OpenVAS, NMAP and Coverity, remediation tracked to closure on SLAs. Security incidents down 50%.
AI-powered log analysis and license scanning
A log-analysis pipeline across firewall, PRTG, SentinelOne, RMM and ThreatLocker for proactive alerting and faster triage, plus AI-driven FOSS/GPL snippet scanning that strengthened IP compliance.
Recurring incidents halved, SLA performance up 40%
ITIL-aligned incident, problem and event management across global follow-the-sun operations. Migrated a 5,000+ board network test lab to a data centre with under 2% downtime and roughly 30% cost reduction.
Releases 8 → 15 per quarter, failures down 60%
CI/CD modernisation on Jenkins, Gerrit, Docker and Kubernetes with pre-QAT quality gates and release governance. Lead time for change down 45%. Enterprise-wide GenAI adoption lifted blended Dev/QA/TAC productivity by about 50% at constant headcount.
How I work
Measure before you move
Lead time, failure rate, MTTR, incident recurrence. Uncomfortable numbers are the only ones that buy change.
Make the right thing the easy thing
Quality gates people route around are theatre. Controls that feel like safety nets get adopted on their own.
Capture facts when they are cheap
Key attribution, build provenance, handover notes. Decide early what you will need to know later, because you cannot reconstruct it afterwards.
Automate the job, not the paperwork
If a tool makes the wrong amount of work more pleasant, the queue is still there. Reduce the count or do the work.
Earn automation in shadow mode
Advisory first, compared against human decisions, promoted per class with evidence. Trust is the whole asset.
Presence is reliability
Distributed teams don't need time-zone overlap. They need to know you will respond, unblock and follow through.
Career
- Mar 2024 — PresentSenior Manager — DevSecOps, Cybersecurity & IT OperationsIP Infusion, Bengaluru · Telecom and networking software. 20-person global organisation, $4M annual budget, 1,000+ engineers supported on a follow-the-sun model. Built the InfoSec function to ISO 27001, AI-powered security operations, ITIL-aligned service management, CI/CD modernisation and enterprise-wide GenAI adoption.
- Apr 2019 — Feb 2024Manager — DevOps, Information Security & ITIP Infusion, Bengaluru · Set DevOps and SecOps strategy, delivered customer security requirements (Nessus, OpenVAS, Kali, NMAP), cut deployment times 30%, owned BCP/DR across all sites, managed the IT budget and vendor evaluations, and led the lab-to-data-centre migration at roughly 30% lower cost.
- Nov 2015 — Apr 2019Principal Engineer — Configuration & Release Engineering / DevOpsOracle, Bengaluru · Enterprise software and conversational bot platform. Built CI/CD from scratch on Jenkins, Artifactory and Gradle/Ant/Maven. Delivered 14 major releases and 22 patches for Oracle Digital Assistant, plus 40+ releases across SUITE/Enterprise and CXA Mobile Cloud Service.
- Dec 2008 — Nov 2015Associate Principal Engineer · Lead Engineer · Senior Software EngineerEMC (now Dell EMC), Bengaluru · Data storage. Managed 50+ active branches and 100+ releases, owned branching strategy and SCM security, cut build times by 86% for SRM/ProSphere.
- 2004 — 2008Early careerTechnical Specialist / Lead at AztecSoft (MindTree) on enterprise pricing platforms and a 50-project source-control migration, Senior System Engineer at Siemens Information Systems, Configuration Management Officer at Huawei Technologies, Programmer at Ypsilon Consulting.
Education
- Executive MBASymbiosis Institute of Business Management, Bangalore
- MSc, ElectronicsKarnataka University, Dharwad
- PGDCAKarnataka University, Dharwad
- BSc, ElectronicsKLE Society's P.C. Jabin Science College, Hubli
Certifications
- PMPProject Management Professional
- ITIL FoundationIT Service Management
- TL9000 / ISO 9001Quality Management