13+ years experienced Information Security professional with a demonstrated history of working in the information technology and services industry. Skilled in Vulnerability Assessment, Risk Management, ISO27001, PCI-DSS, etc. Achieved top industry information security certifications like CEH, ISO27001 LA. Excellent communicator who effectively interacts with peers, management team and executives. Skilled in taking a business-driven approach to security by considering organizational objectives while analyzing security.
Accountable for finding, evaluating, and addressing infrastructure vulnerabilities in an organization. Regularly performs vulnerability scans and assessments using both automated and manual methods. Managed and eliminated all discovered cyber threats while working with internal teams to drive security risk mitigation. Cybersecurity architecture and infrastructure to provide latest security performance. Leading and handling PCI-DSS compliance scanning and look after the Incidents on priority basis.
Manage global Vulnerability Management team which includes false positive validation, reviewing risk acceptance requests, scanning entire organization devices, managing all vulnerabilities, finding new CVEs and running exploits, securing Attack Surface. Work with Threat Intel and Automation team.
Have experience going over raw log files and analyzing them using correlation rule tuning and design to cut down on false positives and alerts/offences/Notifications for the attacks. Observe and analyses threats in real time, manage incidents, offer advice, include customer context, adjust search parameters, and update SOC policies and procedures.
Worked on Nexpose tool for scan scheduling and vulnerability reporting, follow-ups with business owners for remediation of vulnerabilities either at OS or application level and regular monitoring with patch management teams regarding vulnerability updates.
Maintaining strategic and tactical System availability and security administration for banking client following PCI-DSS and ISO27001 compliance standard. Having good Understandings and experience on SIEM, IPS/IDS, McAfee EDR, Imperva, Qualys Guard etc.
I worked on the CWG (Common Wealth Games) and Railtel (Indian Railways) projects as a network engineer. As part of the project, I was monitoring network connectivity in several locations and opened incident tickets when it did.
Communication Skills
Leadership Skills
Problem Solving
Team Building