Summary
Overview
Work History
Education
Skills
Accomplishments
Software
Certification
Timeline
Generic

Devashish Prasad

Cyber Security
Delhi

Summary

Dedicated IT professional with skills in IT service delivery, project management (ITIL principles), and expertise in cybersecurity, GRC. Proficient in navigating complex regulatory landscapes, ensuring compliance with GDPR, PCI DSS, HIPAA, and implementing best practices from ISO 27001 and NIST 800-53 frameworks. Robust understanding of XSOAR engineering, actively enhancing incident response capabilities.

Overview

16
16
years of professional experience
13
13
Certifications

Work History

Senior Manager

HCLTech Supercharge
07.2022 - Current
  • Managed XSOAR engineering lifecycle, overseeing server deployment, configuration, and optimization.
  • Led team in scaling XSOAR components for organizational growth.
  • Spearheaded server administration, maintenance, and application deployment, aligning with security policies.
  • Implemented monitoring, troubleshooting, and migration strategies, reducing downtime and enhancing stability.
  • Orchestrated migration to SaaS platforms, establishing seamless communication channels and integrating with security tools.
  • Implemented automation frameworks, reducing manual efforts.
  • Developed sophisticated playbook logic for efficient incident response.
  • Managed large-scale projects and introduced new systems, tools, and processes to achieve challenging objectives

Assistant Manager IT Security

MetLife Global Operation Service Centre
12.2019 - 07.2022
  • Led ITGC initiatives, conducting internal audits for control framework enhancement and compliance.
  • Pioneered SOC 2 Type 2 assessments, developing policy frameworks and demonstrating continuous improvement.
  • Led high-performing team, enhancing productivity and job satisfaction.
  • Orchestrated kick-off meetings for project alignment, maintaining strong stakeholder relationships.
  • Implemented structured approach for project discussions.
  • Established robust document validation process, identifying and rectifying discrepancies collaboratively.
  • Developed and maintained documentation checklist, streamlining the validation process for audit preparations.

Technical Specialist

HCL Technologies Ltd
12.2016 - 12.2019

Description: Managed global GRC initiatives, aligning with ISO 27001, NIST 800-53, GDPR, PCI DSS, and HIPAA standards. Implemented robust frameworks, led GDPR and PCI DSS compliance, conducted security assessments, and facilitated effective communication for vulnerability resolution in a proactive cybersecurity environment.


  • Managed GRC initiatives globally, aligning with ISO 27001, NIST 800-53, GDPR, PCI DSS, and HIPAA.
  • Implemented robust frameworks, conducted risk assessments, and facilitated audits.
  • Played a key role in GDPR compliance, security assessments, SAST, and DAST.
  • Led PCI DSS compliance with thorough security assessments, SAST, and DAST tests, mitigating risks.
  • Collaborated for prompt pen test and vulnerability scan remediation, fostering proactive cybersecurity.
  • Facilitated cross-functional communication for vulnerability resolution, maintaining continuous dialogue.
  • Conducted end-to-end assessment of COTS solutions for third-party applications, including evaluations of Palo Alto, Symantec, and Mandiant.
  • Shared risk observations and monitored mitigation plan progress.

Technical Specialist

IBM India Private Ltd
04.2011 - 12.2016

Description: Oversee the operations of IT infrastructure, manage cyber incidents, and handle vulnerability management on a 24x7x365 basis for a diverse range of global clients, including industries such as chemical, manufacturing, transportation, logistics, banking, insurance, and retail.


IT Service Delivery _36 Months

  • Manage incidents, coordinate resolutions, and implement proactive measures to minimize disruptions.
  • Oversee Change, Problem, and Asset Configuration Management processes, ensuring compliance.
  • Provide on-site support, coordinate with remote teams.
  • Develop real-time dashboards for monitoring and analysis.
  • Chair management review calls, collaborate for continuous improvement.
  • Ensure seamless coordination across IT service management


Cyber incident response / Cyber security project Management_32 Month

  • Lead SOC development, architect workflows, and integrate technologies for improved threat detection.
  • Establish SOPs, foster analyst collaboration, monitor alerts, and conduct investigations.
  • Refine playbooks and enhance SOC operations through training and proactive threat hunting.
  • Conduct PoC assessments for security tools, seamlessly integrate them into infrastructure, and lead successful production deployment.
  • Drive cybersecurity projects, managing timelines and resources for robust security implementation aligned with organizational goals.

Senior IT Analyst

HCL Technologies Ltd
12.2007 - 04.2011

Description: Began as an IT analyst, initially focusing on service desk and escalation management, later transitioning to specialize in identity and access management for global clients.


IT Service desk & Incident management responsibilities_24 Months

  • Diagnose and resolve technical issues as an IT Service Desk professional, ensuring timely support to end-users.
  • Committed to customer satisfaction, efficiently manage service requests, and maintain detailed documentation.
  • Proficient in troubleshooting hardware and software.
  • Excellent communication skills contribute to ensuring seamless IT operations.


Identity and Access Management_24 Months

  • Administer user identity lifecycle in Active Directory and IDM, ensuring security policy adherence.
  • Resolve email issues using Exchange Console, configure mailbox settings, and optimize services through cross-functional collaboration.
  • Implement Active Directory organizational units for efficient user account management and administrative task delegation.
  • Oversee Distribution List creation and maintenance, ensuring accurate membership and permissions.
  • Manage shared folder creation with secure access controls.

Education

Bachelor of Arts - Globalization, Economics, English

Delhi University
Delhi
04.2001 -

Skills

IT Service Delivery

undefined

Accomplishments

  • Engaged in the migration of the IT help desk.
  • Implemented ITIL successfully for a client transitioning from an offline to an online business setup.
  • Successfully completed the Proof of Concept (POC) and Proof of Value (POV) for a new security product within the specified timeframe.
  • Consistently met deadlines for Governance, internal IS Audit, and SOC2 Type 2 assessment for financial applications used by third parties.
  • Accomplished cloud migration for security tools within established timelines.
  • Actively participated in the maturation of SIEM (Security Information and Event Management) and the implementation of XSOAR (Cortex XSOAR).

Software

Python

Certification

Introductions to CISSP from SimpliLearn

Timeline

Cortex XSOAR Engineering / Administrator Back & restore / XSOAR deployment from Palo Alto

08-2023

CompTIA Security+ Udemy

07-2023

Certified in cyber security from ICS2

06-2023

Certified cloud security professional (CCSP) Cybrary

06-2023

Cyber Security operations and Technology solutions from Udemy

11-2022

Advance Cyber security – Threats and Governance from Great Learning

08-2022

Senior Manager

HCLTech Supercharge
07.2022 - Current

Network defense Essentials (NDE) EC Council

03-2022

Introductions to CISSP from SimpliLearn

02-2022

Completed ISO27001 Lead Auditor from GAQM

11-2021

Ethical Hacking from SimpliLearn

06-2021

CCPA Compliance Traning from WireWheel

10-2020

Assistant Manager IT Security

MetLife Global Operation Service Centre
12.2019 - 07.2022

Scrum Fundamentals Certified (SFC) from Scrumstudy

09-2018

Technical Specialist

HCL Technologies Ltd
12.2016 - 12.2019

ITIL Foundation from EXIN

03-2014

Technical Specialist

IBM India Private Ltd
04.2011 - 12.2016

Senior IT Analyst

HCL Technologies Ltd
12.2007 - 04.2011

Bachelor of Arts - Globalization, Economics, English

Delhi University
04.2001 -
Devashish PrasadCyber Security