Summary
Overview
Work History
Education
Skills
Languages
Accomplishments
Certification
Timeline
Generic
Sathesh Amarnath Thandapani

Sathesh Amarnath Thandapani

Chennai

Summary

Results-driven professional with expertise in risk management, compliance auditing, and cloud security. Proven ability to enhance security measures and ensure adherence to regulations, driving continuous process improvement. Dynamic Principal Consultant with extensive experience in stakeholder engagement and incident response. Skilled in conducting comprehensive risk evaluations and collaborating with teams to implement effective controls, delivering measurable improvements in security posture. Proactive and adaptable expert in cloud security and process improvement. Known for leading security operations and refining compliance measures, ready to leverage deep industry knowledge to drive impactful outcomes.

Overview

13
13
years of professional experience
1
1
Certification

Work History

Principal Consultant

Wipro Ltd.,
Chennai
01.2023 - Current
  • Managed GRC metrics for Global Technology Business Controls in Banking sector as part of Special Access Governance Team.
  • Assessed GIS exceptions through comprehensive risk evaluations.
  • Conducted 360-degree due diligence on exceptions to identify associated risks and control effectiveness.
  • Collaborated with stakeholders to gather business requirements and capture artifacts for informed decision-making.
  • Challenged existing controls to enhance security measures and compliance.
  • Supported Global Information Security policies by reviewing adherence to applicable laws, rules, and regulations.
  • Facilitated internal and external audits by collecting data related to raised exceptions.
  • Compiled detailed review summaries of raised exceptions for Band 2 approvers' acceptance or rejection decisions.

Head of Security Operation center

Hexaware Technologies.,
Chennai
02.2022 - 12.2022

Monitored alerts from network security tools and Windows servers with SecureWorks XDR.

  • Conducted trend analysis to enhance cloud security posture and suggested improvements.
  • Managed MS Azure and Microsoft Cloud Azure Security (MCAS) alerts effectively.
  • Prepared weekly and monthly reports, refining processes and performing gap analysis.
  • Led SAC team to ensure timely updates for role-based access control and access management.
  • Designed and implemented AWS Cloud Security Solution Architecture, including runbooks and SOPs.
  • Monitored AWS services using Security Hub, Guard Duty, and WAF, addressing incidents promptly.
  • Coordinated completion of internal and external security audits and assessments on schedule.

Senior IT Security Analyst

Likewize
Chennai
07.2021 - 02.2022
  • Verified policies and procedures according to NIST standards.
  • Presented Monthly Security Dashboard with patching updates and vulnerability status.
  • Analyzed IT security and compliance tickets escalated in ServiceNow.
  • Executed gap analysis and documented findings.
  • Created and maintained Risk Register within the Risk Management Framework.
  • Managed vulnerability remediation using Rapid7 VM.
  • Conducted high-level architectural design assessments of IT security tools.
  • Provided evidence for Client IT Security Questionnaire and GDPR requests.

Technology Lead

Infosys Ltd.,
Chennai
03.2016 - 07.2021

Executed SOC operations for hybrid cloud platform using Splunk, Sophos AV, and Imperva.

  • Conducted daily security status updates and health checks for stakeholders.
  • Implemented NETIQ Identity Manager to enhance identity management and compliance.
  • Managed application security reviews and IAM processes to safeguard access controls.
  • Developed documentation for design architecture and standard operating procedures for security tools.
  • Configured McAfee vulnerability management via API to identify weaknesses in applications.
  • Designed and deployed Trend Micro Deep Security for ERP systems on AWS Cloud.
  • Oversaw alert management for Alert Logic WAF, ensuring robust web security measures.

IT Expert

Maersk Drilling IT
Chennai
06.2012 - 02.2016
  • Ensured global users of Maersk Drilling received uninterrupted access to IT resources and support.
  • Assigned firewall, application, and device control policies alongside IPS rules.
  • Generated vulnerability reports and escalated significant issues promptly.
  • Participated in IT separation projects, including Active Directory migration and Mail365 implementation.
  • Provided onsite support for troubleshooting, fault resolution, configuration, and installation of desktop software and hardware.
  • Engaged in IT meetings for knowledge sharing and updates on current site issues.
  • Updated team on upcoming process changes and solutions for network security threats and events.

Education

Bachelor of Science - Computer Science

SRM Easwari Engineering College
Chennai,TamilNadu,India.
04-2007

Skills

  • Risk management
  • Compliance auditing
  • Vulnerability assessment
  • Incident response
  • Security architecture
  • Cloud security
  • Regulatory knowledge
  • Process improvement
  • Stakeholder engagement
  • Project management
  • Team leadership
  • Effective communication
  • Problem solving
  • Strategic planning
  • Innovation management
  • Strategic development
  • Organizational development
  • Research and development

Languages

English
First Language
Tamil
Advanced (C1)
C1
Finnesh
Beginner
A1
Danish
Beginner
A1

Accomplishments

  • Successful SOC Implementation for Infosys UK Project & Training L1 & L2 teams for the initial response for security Events.
  • Setup of SOC Monitoring in Infosys Electronic city Bengaluru. (UK and Finland Managed Security Services).
  • Perform Risk Management and gathered all the IT Risk and registered in risk register for mitigation and creation of the Risk acceptance form.
  • Design & Implementation of Symantec Endpoint Protection for APAC region Logistics company Project.
  • Initial IT Setup for XLE3 (Maersk Integrator) Project, Singapore 2015 (On-site Role).
  • Mail365 & AD (Active Directory) Migration project support for Copenhagen HQ Maersk drilling 2014 Denmark.
  • Local IT Support for Copenhagen HQ Maersk drilling 2012 Denmark (On-site Role).
  • Won the Annual performance Award from Netgear in CSS Corp.

Certification

  • CISA - Certified Information Systems Auditor.
  • CCNA Security
  • ISO 27001 Lead Auditor.
  • ITIL V3 Foundation.
  • Agile Methodology.
  • Lean Six Sigma Trainer.

Timeline

Principal Consultant

Wipro Ltd.,
01.2023 - Current

Head of Security Operation center

Hexaware Technologies.,
02.2022 - 12.2022

Senior IT Security Analyst

Likewize
07.2021 - 02.2022

Technology Lead

Infosys Ltd.,
03.2016 - 07.2021

IT Expert

Maersk Drilling IT
06.2012 - 02.2016

Bachelor of Science - Computer Science

SRM Easwari Engineering College
Sathesh Amarnath Thandapani