top of page

Vineeth Reddy Mandadi

Splunk Security Engineer at Leidos

Vineeth Reddy Mandadi

FELLOW MEMBER

Over the last decade, Vineeth Reddy Mandadi has built a specialization at the operational core of modern digital enterprises: observability, security analytics, and cloud automation. His career is defined by designing and running Splunk-based monitoring and security programs that keep critical platforms measurable, compliant, and resilient across highly regulated and high-traffic environments—including healthcare and federal systems, financial services, telecommunications, and automotive digital products. With credentials spanning Splunk Admin and Power User as well as AWS Certified Solutions Architect, Mandadi’s work sits at the intersection of signal engineering, infrastructure automation, incident response enablement, and compliance telemetry.

At Leidos, Mandadi serves as a Splunk Security Engineer supporting a Digital Modernization initiative, owning full lifecycle management of Splunk infrastructure across four clustered hybrid environments. His work emphasizes automation and controlled change in production-grade systems. By building Jenkins + Terraform deployment workflows, he reduced provisioning time by 60%+, and by leading a RHEL-7 to AL-2023 migration using Ansible, he achieved zero downtime with automated rollback capability—an outcome that reflects disciplined release engineering in environments where outages carry operational and reputational cost. He also expanded monitoring value by developing Splunk ITSI dashboards that increased infrastructure monitoring coverage by ~40%, and by integrating Splunk with NetBox and Jira via REST APIs, he enabled real-time correlation between operational events and configuration or ticketing context. His responsibilities include managing multi-terabyte daily ingestion while maintaining high availability—work that requires careful control of pipelines, indexing strategy, capacity management, and fault domains.

Mandadi’s Leidos work also extends into federal compliance and security operations for the Centers for Medicare & Medicaid Services under the Infrastructure Hosting and Centralized Connectivity Services program. Implementing Splunk Enterprise Security with Risk-Based Alerting, he reduced false positives by 40%+, improving analyst throughput and signal quality. He built automated ingestion pipelines that continuously bring in security telemetry from firewalls, intrusion detection systems, and cloud infrastructure. A major differentiator of this work is translating security data into audit-ready evidence: dashboards mapping logs to NIST 800-53, FISMA, and CMS-specific controls reduced audit preparation effort from weeks to days while processing terabytes of security data daily across hundreds of CMS systems. In practice, this is not “dashboarding”—it is operationalizing governance through data.

In financial services, Mandadi’s work at Early Warning Services supported the expansion of the Zelle Network used by over 2,100 financial institutions. By building advanced alerting and anomaly detection integrated with ServiceNow, he reduced MTTD by ~65% and MTTR by ~50%, strengthening incident response in a payments ecosystem that indirectly affects over 100 million end users. He also built 80+ custom dashboards supporting executive reporting, fraud detection, and engineering diagnostics. His architecture work included high availability indexer clusters achieving 99.999% uptime, while maintaining SOX and PCI-DSS compliance, and delivering monitoring views aligned to PCI-DSS, NACHA, and FFIEC requirements.

In telecommunications, Mandadi developed a Video Advertising Monitoring Solution at Charter Communications, consolidating monitoring across multiple ad-delivery channels and third-party systems (including Canoe, FreeWheel, and Cadent POIS). Processing logs from 9 ad routers and ~80 mADMs, he authored 50+ correlation searches that reduced mean time to detect ad insertion failures by 70%+. Integrating SNMP trap alerts into NetCool NOC enabled 24/7 visibility, and summary indexing improved report generation speed by ~40%—a combination of real-time operations and reporting efficiency. The solution received Media Rating Council recognition as a “Best DAI Monitoring Solution among MSOs,” indicating external validation of monitoring rigor in an industry where measurement integrity is central.

Earlier, at Legg Mason, Mandadi acted as the sole Splunk point-of-contact and led a full on-prem to AWS migration, owning planning, execution, and post-migration optimization. This work included advanced parsing, filtration, and data masking at the indexing layer, real-time vulnerability alerting from Palo Alto firewall logs, and AWS security monitoring across subnets, IAM roles, VPC changes, and gateways. He also integrated multiple threat intelligence sources (e.g., PhishMe, Recorded Future, Cofensive) and collaborated with providers such as SecureWorks to strengthen user behavior analytics for detecting insider threats and anomalous activity—an example of turning telemetry into actionable security posture.

At Ford Motor Company, Mandadi implemented Splunk-based monitoring for the FordPass App, supporting millions of users worldwide. He designed ingestion pipelines capturing telemetry, API performance, and connected vehicle communication events; built dashboards for uptime, latency, and error trends; and integrated Splunk with incident management to trigger automated escalation workflows. Beyond reliability, his executive dashboards on engagement and feature usage influenced product roadmap decisions, while authentication and API security monitoring strengthened platform defenses.

Across roles, a consistent pattern emerges: Mandadi’s work does not stop at “collecting logs.” He builds operational systems—dashboards, correlation searches, risk models, runbooks, and automated pipelines—that convert telemetry into reliability outcomes, measurable security improvements, and compliance readiness, while transferring knowledge through training, architecture documentation, and onboarding playbooks.

bottom of page