“Cybersecurity professional with 7+ years of experience specializing in vulnerability management, risk assessment, and system hardening across cloud and on-prem environments.”
Overview
7
7
years of professional experience
1
1
Certification
Work History
Cybersecurity Analyst
Tata Consultancy Services
Kolkata
12.2021 - Current
Experience working as a Vulnerability Analyst. Familiarity with Vulnerability Management tools such as Qualys & Nexpose.
Linux Administrator – Installing and configuring Linux systems, monitoring performance, troubleshooting issues, managing user accounts and permissions, implementing security measures, updating software, patching, hardening compliance and ensuring system stability.
Ansible automations & PowerShell Scripting.
Conduct regular risk assessments and vulnerability scans to ensure the organizations security posture.
Guide team to perform vulnerabilities analysis and mitigations.
Create and maintain risk registers and regularly report on risk metrics.
Mitigating Security vulnerabilities on google cloud.
Knowledge on network security concepts such as firewalls, VPNs, and load balancers.
Experience on managing window & Linux Patching / Vulnerability Management with the help of Qualys Tool & Nexpose Tool. The team also assists with the prioritization and remediation of the identified vulnerabilities utilizing operational best practices to maintain all tools that are used in the scanning and identification of vulnerabilities as well as the tools used to rationalize, consolidate and apply additional contextual information.
Knowledge of and experience with applying the solution as per the Qualys & Nexpose report and implementing the Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE and Open Web Application Security Project (OWASP) processes and remediation recommendations.
Reviewed security bulletins and vulnerability patch releases.
Participated in risk assessment exercises designed to identify areas of vulnerability within the organization's IT infrastructure.
Led a team of 8 engineers, delivering 100% SLA compliance for patch management.
Reduced vulnerability count by 35% across 200+ systems through consistent remediation efforts.
Respond to and address prioritize vulnerabilities.
Prioritize and implement process and tools to provide for the continuous analysis of security threat information (viruses, industry events, hackers and zero-day exploits, OEM weaknesses, etc.) in order to proactively assess and investigate existing as well as emerging vulnerabilities and their potential impact.
Demonstrated knowledge of security industry standards and leading practices (e.g. PCI, OWASP, NIST, CIS, CVSSv3).
Plan, develop, and execute vulnerability scans of organization information systems.
Analyze data from threat and vulnerability feeds and analyze data for applicability to the environment.
Conduct threat modeling, vulnerability assessments, and implement strategic mitigations.
Identifying and addressing vulnerabilities across networks, cloud environments, and third-party services.
Technical Support Engineer
Renovision Automation Pvt Ltd
Kolkata
01.2018 - 11.2021
Provide security awareness training on vulnerability management best practices to internal stakeholders.
Establishing daily operations, regular communications, resource planning, providing guidance, relaying leadership expectations and leading team initiatives and activities.
Work with security governance, risk, and compliance capability to ensure vulnerability scanning incorporates controls and compliance requirements.
Proficient in Linux & Windows operating systems in remediating vulnerabilities.
Education
B-Tech - Electrical Engineering
Mallabhum Institute of Technology
01.2016
Higher Secondary Education - Science
B.S.K collage Maithon
01.2012
Skills
Qualys
Nexpose
Ansible
Vulnerability Assessment
Linux/Windows Hardening
IDPS
Python
PowerShell
Team Leadership
Vulnerability analysis
Risk assessment
Threat modeling
Vulnerability management
Security compliance
Patch management
Linux administration
Ansible automation
PowerShell scripting
Cloud security
Ethical hacking
Certification
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
Mitigating security vulnerabilities on google cloud
Ansible Automation
ITIL Foundation (Information Technology Infrastructure Library)
Microsoft Certified: Azure Administrator Associate (AZ-104)
Assistant Delivery Manager at Tata Consultancy Services, Global Shared ServicesAssistant Delivery Manager at Tata Consultancy Services, Global Shared Services