Results-oriented Information Security and Risk Analyst with 3.5 years of experience in cloud security, ISO 27001 compliance, vulnerability management, policy compliance, and risk assessment. Skilled in designing and implementing security frameworks, remediation plans, and compliance controls to protect critical enterprise assets and ensure adherence to regulatory standards. Proficient in leveraging tools like ServiceNow, Qualys Guard, JIRA, and Power BI for risk tracking, remediation monitoring, and compliance automation. Demonstrated ability to conduct vulnerability assessments, gap analyses, and incident investigations to mitigate threats and enforce cloud security controls. Extensive hands-on expertise in configuring, managing, and monitoring firewalls including FortiGate, Palo Alto Networks, Cisco ASA, and Zscaler to enforce robust perimeter security, ensure secure remote access, and implement advanced threat protection. Experienced in deploying and optimizing firewall policies, VPN configurations, and intrusion prevention systems (IPS) across complex multi-cloud and hybrid environments. Recognized for extensive experience with ISO 27001 audits, risk treatment plans, and enforcing information security policies. Proven expertise in aligning security operations with industry standards including NIST, CIS benchmarks, SOX, and GDPR. Skilled in conducting threat intelligence analysis and leveraging firewall capabilities to enhance incident response and mitigation. Adept at collaborating in Agile environments, integrating security governance into the SDLC, and driving continuous improvements in compliance monitoring, disaster recovery planning (DRP), and business continuity management (BCM). Known for optimizing process workflows, security frameworks, and firewall configurations to support enterprise security posture and regulatory compliance.