Qualys
Insightful and results-driven IT professional with extensive expertise in servers, web technologies, GRC, and web security, aligned with the ISO 27001:2013 ISMS framework. Strong communication and interpersonal skills, coupled with hands-on experience in project management, security tools (Qualys, TrendMicro, SentinelOne EDR, Tenable Nessus), audits, process optimization, and documentation. Proven ability to manage stakeholders, oversee end-to-end project implementation, and drive strategic improvements. Adept at leading and mentoring teams, fostering innovation, and enhancing operational efficiency. Skilled in problem-solving and decision-making, contributing to a high-performance security posture.
• Handling multiple clients with different requirements such as security policies assessment, reporting and maintaining GRC topics, VM/ WAS scan.
• Led Vulnerability Management, Patch Management, and remediation tracking to mitigate cyber threats.
• Established and enforced corporate policies, security controls, and compliance procedures to enhance data protection and regulatory adherence.
• Identified, assessed, and mitigated cybersecurity risks, ensuring proactive security measures running permanent supervision controls and getting risk identified and accepted, documented.
• Having good experience into banking domain and healthcare Infra security and compliance.
• Ensured IT infrastructure compliance with respect to ISO27001 ISMS.
• Managed security controls implementation (Firewalls, SIEM, IAM, EDR, DLP, WAF) to meet compliance mandates.
• Implemented Zero Trust Security Model to enhance infrastructure protection.
• Governance on internal access management to practice (RBAC role-based access control)
• Handling governance on SOC VM report to be vigilant on remediation as per company policy which help in keeping open vulnerabilities to aging.
• Developed and implemented IT security governance frameworks aligned with industry standards example ISO 27001.
• Maintained compliance with industry regulations while adapting best practices as needed.
• Engage with Pentesters for POC on SEC patches related to critical CVE has available exploits and has direct impact to business and control it ahead of time.
• Managed Third-Party Risk Assessments (TPRM) and vendor security evaluations to ensure compliance with security frameworks.
• Work closely with SEC heads and directors to foresee upcoming issues and fixing it with help of NIST, SOC tools like Qualys/ Trend Micro, SIEM for secure banking operations.
• Designed Security Policies, Standard Operating Procedures (SOPs), and compliance checklists for regulatory adherence.
• Managed quality assurance program, including on-site evaluations, internal audits and customer surveys.
• Work closely with Regulators like as per clients region and local authorities following IT standards and best practice guidelines.
• Managing Large Team with Large clients to implement, delivery on security space majorly on GRC, Penetration Testing, IDS/IPS for Infra SOC, SIEM.
• Projecting KPI , KRI to CISO and business Heads and as having hands on experience on IT infrastructure domain guide to technical teams with solutioning for fix as per MAITRE ATT$CK.
Cybersecurity
Qualys
TrendMicro Deep Security
Linux
Windows
Middleware
Load Balancer
Jira
CyberArk
ServiceNow
Qualys VM
Qualys Web Application Scan
CISM Training Completed
PMP
Qualys VM
TrendMicro Deep Security
Agile Scrum Master
Prince2 Practitioner
ISO 27K:2013 ISMS Lead Implementer
Lean Six Sigma Yellow Belt Internal Certificate
ITILv3 Foundation