© Mapbox, © OpenStreetMap
Randi Ratnayake

Randi Ratnayake

Azure | Consultant | Developer | Architect | DevSecOps Evangelist | Mentor

Melbourne, Australia

Actions

Randi is a cloud architect, developer, passionate consultant, and DevSecOps expert who empowers organisations to innovate with secure, agile, and fast-moving technology. A Microsoft-certified coach and NextGen mentor, he trains teams and inspires young developers to confidently navigate cutting-edge tech stacks and thrive in the industry.

Area of Expertise

  • Information & Communications Technology

Topics

  • Azure
  • API-Management
  • DevSecOps
  • DevOps
  • GitHub Actions
  • GitHub
  • Azure DevOps
  • iPaaS
  • Azure Logic Apps
  • Cloud Architecture
  • Software Development Best Practices
  • Azure DevOps Pipelines
  • Azure Bicep
  • Azure Data Factory

Your Application Knows Too Much

Names, emails, phone numbers, addresses, and financial details our applications handle way too much personal information every day.

But once a user gives us their data, do we really know where it travels?

It can quietly travel through APIs, logs, databases, telemetry, analytics, support systems, third-party services and often without anyone stopping to ask whether it should.

We spend a lot of time securing data. But security asks, "How do we protect it?"

Privacy starts with a different question: "Should this data be here at all?"

In this session, we'll explore how developers can build applications that recognise sensitive information, understand where it is going, and automatically protect or anonymise it before it escapes its intended boundaries.

We'll look at real-world scenarios, practical techniques, and modern approaches to detecting and protecting personal information across applications, including the increasingly important boundary between our systems.

Because a data breach doesn't always start with a hacker.

Sometimes, it starts with our application knowing too much.

Keep the Story, Lose the Identity

Synthetic data is safe. It is also often too perfect. Real-world data contains messy language, missing information, strange formats and unexpected patterns that expose where our solutions fail.

So how do we use real-world data responsibly? How do we keep the story but leave the identity?

Behind every record is a real person, and using data beyond its original intent carries responsibility. Yet without those real stories, our solutions can become a fairy tale.

For engineers and architects, this talk explores how to use real-world data responsibly. We’ll look at why redacting obvious personal information is not enough, how context can reveal identity, and how replacing sensitive data can change the meaning of the original story.

You’ll leave with a practical way to think about what data you need, what to redact, what to retain, and how to validate the result.

I Built a Better Version of Me. It Runs on AI.

It's a story about a system designed around my weaknesses, powered by AI to help me make better decisions, and backed by information and facts rather than emotions.

I have spent my career building systems that are reliable, scalable, and predictable. Then I realised the least predictable system I interact with every day is myself.

When making decisions, I don't always have perfect information. Sometimes emotions take over, sometimes I focus on information that confirms what I already believe, and sometimes I act before fully understanding the risks. So I did what engineers do.

I built an ecosystem; the aim was simple. Build a better version of me.

A personalised AI decision partner designed to help make decisions for me, but one that helps me gather information, analyse evidence, challenge assumptions, and think more clearly before making financial decisions.

We will explore how AI can move beyond simple conversations into practical systems that act as a thinking partner, why human judgement still matters, and what happens when you build technology designed not to replace yourself, but to make yourself better.

This is not a story about AI replacing humans. It is a story about using AI to build a better version of ourselves.

45-minute session combining personal story, AI engineering, and practical lessons from building an AI-powered decision assistant. Suitable for developers, architects, and anyone interested in practical AI systems. No prior AI experience required. First public delivery.

From Chaos to Insights with Azure Content Understanding

What if every call your organisation take could generate actionable insights faster than the call itself? In this session, we’ll explore a real-world business transformation: how one organisation went from auditing less than 10% of calls to achieving 100% coverage, turning compliance from a persistent headache into real-time clarity.

We will also explore how Azure Content Understanding can transform not just audio, but videos, documents, and images into structured, actionable insights almost instantly, enabling smarter, faster decision-making across the organisation, whether it’s a thousand invoices or a 1,000-page contract, and how to unlock actionable insights in minutes.

By the end of this session, you’ll walk away thinking about the endless possibilities of what your organisation could achieve when content truly understands itself.

Refactoring Your Career: From First Commit to Last Pull Request

Just like the code we write, our careers need refactoring. Technology never stands still. Frameworks rise and fall, cloud evolving at this very minute. AI is transforming how we build software, and something else will be next.

The skills that helped you get one job might not be enough for your next one. The challenge (and the opportunity) is learning how to adapt without burning out or feeling left behind.

In this talk, we’ll explore what it means to “refactor your career” so you can thrive no matter what the next tech wave is. Whether you’re looking for your first dev role or have been coding for decades, the principles are the same: embrace change, invest in timeless skills, and leverage emerging tools to your advantage.

The term refactoring was popularised in the 1990s to describe improving code without changing its behaviour. Small, thoughtful improvements keep the system healthy, and the same applies to our careers.

With so many technologies emerging constantly, the key isn’t to learn everything, but to stay open, curious, and adaptable. You’ll learn how newcomers can stand out by building solid problem-solving foundations, how mid-career developers can avoid stagnation by diversifying their skills, and how experienced developers can remain in demand by focusing on leadership, mentoring, and system-level thinking that no tech wave can replace you ever.

Treat your career as a codebase. Review, identify what to keep, what to improve, and what to rewrite. By treating your career like evolving software, you’ll be ready for today’s wave and whatever comes next.

Let’s explore, share, and learn together how to keep our developer careers adaptable, resilient, and in demand from first commit to the last pull request.

Zero to Hero in Azure Bicep

This session aims to show how easy it is to get a good grip on Azure Bicep without prior knowledge. Azure Bicep is the successor of ARM templates and the way forward to deploy resources to Azure. This session is not only for infrastructure developers, any developer who needs to get a good grip of how easily you can add the infrastructure skills will benefit from this.

If you are not new to Bicep, this session will also share some good insights on the best practices to organise and maintain your Bicep to scale.

APIs at Scale with Azure API-Management (API-M)

In the dynamic landscape of modern software development, APIs have emerged as the connective tissue enabling seamless integration and collaboration across diverse applications. As businesses expand and digital ecosystems grow increasingly intricate, managing APIs have becomes a paramount challenge.

Join me as I share my experience in APIs at Scale with Azure API Management (API-M). In this session, I will explore Azure API Management's role in taming the complexities of API management in a rapidly evolving technological landscape. I will share real-world challenges, best practices, and case studies, showcasing how Azure API Management empowers organisations to orchestrate, secure, analyse, and scale APIs effectively.

Whether you're a developer, an architect, a technology enthusiast or a business stakeholder, this session will promise valuable insights into harnessing a solid foundation for successfully adopting Azure API Management (API-M) in your organisation and Integration Platform as a Service iPaaS solutions.

This is the first public delivery of this topic and require 45 minutes slot at minimum.

DevSecOps is not a role! not a title!

Did DevSecOps become another buzzword? Is it a fancy way to say deployments are automated? Do organisations still see DevSecOps as another skill set? Treat DevOps as another speciality, another Silo! Consider DevSecOps as another role or a job title.

The DevSecOps engineer is supposed to be the person who implements all DevOps practices. Why a single specialised role has to do all this? DevOps, in aiming to break the silos between development and operations teams, did we create another silo?

This talk discusses why DevSecOps is not a role or job title. Instead, developers maintain a culture, practice, and constitution for confidently deploying every version on production servers why each one of us developers should be a DevSecOps engineer.

This is a lightning talk, aim for 10-15 minutes highlighting one of the greatest failures in organisations in adopting DevOps practices.

Beyond Prompts: Building Production-Grade AI with Microsoft Foundry Hosted Agents

Traditional AI agents are great for chat experiences, but enterprise applications often require much more than prompts and tools. Microsoft Foundry Hosted Agents enable developers to build code-first, containerised agent applications while Azure handles hosting, scaling, identity, and operational concerns. In this session, we'll explore the evolution from traditional Foundry Agents to Hosted Agents, compare the classic and new Foundry experiences, and demonstrate how Hosted Agents enable production-grade orchestration, multi-agent systems, and enterprise integration patterns. Learn when Hosted Agents are the right choice and how they can accelerate your journey from AI prototype to enterprise solution.

Target Audience
Developers, Architects, AI Engineers, Cloud Engineers, and Technical Leads.

Preferred Session Duration
40 minutes (a 30-minute condensed version is also available).

Secure by Design: Building Production-Ready MCP Servers

Building an MCP server is easy. Building one that is secure, production ready, and designed for enterprise applications is a very different challenge.

In this session, we'll start by looking under the hood to understand how the Model Context Protocol actually works. We'll unpack the protocol, explore what the client libraries abstract away, and see how tools are discovered, invoked, and secured. Understanding these fundamentals is key to building MCP servers that are secure by design.

From there, we'll implement authentication using OAuth 2.0, Microsoft Entra ID, and the On-Behalf-Of flow, while covering common security pitfalls and production best practices. Although the concepts and architecture are language agnostic, all demonstrations and code examples will be implemented in .NET.

Whether you're building AI agents for internal tools or enterprise platforms, you'll leave with a solid understanding of MCP under the hood and the practical knowledge to build secure, production-ready MCP servers with confidence.

Randi Ratnayake

Azure | Consultant | Developer | Architect | DevSecOps Evangelist | Mentor

Melbourne, Australia

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top