We provide IT Staff Augmentation Services!

Pci Technical Sme Relevant Resume

2.00/5 (Submit Your Rating)

SUMMARY:

  • Conducted and directed the security assessments, GAP analysis, and remediations based on the industrial best practices, e.g. PCI DSS, ISO 27001/27002.
  • Conducted internal and external Pen Tests for applications on critical systems, including networks and web applications.
  • Improved the accuracy of the scope of security assessment according to the captures, processes, storage, transmission of the sensitive data, the systems connected, and the systems which may impact the security of environment in scope, and the outsources systems at service providers.
  • Rectified the vendor engagement processes and responsibilities including the due diligent questionnaire to meet the regulatory requirements, e.g. PCI DSS 12.8.
  • Directed and advised the scanning/correction/re - scanning of the vulnerability scanning for high ranking known vulnerabilities based on the industrial best practice, e.g. PCI DSS.
  • Identified the affected users and systems ; isolated the compromised network; evaluated the root cause of the infected systems; eradication, and recover the isolated network in an incident response processes.
  • Develop the policies and procedures based on the industrial best practices, like PCI DSS, ISO 27001/2.
  • Communicated effectively to the business and technical teams to define the audit scope, to conduct adequate fieldwork, and to remediate exceptions.
  • Reviewed and established continuous compliance tools below.
  • Standard firewall rules sets to isolate DMZ and sensitive data networks.
  • System hardening configuration standard for all new installed system.
  • File integrity monitoring to prevent unauthorized changes of data files.
  • Configuration of the IDS/IPS to monitor malicious activities.
  • Endpoint security including antivirus functions.
  • Web application firewall that detects and prevents web based attacks.
  • Centralized SIEM to capture and analyze the log files.

PROFESSIONAL EXPERIENCE:

Confidential

PCI Technical SME relevant

Responsibilities:

  • Participated in the Confidential ’s Application Review Board and reviewed new applications regarding the PCI risk assessment.
  • Performed and directed regulatory risk assessments and remediations for the tokenization and P2PE solution providers regarding sensitive data storage.
  • Conducted regulatory risk assessments and compliance audits for Confidential fax and telephone service containing the sensitive data.
  • Rectified the accuracy of the scope of the call center for the outsourced controls which does not cover the regulatory compliance attestation report.
  • Directed and educated the misunderstanding and misinterpretation of regulatory requirements, e.g. P2PE, POS scope.
  • Analyzed and rectified the responsibilities and scope of the Ecommerce website which redirects payment pages.
  • Coordinated Confidential ’s vulnerability scanning team and redirected the control processes to meet the PCI requirements.
  • Planned, coordinated inter-department, and executed PCI internal and external risk assessments in hospitals, pharmaceutical production lines, and research centers all over the US.
  • Cybersecurity Investigation red team relevant
  • Conducted a cybersecurity investigation, Penetration Test, on Metasploitable2 which is an intentionally vulnerable Linux machine and successfully exploited all 30 open ports out of the whole 65,535 ports scanned.
  • Researched methodologies of exploitations on common vulnerabilities for network and web.
  • Performed internal and external Pen Tests on product cybersecurity and application cybersecurity including network and web applications.

Confidential

Independent IT Security Consultant

  • Conducted ISO 27001/2 Internal Audit.
  • Evaluated the organization’s context, Leadership commitment, plan, support, operation, performance, and continuous improvement.
  • Applied the risk assessment, risk treatment methodology, and conducted the risk assessment process and risk treatment plan.
  • Conducted ISO 27001/2 GAP Assessment.
  • Identified the nonconformities between the ISO 27001/Annex A and the organization’s internal controls and provided remediation controls.

Confidential

IT Security Consultant and PCI Qualified Security Assessor

  • Conducted PCI DSS 3.2 Report on Compliance (ROC) Assessment/GAP Analysis/SAQ assessment including Presale Support, Charter Call, RFI Pre-assessment, Analysis and Sampling, Onsite assessment, Remote Validation, Submission of ROC, Exit meeting
  • Conducted SOC 2, SSAE16 Assessment
  • Conducted HIPAA Risk Assessment
  • Network Segmentation: Reviewed the firewall/router configuration standard, evaluated the firewall rule sets, and identified the documented business justification for the service/protocol allowed into the sensitive data network segments to substantiate the regulatory requirements, like PCI, SOC2, and the HIPAA/HITRUST.
  • System Hardening: Reviewed the configuration file, active services list and compared with the vendor documentation to ensure that system hardening was conducted per industry best practice.
  • Cryptography: Observed the configuration settings of the cryptography for the data at rest and in motion to verify that strong and secure encryption protocols were designed properly and in place.
  • Anti-virus (Defender, McAfee, Kaspersky, Symantec, Trend Micro) and Patch Management: Examined the configuration files of Anti-virus and Patch Management to ensure that signature was current, periodic scanning was performed, and the log file was generated.
  • SDLC: Reviewed the SDLC policies and procedures and observed the ticket of a recent modification of the code to verify that code review was conducted, and segregation of the duty was performed.
  • Change Management (Jira, Lighthouse): Inspected the change ticket to verify that change was approved by the management, the impact was evaluated, function test was conducted and the back-out was prepared.
  • Evaluated the Common Coding Vulnerability, OWASP, on the SDLC
  • Identity/Authentication Management: Examined the access control matrix, like AD domain controller, authentication credential, the password parameters to ensure that identity and authentication management were executed per industry best practice.
  • Physical Access: Observed the physical access control, like Facility Entrance Control, Visitor Log/Badge Management, and media controls to ensure the regulatory requirements were met.
  • Audit Trail Management: Examined the configuration file and observed the alert ticket to ensure that audit trail was generated for security management events, time server was configured coherently, centralized log server was implemented, the audit trail was secured, and the alert was reviewed.
  • Vulnerability Scanning/Penetration Test: Reviewed the Vulnerability scanning/Penetration Test reports to ensure that vulnerability scans were periodically performed, corrections were conducted and the re-scan to pass was executed.
  • IDS/IPS (SonicWall, FortiGate, Cisco, Ossec): Examined the configuration of the IDS/IPS to ensure that the signature was current, and the alert was generated and reviewed in a timely manner.
  • File Integrity Monitor (FIM): Reviewed the configuration of the FIM to ensure that critical files were monitored, and the alerts were generated and reviewed in a timely manner.
  • PII Privacy: Delivered advisory service on the de-identification of the Personal Identifiable Information (PII)
  • Incident Response Plan (IRP): Reviewed the policies, the procedures, and the training record of the IRP to ensure that the IRP was thorough and contain all the key elements to allow the company to respond effectively in the event of a breach that could impact cardholder data.
  • Identified, evaluated the IP range in scope for the Penetration Test on the segmentation of the network, and reviewed and judged the adequacy of the detail of the Penetration Test Report regarding the PCI requirements.

Confidential

  • Helped clients file tax returns, performed Revenue Recognition, amortized and controlled Fixed Assets, reconciled Bank statements, resolved G/L, reconciled Trial balances, and compiled financial reports.
  • Audited Information Systems over financial reports.
  • Managed Data Migration, and recommended risk mitigation plan in internal control.
  • IT Audit on Account and password management, File Integrity Monitor, Network security and controls, Centralized Log management, and General Controls on Operating Systems, Database Servers, Applications, Web Application, and Internet Servers.
  • Evaluated change, configuration and release management practices to determine whether scheduled and nonscheduled changes made to the organization’s production environment are adequately controlled and documented.
  • Evaluated Identification, authentication and authorization processes, including login controls, password controls and role-based access controls to mitigate access risk
  • Evaluated the design, implementation, and monitoring of system and logical security controls to verify the confidentiality, integrity and availability of information.
  • Evaluated the design, implementation, and monitoring of physical access and environmental controls to determine whether information assets are adequately safeguarded.

We'd love your feedback!