Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

ANSHU RANA

Brampton

Summary

Dynamic Senior Information Security Engineer with a proven track record at Infosys Limited, excelling in cloud security and vulnerability management. Achieved an 80% reduction in vulnerabilities through robust application security programs. Adept at incident response and risk assessment, fostering collaboration across teams to enhance security posture and compliance.

Overview

4
4
years of professional experience
1
1
Certification

Work History

Senior Information Security Engineer

Infosys Limited
09.2021 - 07.2025
  • Led end-to-end investigation and resolution of security & privacy incidents, meeting SLA and regulatory requirements
  • Analyzed and remediated incidents using RAVE, DFM, ASD, CAP, and ServiceNow
  • Served as primary contact for customer notifications and remediation follow-ups
  • Monitored network and endpoint activity using Symantec DLP
  • Performed threat modeling with IriusRisk to identify and mitigate application risks.
  • Integrated and onboarded security tools (SonarQube, Fortify, Qualys, Prisma Cloud) into ArmorCode.
  • Developed SOPs, mentored junior engineers, and tracked security initiatives using Jira
  • Cloud and Application Security initiatives including posture assessments, secure architecture design, and vulnerability management across AWS & Azure
  • Implemented end-to-end AppSec programs (SAST, DAST, SCA, SCM), achieving 80% vulnerability reduction and 100% code scan coverage via AZDO, GitLab, Bitbucket integrations.
  • Conducted infrastructure and cloud vulnerability assessments using Qualys/Rapid7, reducing risk exposure by 60%through prioritized remediation
  • Designed threat modeling processes to identify, prioritize, and mitigate application and system risks
  • Built real-time vulnerability and compliance dashboards using ServiceNow (ITSM/CSM).
  • Supported NIST, CIS Controls, Mitre Attacks, ISO 27001 compliance efforts; collaborated cross-functionally and delivered cloud security awareness sessions

Education

B.Tech - Information Technology

Panipat Institute of Engineering And Technology
Haryana
07-2021

Skills

  • Cloud security
  • Vulnerability management
  • Incident response
  • Security analysis
  • Risk assessment
  • Application security
  • Threat modeling

Certification

  • Infosys Certified Associate - Cyber Security Fundamentals
  • Infosys Certified Associate - Data Privacy & Protection

Timeline

Senior Information Security Engineer

Infosys Limited
09.2021 - 07.2025

B.Tech - Information Technology

Panipat Institute of Engineering And Technology
ANSHU RANA