Summary
Overview
Work History
Skills
Accomplishments
Certification
Education
Timeline
Generic
Prawez Samani

Prawez Samani

CYBERSECURITY & INFORMATION SECURITY PROFESSIONAL
Gurugram, NCR

Summary

Cybersecurity and Information security professional with 9 years of progressive experience operating within the corporate domain, proficient in security research, planning, execution, and maintenance. Deep understanding of computer science, cybersecurity, and information security.

Specialized in managing focused on vulnerability management and penetration testing operations, IT infrastructure/network security, offensive architecting, threat modeling, and attack vector analysis, and working to prevent cyberattacks, especially in business and corporate settings, and building more secure systems to improve cyber defensive posture.

Adept with extensive knowledge of security vulnerabilities, offensive and defensive security capabilities, solutions, and risks in IT and highly capable of working with various types of classified network environments, and flexible in testing, development, implementation, and management of various cybersecurity solutions.

Overview

9
9
years of professional experience
6
6
Certification
45
45

Independent Coursework

2
2
Languages

Work History

Information Security Manager

Teleperformance
Gurugram, HR
04.2022 - Current

• Managing In-House Vulnerability Management Operations (PAN-India footprints) over ~50k assets along with secure configuration over ~2k assets, and penetration testing over ~5k assets for IT infra, and cloud security assessments over ~1.5kresources via cutting-edge technologies like Tenable Suite and Metasploit Pro
• Acting as a subject matter expert and “single point person” for the Vulnerability Management Operations
• Designed and developed the Risk-based prioritized vulnerabilities reporting mechanism and implemented
• Governance with IT stakeholders for prioritizing vulnerabilities response on required treatment actions
• Deployed and operationalizing Tenable agents (end-to-end) over ~50k assets (Windows family/Linux)
• Conducted gap assessments to improve the overall vulnerability management program maturity
• Participating in various POCs and implementations, assisted with scope engagements, and facilitated end-to-end independent 3rd party security assessments over 1kassets
• Automated vulnerability reporting process using Power Queries to provide a rich visual summary for IT groups
• Developed and maintained enterprise reporting metrics on vulnerabilities and cyber dashboards
• Providing technical support to IT groups to propose mitigation and remediation of the identified vulnerabilities
• Oversing the development, maintenance, and continual improvement of the vulnerability management platforms, process, procedure, and technical assessments
• Assisting client-facing teams with client queries on various engagements, and facilitated providing the fulfillment of MSAs and RFPs (Vulnerability Management) and multiple Audits
• Providing input to the leadership for enhancing the vulnerability management strategies and, supporting the budget and resource forecasting in the decision-making process of the overall VM program
• Supervising staff, mentoring junior staff, and providing feedback and coaching, so they can grow their technical and management skills

Associate Consultant

HCL Technologies
Noida, UP
10.2021 - 03.2022

• Managed Vulnerabilities Management Process for a dedicated client with over ~18k assets
• Worked with internal IT stakeholders to ensure remediation efforts adhere to the client’s policies
• Governance with IT stakeholders for prioritizing vulnerabilities response on required treatment actions
• Collaborated with client and IT teams to provide security expertise to implement the proper remediation solutions for security threats and vulnerabilities
• Automated vulnerability reporting process using Power Queries to provide a rich visual summary for IT remediation groups
• Assimilating technical data, working with large datasets, and translating into layman’s terms
• Prepared various deliverables/reports and assisted the immediate supervisor during submissions and client discussions
• Worked with the Cybersecurity GRC Team to contribute to the overall security goals and objectives

Lead Assistant Manager

EXL Service
Noida, UP
11.2019 - 10.2021

• Managed In-House Vulnerability Management Operations (Global footprints in US, Europe, LATAM, South Africa, India & Philippines) along with secure configuration over ~40k assets and penetration testing over ~7k assets of IT infra, and cloud security over ~15k resources via cutting-edge technologies like Qualys Cloud Suite and Metasploit Pro
• Acted as a subject matter expert and “single point person” for the Vulnerability Management Operations
• Designed and developed the Risk-based prioritized vulnerabilities reporting mechanism and implemented
• Governance with IT stakeholders for prioritizing vulnerabilities response on required treatment actions
• Facilitated various integration of security tools as and when required
• Implemented CIS hardening standard and operationalized over ~40k assets (Windows family, and MYSQL database)
• Deployed and operationalized Qualys agents (end-to-end) and maintain compliance over ~40k assets (Windows family/Linux)
• Conducted gap assessments to improve the overall vulnerability management program maturity
• Designed, developed, and implemented various use cases related to the vulnerability’s life cycle
• Participated in various POCs and implementations, assisted with scope engagements, and facilitated end-to-end independent 3rd party security assessments by BIG4 vendors over 7k assets
• Automated vulnerability reporting process using macros to provide a rich visual summary for IT groups
• Developed and maintained enterprise reporting metrics on vulnerabilities and cyber dashboards
• Provided technical support to IT groups to propose mitigation and remediation of the identified vulnerabilities
• Oversee the development, maintenance, and continual improvement of the vulnerability management platforms, process, procedure, and technical assessments to meet the various compliance (PCI DSS/ISO 27001/HIPAA/SOC/SOX/HITURST)
• Assisted client-facing teams with client queries on various engagements, and facilitated providing the fulfillment of MSAs and RFPs (Vulnerability Management) and Audits
• Provided input to the leadership for enhancing the vulnerability management strategies and, supported the budget and resource forecasting and the decision-making process of the overall VM program
• Supervised staff, mentoring junior staff, and provided feedback and coaching so that they can grow their technical and management skills
• Conduced Breached Attack Simulations using the MANDIANT Security Validation Platform to continuously measure and validate security effectiveness against today’s adversaries

Senior Security Analyst

Paladion Networks
Mumbai, MH
01.2017 - 11.2019

• Conducted vulnerability assessments and penetration testing for client IT infrastructure over ~11k assets including servers and network devices using Qualys VM, Nessus Pro, Metasploit Pro, and other open-source tools
• Conducted secure configuration assessments for client IT infrastructure over ~2k assets including servers & network devices, using Qualys PC and Nessus Pro
• Conducted security testing assessments to meet the PCI DSS Requirements 11 and compliance over ~1k assets
• Discussed prioritized vulnerabilities response with IT stakeholders on required treatment actions
• Developed and implemented the scanning, reporting strategies, and various VM-related use cases
• Designed and developed various vulnerability data dashboards, used by the management in the decision-making process
• Automated vulnerability reporting process using macros to provide a rich visual summary for IT groups
• Facilitated end-to-end independent 3rd party security assessments by BIG4 vendors over ~4k assets
• Conducted Qualys agent POC and helped the management in the decision-making process for solution procurement
• Deployed Qualys agent on the critical servers over ~3k assets to optimize the vulnerability management program
• Integrated Qualys with CyberArk PIM Suite and implemented various platforms centralized authentication solutions

Security Analyst

SecLabs & Systems
Greater Noida, UP
02.2016 - 02.2017

• Conducted vulnerability assessments for client infrastructure and prepared deliverable reports
• Discussed identified vulnerabilities with the client and possible solutions for remediation
• Conducted various social engineering campaigns for trust exploitation on specific targets
• Managed and maintained the C2 network and other security tools infrastructure
• Carried out the data analysis activities of various campaigns using the IBM i2® Intelligence Analysis platform
• Facilitated and designed the different scenario-based infection vectors to use for various social engineering campaigns

Technology Evangelist

Appin Technology
Pune, MH
02.2015 - 02.2016

• Trained more than 60 candidates over 1 year in cybersecurity and prepare them to achieve the relevant certification
• Conducted daily hands-on training sessions on cybersecurity and information security domains for students
• Assisted and advised trainees on short-term projects on cybersecurity concepts
• Implemented an open-source firewall for Appin’s local office to optimize and control the network traffic
• Demonstrated implementation of various open-source security products like Firewalls (Endian, pfSense), IDS/IPS (EasyIDS, Smooth-Sec, Security Onion, and Snort IDS/IPS) for educational purposes to defend the IT Infrastructure

Skills

  • SAMANI
  • Bash, Python, C, PowerShell, HTML
  • Git, Docker, VMware, Software/
  • System Engineering, Active Directory/
  • Services, Incident Response, Cyber
  • Training Development, Cybersecurity
  • Documentation, Computer Engineering
  • Technical Writing, Research &
  • Development of Cybersecurity
  • Proof of Concepts, SQL, AWS/Azure
  • CheckPoint/PaloAlto, Cryptography
  • IAM, PKI, Endpoint Protection/AV/EDR
  • VPN, SIEM, Proxy, Encryption, WAF
  • TCP/IP, MFA/SAML/SSO
  • PCI DSS
  • ISO/IEC 27001/2
  • CIS Controls
  • NIST SPs
  • OWASP
  • Cyber Kill Chain
  • MITRE ATT&CK
  • The Cybersecurity Framework (CSF)
  • PrawezSamani
  • Key Tools :
  • Nmap, Netcat, Wireshark, SysInternals
  • Qualys SuiteVMDR,PC,SCA,CSA,TP,PCI,PM,CM,FIM
  • Tanable Suitenessus,tenableio,tenablesc,tenablecs,lumin
  • Rapid7 SuiteMetasploitPro
  • Mandiant SIP (Verodin)
  • Computer Forensics Tools
  • Kali & Other Security Testing Platfroms
  • Many More Open Source Security Tools

Accomplishments

  • STD & F W K, Security (M.Sc.)- 2018
  • PROFESSIONAL » Cyber Offensive & Defensive » Cyber Intelligence » Cyber Counterintelligence » Red & Pruple Teaming » Adversarial Attacks & Emulation
  • PRAWEZ
  • CYBERSECURITY & INFORMATION SECURITY PROFESSIONAL
  • SAMANI
  • PA LADIONSI LV E R S TA R
  • AWARD WINNING
  • Nov, 2017

Certification

AWARDS INTERESTS Foundations of Operationalizing MITRE ATT&CK | Apr 2021 Qualys Certified Specialist (VM|PC|SSBP|RSBP|CA) | Apr 2017 - Oct 2020 Operational Security (OPSEC) for Control Systems | Oct 2020 Nessus Certificate of Proficiency | Mar 2018 FireEye Enterprise Incident Response | Oct 2017 FireEye Endpoint Security | July 2017 CERTIFICATIONS Certified Information Systems Security Professional (CISSP) | CBT & Pearson Certified Chief Information Security Officer (CCISO) | EC-Council Certified Information Security Manager (CISM) | ElementK SEC401: Security Essentials Bootcamp Style (GSEC) | SANS SEC560: Network Penetration Testing and Ethical Hacking (GPEN) | SANS SEC542: Web Penetration Testing and Ethical Hacking (GWAPT) | SANS Offensive Security Certified Professional (OSCP) | Offensive Security Metasploit Unleashed (MSFU) | Offensive Security Red Team Operations with Cobalt Strike | Raphael Mudge SecurityTube Metasploit Framework Expert (SMFE) | SecurityTube SecurityTube Wi-Fi Security Expert (SWSE) | SecurityTube SecurityTube Python Scripting Expert (SPSE) | SecurityTube Network Pentesting | PentesterAcademy Web Application Pentesting | PentesterAcademy RED TEAM Operator: Privilege Escalation in Windows | Sektor7 Windows/Linux Privilege Escalation (Beginners & Beyond) | TCM Security Certified Ethical Hacker (CEH) | EC-Council & CBT Nuggets Check Point (CCSA GAiA) | CBT Nuggets Palo Alto Networks Firewall | iNE Red Hat Certified System Administrator (RHCSA) | Pearson Red Hat Certified Engineer (RHCE) | Pearson Nmap Secrets Training Course | Professor Messer Mandiant Security Validation (Verodin - SIP) | FireEye Many More...

Education

Testing

Timeline

Information Security Manager

Teleperformance
04.2022 - Current

Associate Consultant

HCL Technologies
10.2021 - 03.2022

Lead Assistant Manager

EXL Service
11.2019 - 10.2021

Senior Security Analyst

Paladion Networks
01.2017 - 11.2019

Security Analyst

SecLabs & Systems
02.2016 - 02.2017

Technology Evangelist

Appin Technology
02.2015 - 02.2016

Testing
Prawez SamaniCYBERSECURITY & INFORMATION SECURITY PROFESSIONAL