Experienced Technical Speclist focused on maintaining highly secure IT environments for semi-conductor companies. Skilled in network development, configuration and patching. Leads IT teams in executing company-wide data protection protocols and security training.
§ Worked on both infrastructure and application scanning.
§ To deal with windows server, WAF, firewall and Perimeter devices.
§ Conducting weekly, Monthly, quarterly and on demand vulnerability assessment.
§ Working on vulnerability mitigation activities.
§ Identified and evaluated potential threats and vulnerabilities.
§ Creating trend reports and educating user on different vulnerabilities which needs attention.
§ Providing technical snapshots or evidences to user as well as remediation steps.
§ Conducting test on servers within test environment to find best possible solution.
§ Assessed incoming threats and developed plans to close loopholes.
§ Performed risk assessments to help create optimal prevention and management plans.
§ Maintained and tested corporate response plans.
§ Actively worked in both Infrastructure and application vulnerability scanning.
§ Worked on mitigation or remediation of discovered vulnerabilities rather than passing on scan report.
§ Performing manual assessments, identifying root cause & fix recommendations.
§ Identifying & recommendations to fix the vulnerabilities.
§ Verification of false positives reported by automated tool.
§ Actively worked in network security, Infrastructure security and application security.
§ Monitoring various tools and alerts and respond with defined SLA.
§ Monitoring support of Infrastructure devices like network device and servers, applications and other operations.
§ Incident, Alert Management and Outage handling.
§ Worked on vulnerability assessment for network devices.
§ Coordination with the vendors during network planned maintenance.
§ Monitor performance and ensure system availability and reliability.
§ Liaise with vendors and other IT personnel for problem resolution.
§ Facilitate technical/crisis management conference calls during production outages, providing written and verbal updates in timely and consistent manner.
§ Rapidly respond to all alerts, restoring or escalating service/applications issues as per established SLA.
§ Actively participated in risk analysis and mitigation plan based on review of IT Infra setup.
§ Worked on OWASP Top 10 and different attack vectors. Hands-on experience in different vulnerability scanning tools such as Nexpose, Nessus Qualys Guard, Appscan.
§ Performing application vulnerability assessments.
§ Performing assessments of SDLC processes.
§ Compliance monitoring to Information security policies and standards and assists the information security risk manager.
§ Assisting other teams and customers with vulnerability research and impact analysis of breaking issues.
Vulnerability Assessment
CEH (Certified Ethical Hacker)
CEH (Certified Ethical Hacker)