

Information Security professional with 20 years of progressive experience in managing investigations, personnel matters and sensitive information and intelligence. Leads, maintains and improves operations and functions of security department while effectively managing crises in fast-paced environment. Thorough knowledge of advanced security systems, computerized access control, and security-related legislation and regulation. Information Security Specialist with passion for aligning security architecture plans and processes with security standards and business goals. Extensive experience developing and testing security framework for cloud-based software. Versed in robust network defense strategies.
Infrastructure & Network Security
Identity & Access Management
Cybersecurity Risk Management( ISO 27001,SOC 1 & 2, ISO 27701,GDPR, HIPPA, PCI-DSS)
Code Security & Vulnerability Management
Data Privacy and Protection Compliance Management
Threat Monitoring & Incident Management( SIEM SecOps)
Physical & Device Security
SIEM Tools - (Squadcast, SOCRadar, Bitsight)
Application Security Tools- BurpSuite, Webinspect,Fortify,Sonarqube,ZAP,Github-Depandabot,CodeScanning,Secret Scanning)
Cloud Security( AWS Shield, Inspector, GuardDuty,Securityhub, AWS Event Bridge,VPC Flowlogs
Cyber Security Awareness Training
Design & Implement information Security Framework
CISM
CISM