Hemanth Chinnadandluru / Integration & Security

API integration · Security · Secrets management

Secure integration
for banking systems.

I build the connections between middleware, core banking systems and the applications around them — and the secrets management that keeps them controlled.

5+ years across ESB and API management for BFSI. Senior Solution Specialist at Pronteff IT Solutions, Hyderabad.

Coverage — platform × service
Platform
PRE
CON
ENG
MIG
HashiCorp Vault
IBM API Connect
IBM DataPower
App Connect / IIB
Cloud Pak for Integration
Apigee / WSO2
Akamai API Security
PRE presales & sizing
CON consulting & strategy
ENG engineering & implementation
MIG upgrade & migration

Expertise

One problem, three angles.

Middleware moves the data. API gateways expose it. Secrets management decides who gets to ask. I work across all three, which is usually where the interesting failures live.

Integration & ESB

Middleware that banks run on

Connecting core banking systems, databases and external applications through IBM integration platforms — designed for throughput first, then for the audit that follows.

  • IBM App Connect Enterprise & IIB
  • IBM DataPower gateway policies
  • Cloud Pak for Integration on OpenShift
  • IBM MQ & Aspera transfers
  • Core banking & database connectivity

API management & security

Enterprise APIs, exposed carefully

Full API lifecycle across more than one vendor's platform, with the security layer treated as part of the design rather than something bolted on at UAT.

  • IBM API Connect lifecycle & consumer orgs
  • Google Apigee
  • WSO2 API Manager
  • Akamai API security
  • OAuth, mTLS & threat protection

Secrets management

Vault, and the case for it

Enterprise secrets management from architecture through rollout — and the solution design, sizing and licensing work that gets it signed off in the first place.

  • Vault HA topologies & DR replication
  • PKI engine & certificate automation
  • AppRole, policies, credential rotation
  • RBI & SEBI control mapping
  • Solution design, BOQ & RFP responses

Services

Four ways I come into a project.

Most engagements start at the left and move right. I can pick up at any point — including the ones where someone else built it and it now needs to move.

01 — Presales, sizing & sales

Making the technical case before anyone signs

Requirement analysis, RFP and tender responses, pre-bid clarifications, vendor-neutral platform comparisons, and demos and proofs of concept that answer the question actually being asked. On the commercial side: edition and licence selection, capacity sizing, and multi-year bills of quantity that hold up when procurement re-checks them.

RFP responsePlatform evaluationLicensing & BOQPoC

02 — Consulting & strategy

Deciding what to build, and what not to

Target architecture for integration and API estates, solution design documents, and reference topologies across data centre and DR. Includes mapping platform controls to the regulation the customer is actually audited against, API governance models, and honest advice on where a product does not fit the requirement.

Solution designReference architectureAPI governanceRBI / SEBI

03 — Engineering & implementation

Building it, and handing it over properly

Installation and hardening across DataPower, App Connect, API Connect and Vault — highly available topologies, gateway and message flow build, API lifecycle and consumer models, certificate and credential automation, and integration with SIEM and monitoring. Performance tuning where it matters, and runbooks so operations is not dependent on me afterwards.

HA & DRGateway buildHardeningRunbooks

04 — Upgrade & migration

Moving live platforms without breaking consumers

Version upgrades across the IBM integration stack, migrations onto containerised Cloud Pak for Integration on OpenShift, and moves between API platforms. The work is mostly in the planning: dependency and compatibility assessment, cutover and rollback runbooks, parallel-run windows, and preserving existing consumer credentials so downstream applications never notice.

Version upgradesPlatform migrationCP4ICutover

Credentials

Certified where it counts, hands-on everywhere else.

Certifications

IBM Cloud Pak for Integration — ArchitectHeld
Akamai API Security ArchitectHeld
HashiCorp Vault Practitioner — AdvancedHeld
HashiCorp Certified: Vault AssociateHeld
IBM Certified Administrator — Aspera HSTS v3.9.6Held
HashiCorp Vault Operations ProfessionalIn progress

Tools I work in

HashiCorp Vault IBM API Connect IBM DataPower App Connect / IIB Cloud Pak for Integration Google Apigee WSO2 API Manager Akamai API Security IBM MQ IBM Aspera IBM Sterling Vault PKI / AppRole OpenShift HAProxy / F5 QRadar RHEL / Oracle Linux

Speaking & writing

Delivered Banking Beyond Passwords, a webinar for a BFSI audience on retiring static credentials — API key rotation at scale, securing core banking batch scripts and automating certificates. Ongoing technical notes at hemanthch.com/writing.

Writing

Recent technical notes.

Contact

Have an integration or secrets problem worth solving?

Tell me what you are building and what is in the way. If it is a fit I will say so, and if it is not I will tell you that too.