We provide IT Staff Augmentation Services!

Lead Security Engineer/consultant Resume

2.00/5 (Submit Your Rating)

O Fallon, MO

SUMMARY

  • An Information Security Professional with experience of over 10 years in Application Security, Security Architecture & Design, Cloud Security (AWS & Azure), API Security, Penetration Testing, Network Security, Secure Coding, Mobile Security, Cryptography, PKI, Security Information Event Management (SIEM), SOC, Security Controls and Validation, IT Risk Assessments, Regulatory Compliance and Secure Software Development Life Cycle (secureSDLC)
  • Penetration testing based on OWASP Top 10 and SANS25.
  • Analyze the results of penetrations tests, design reviews, source code reviews and other security tests.
  • Decide on wat to remediate and wat to risk accept based on security requirements.
  • Highly analytical computer security analyst with success both defending and attacking large - scale enterprise networks.
  • Cloud security experience using AWS Landing Zone, VPC, WAF, S3, EC2, GuardDuty, Trusted Advisor, and Direct Connect.
  • Experience using a wide variety of security tools to include Kali-Linux, Metasploit, HP WebInspect, HP Fortify, Burp Suite Pro, Wireshark, L0phtcrack, Snort, Nmap, Nmap-NSE, Cain and Abel, Nitko, Dirbuster, IBM App Scan, OWASP ZAProxy, Nessus, Open Vas, W3AF, BeEF, Etthercap, Maltego, Wifi-Security, SOAP UI, Havij, Recon-ng, Aircrack-ng suite.
  • Involved in implementing and validating the security principals of minimum attack surface area, least privilege, secure defaults, avoiding security by obscurity, keep security simple, Fixing security issues correctly.
  • Strong noledge in Manual and Automated Security testing for Web Applications.
  • Working noledge of OWASP Top 10 and SANS Top 25 software guidelines, Federal Financial Institutions Examination Council's (FFIEC) regulations, including Payment Card Industry (PCI-DSS), HIPAA and Sarbanes-Oxley Section404 (SOX).
  • Analyze the results of penetrations tests, design reviews, source code reviews and other security tests. Decide on wat to remediate and wat to risk accept based on security requirements.
  • SOX Compliance Audit experience on controls like User access management, Change Management, Incident Management.
  • Perform all cloud engineering and DevSecOps services.
  • Good Experience in exploiting the recognized vulnerabilities.
  • Experience in Threat Modeling during Requirement gathering and Design phases.
  • Designed PKI and Encryption systems.
  • Worked with CASB such as NetSkope and Skyhigh.
  • Significant experience with AWS, GCP and Azure Security.
  • Experience with Security Risk Management with TCP-based networking.
  • Experience with TCP/IP, Firewalls, LAN/WAN.
  • Experience in implementing Security Incident and Event Management System (SIEM) using HP ArcSight, Splunk ES, Exabeam UBA, UEBA.
  • Quick Learner, Committed team player with interpersonal skills and enjoy challenging environment with scope to improve self and contribute to the cause of the organization.
  • Excellent problem-solving and leadership abilities.
  • Experience in Web UI Development implementing web development tools like HTML 4.0/5, XHTML, DHTML, CSS/CSS3, JavaScript, and jQuery, AJAX, JSON and XML.
  • Knowledgeable about Document Object Model (DOM) and DOM Functions along with experience in Object Oriented Programming Concepts, Object Oriented JavaScript and Implementation.

TECHNICAL SKILLS

Security Tools: HCL AppScan Enterprise (ASE), Standard & Source editions, Microfocus WebInspect, QualysGuard, RSAArcher, FireEye Retina, Onapsis, BurpSuite Pro, Acunetix, Fortify SCA, WAS, SQLMAP. CHEKMARX . SecureAssist, AppDetect, AppRador, Oracle Identity Manager, Oracle Access Manager, Hijack, Metasploit Pro, ZED attack proxy, Firemon, SQLMAP, Wireshark, WebScarab, Paros, BlueCoat Proxy, Nmap, BMC BladeLogic, Nessus, Rapid7 Nexpose, Tripwire, Symantec Vontu, DBProtect, ArcSight SIEM, e-DMZ Password Auto Repository (PAR), Varonis, Amazon Web Services (AWS) Cloud security.

Programming Languages: Java, C# .NET, C, C++

Identity & Data Protection Tools: SafeNet KeySecure, ProtectDB, ProtectFile, RSA Single Sign-On (SSO), Two-Factor (2F) autantication, SafeNet eToken 5110.

Scripting Languages: Python, Basic shell Scripting, Perl

Web Technologies: HTML 4.0/5, XHTML, DHTML, CSS2/CSS3, JAVASCRIPT, JQUERY, AJAX, JSON and XML

Web Services: Restful/SOAP, SOA, UDDI, WSDL

Operating System: Linux/Unix (Red Hat Enterprise Linux, Debian, Ubuntu, Fedora, Kali Linux), Windows.

Databases: MySQL, Oracle, Sybase, MongoDB

Network Enumeration: Maltego, Google Hacking, DNS, SMB, LDAP.

Port/Vulnerability Scanning: Nmap/Nmap Scripting Engine (NSE), Netcat, Nessus

Cloud Security: AWS Landing Zone, AWS Guard Duty, VPC, EC2 & S3 bucket security, MS Azure (Iaas, PaaS, SaaS)

Sniffing/Man-in-the-Middle: Wireshark, Ettercap, Cain

Web Application Vulnerability Scanning: , Nessus, OpenVas, Vega, Acunetix, HP Web inspect, IBMAppScan, Qualys guard.

Server/Client-Side Exploitation: Metasploit, Social Engineering Toolkit (SET).

Password Cracking: Hydra, Medusa, Rainbow Crack, 0phcrack, John the Ripper, Pyrit

Web Application: Manual SQL Injection, Manual Cross Site Scritping(XSS), Cross site request forgery(CSRF), SQLmap

Debuggers: Ollydbg, WinDBG.

Wireless: Aircrack-NG Suite and Kismet

PROFESSIONAL EXPERIENCE

Lead Security Engineer/Consultant

Confidential, O’Fallon, MO

Responsibilities:

  • Conducted Vulnerability Assessment (DAST and SAST) of Web and Mobile (iOS and Android Applications, including third party applications. The tools HCL AppScan, ZAProxy, BurpSuite Pro, SecureAssist, Microfocus Fortify, WebInspect, Checkmarx, Qradar.
  • Conducted IT security risk assessments including, threat analysis and threat modeling (STRIDE, DREAD).
  • Developed security controls for API proxies using Apigee and enabled security for backend web services (RESTful, SOAP, Microservices).
  • Implementation experience on patching Windows servers and workstations using Solarwinds Patch Manager Software.
  • Participated in the implementation of Splunk Phantom to automate security operations as part of Security Orchestration, Automation and Response (SOAR) project.
  • Integrated Prisma Cloud Compute Native Security Platform into CI/CD pipelines to continuously scan and monitor for security anomalies of host, container, and serverless functions.
  • Implemented AWS Landing Zone and applied security baselines for multi-account access across the enterprise in the cloud environment.
  • Participated in MS Azure migration and developed security controls for IaaS, PaaS, SaaS based application in the cloud.
  • Configured AWS VPC, Simple Storage Service (S3) to securely store the organization’s critical file systems. Implemented Access Control Lists (ACLs) and Bucket Policies for controlling access to the data.
  • Monitored AWS accounts and workloads using AWS GuardDuty to detect malicious activity and unauthorized behavior.
  • Performed security incident review to detect security anomalies using Splunk Enterprise Security. In addition, developed preventative controls and Incident Response (IR) rules for “cyber kill chain” attack models.
  • Conducted application penetration testing of 85+ business applications.
  • Implemented Secure Software Development Life Cycle (S-SDLC) processes; developed secure coding practices for web, mobile applications, including database and middleware systems.
  • Triaged security vulnerabilities to eliminate false positives and worked with the developers for remediation.
  • Work experience with HTTP, HTTPS, network layer protocols, WS-Federation and application layer protocols.
  • Performed threat hunting, Incident Response (IR) using Carbon Black Endpoint Detection and Response (EDR). Developed correlation rules and conducted incident analysis using Splunk ES and Exabeam UBA, UEBA.
  • Acquainted with various approaches to Grey & Black box security testing.
  • Hands-on with database security / Vulnerability scanner using Imperva Scuba.
  • Developed security policies and standards and made sure the business applications are in compliance with the standards.
  • Developed reports to document security breaches and the extent of the damage caused by the breaches and responsible for the tracking and assignment of tickets to Security Operations Team
  • Implemented OAuth2.0, SAML and Single Sign-on (SSO) for Azure AD& Mobile applications for corporate applications Working noledge of OSSTMM, OWASP Top 10 and SANS Top 25 software guidelines, Federal Financial Institutions Examination Council's (FFIEC) regulations, including Payment Card Industry (PCI-DSS), HIPAA and Sarbanes-Oxley Section404 (SOX).
  • Identifying the critical, High, Medium, Low vulnerabilities in the applications based on OWASP Top 10 and SANS 25 and prioritizing them based on the criticality.
  • Proficient in understanding application level vulnerabilities like XSS, SQL Injection, ClickJacking, CSRF, autantication bypass, cryptographic attacks, autantication flaws etc.
  • Conducted security assessment of PKI Enabled Applications.
  • Performing risk assessments throughout cloud DevSecOps / CICD pipelines including automated & manual source code reviews and OWASP manual penetration testing of mobile & web applications on AWS/Azure.
  • Penetration testing a variety of systems including mobile / web applications and services, operating systems and databases (hybrid, automated and manual penetration testing).
  • Penetration testing web applications, web services and mobile applications.
  • Performing Dynamic Application Security Testing (DAST) & Static Application Security Testing (SAST) as well as penetration testing (hybrid, automated and manual penetration testing).
  • Manual penetration testing using Burp Suite Pro, Metasploit, parameter tampering, cookie poisoning, and session hijacking, and crafting python scripts and manual exploits to commandeer websites.
  • Advanced manual penetration testing bypassing general OWASP testing techniques looking for business logic vulnerabilities, deep dive analysis of website architecture, malicious threat vectors, and Threat Modelling.
  • Penetration testing of Web Apps with SSO, OAuth, OpenID, JWT, LDAP, API, GraphQL, REST, AJAX, J2EE, PHP, C# .NET, Spring Framework, AWS, Azure
  • Red Team Leader. Lead penetration testing attacks on critical corporate infrastructure, cloud, and applications.
  • Lead Red Team efforts on Application security, penetration testing, and risk assessments of mobile platforms for J2ME, Android, iOS, and Blackberry.
  • Performed pen testing of both internal and external networks. The pen testing scope included O/S (Windows and Linux) and external facing web apps and database servers that store customer confidential information.
  • Designed and review the windows architecture and identify security gaps within the architecture environments.
  • Established best practice framework for the creation of an enterprise Email Protection Program that reduces security risk, measures TEMPeffectiveness and supports governance to maintain success.
  • Led development of professional service offering Email Security Practioner to reduce resource impact and streamline implementation for accounts.
  • Key contributing member of Trusted Email Engineering teams with responsibility for selecting, designing and implementing Proofpoint Email Protection gateway essential to maintain platform currency, align new security control capability and position Aetna to address emerging email driven security threats.
  • Investigated emails using various tools such as Email Protection Systems, Malware Sandboxes, and Anti-Virus Engines.
  • The technologies applied to GCRC applications utilized at the time met HIPAA security standards for subject (patient) confidentiality.
  • Design role includes experience with frameworks such as PCI, HIPPA, NIST, and other standard regulations that drive controls that create enterprise architecture, with secure installation or testing of applications, systems (virtual and physical), routers, firewalls, IPAM - IP/DNS, and switches for client development and to enhance security posture.
  • Implemented all components of AWS, Azure and GCP security standards.
  • Used Google Cloud Platform (GCP) Services like Compute Engine, Cloud Functions, Cloud DNS, Cloud Storage and Cloud Deployment Manager and SaaS, PaaS, and IaaS concepts of Cloud computing and Implementation using GCP.
  • Setup GCP Firewall rules to allow or deny traffic to and from the VM’s instances based on specified configuration, used GCP cloud CDN to deliver content from GCP cache, drastically improving user experience and latency.
  • Architected DevOps deployments in AWS, Microsoft Azure, and Google Cloud Platform, including deployment of platform offerings (Cloud Formation, Elastic Beanstalk) and third-party (Puppet, Chef, Terraform, Salt, Ansible) products
  • Assisted customers in the migration of Amazon Web Services deployments (IaaS/SaaS/PaaS) to Microsoft Azure and Google Cloud Platform.
  • Lead, designed, and implemented greenfield cloud deployments for customers in Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform, to include development of full-cloud/cloud-native infrastructure and platform solutions.
  • Implemented CASB solutions for DLP, IAM and VA for an agency.
  • For a large agency conducted a PCI, NIST and FISMA based security assessment. dis included developing an application security framework and a GRC framework
  • Implemented DLP solutions for WebSense, Symantec and RSA over cloud environments
  • Developed a DLP strategy for a large manufacturer.
  • For a large agency, architected and implemented PCI solutions for P2P encryption, tokenization and Network Enclaving/Zoning
  • Skilled using Burp Suite Pro, HP Web Inspect, IBM AppScan Standard, Source and Enterprise, NMAP,, Nessus, SQLMap, RSAArcher, Dirbuster, Qualysguard, FireEye Retina for web application penetration tests and infrastructure testing. Performing onsite & remote security consulting including penetration testing, application testing, web application security assessment, onsite internet security assessment, social engineering, wireless assessment, and IDS/IPS hardware deployment.
  • Capturing and analyzing network traffic at all layers of the OSI model using Wireshark. Performed malware reverse engineering using IDA Pro.
  • Monitor the Security of Critical System (e.g. e-mail servers, database servers, Web Servers, Application Servers, etc.).
  • Performed pen testing of both internal and external networks. The pen testing scope included O/S AIX, SQL, and Oracle Database.
  • As an experienced hands-on DevSecOps Engineer directly reporting into the CTO, me had been tasked with managing and refining Client Technology team and service offerings. Responsibilities included building and leading a team responsible for supporting and securing best in class SaaS platform (DecisionPoint).
  • Responsible for source code and binary repository management tools. Implemented their secure automated CI/CD pipeline in adherence to the latest DevSecOps initiatives.
  • As a Senior DevSecOps Engineer that works with cloud technologies to deploy and maintain applications in a secure production environment.
  • Senior a team of Cloud and DevSecOps engineers serving a large diverse team of multidisciplinary professionals defining and supporting the DevSecOps and CI/CD platforms across a portfolio of systems
  • Drive DevSecOps Adoption Strategy of the provided platform with your vision and industry experience
  • me has an excellent working noledge of DevSecOps engineering, tools & technologies, like Kubernetes, Jenkins, SonarQube, etc.
  • Design and implement AWS/Cloud based DevSecOps processes and tools like (Security Monkey, UptimeRobot etc)
  • Performed the configuration of security solutions like RSA two factor autantication, Single Sign on (SSO), Symantec DLP and log aggregation and analysis using Splunk Enterprise Security.
  • Change Management to highly sensitive Computer Security Controls to ensure appropriate system administrative actions, investigate and report on noted irregularities.
  • Conduct network Vulnerability Assessments using tools to evaluate attack vectors, Identify System Vulnerabilities and develop remediation plans including, security policies, standards and procedures.
  • Remains current on cyber security best practices, news, issues, vulnerabilities and threats
  • Supplying actionable recommendations to other teams within the Cyber Security Center, to bolster cyber security efforts.
  • My primary focus has always been as a Cyber Security engineer and using the other fields as a force multiplier for security in one way or another.
  • Adhering to Cybersecurity practices within all applications. Maintained key relationships across corporate verticals spanning the enterprise with an emphasis on Technology Management.
  • Experience in Cybersecurity in Penetration Testing, Intrusion Detection and Prevention, Vulnerability Management, Incident Management & Response. Cloud Security experience in AWS. Preferred DevOps/Development background.
  • Implement security and integrate risk management principals and cybersecurity compliance requirements into CBP’s SOC development and production workflows
  • Author of iRules for F5 WAF to automatically block the excessive bad web requests from cyber security attacks that causes web deny of services and generates thousands of F5 WAF alerts jamming Splunk SIEM cyber security incident response.
  • SOC on-call integration and automation with cyber security tools of F5 WAF, CloudFlare WAF, PaloAlto firewall, Splunk SIEM, DarkTrace, InsightUBA, Reliaquest, Carbon Black, ProofPoint, ESET, PRTG, VictorOps, and JIRA.
  • Conducted IT security risk assessments including, threat analysis and threat modeling (STRIDE, DREAD).
  • Developed security controls for API proxies using Apigee and enabled security for backend web services (RESTful, SOAP, and Microservices).
  • Risk Management Framework (RMF) Using NIST 800-37 as a guide, assessments and Continuous Monitoring: Performed RMF assessment included initiating meetings with various System Owners and Information System Security Officers (ISSO), providing guidance of evidence needed for security controls, and documenting findings of assessment.
  • Expertise in National Institute of Standards and Technology Special Publication (NIST SP) documentation: Performed assessments, POAM Remediation, and document creation using NIST SP 800-53 Rev.1 and NIST SP 800-53 rev.4.
  • Security Documentation: Perform updates to System Security Plans (SSP) Using NIST 800-18 as a guide to develop SSP, Risk Assessments, and Incident Response Plans, create Change Control procedures, and draft, review, update Plans of Action and Milestones (POAMs).

Sr. Information Security Engineer

Confidential, Durham, NC

Responsibilities:

  • Conducted Vulnerability Assessment for various applications.
  • Managed security assessments to ensure compliance to firm’s security standards (me.e., OWASP Top 10, SANS25). Specifically, security testing has been performed to identify XML External Entity (XXE), Cross-Site Scripting and SQL Injection related attacks within the code.
  • Work closely with product and platform teams to engineer and implement Cloud security controls with a focus on DevSecOps
  • Implemented Single Sign-On (SSO), MFA, and user provisioning for enterprise applications using Okta, SAML, OAuth2.0, OpenID Connect (OIDC) flows.
  • Enabled security controls for APIs to secure RESTful and SOAP based web services from various security attacks.
  • Conducted security assessment of Cryptography applications including the apps that use Hardware Security Model (HSM).
  • Strong understanding of IP networking concepts and TCP/IP protocols
  • me assisted in the integration of DevSecOps pipeline components to include, using a code repository, an artifact repository, security assessment platform, and an orchestrated integration and delivery platform to enable automated application building, testing, securing and deployment.
  • me was part of the team that design and integrate of capabilities to establish a DevSecOps pipeline, utilizing lab and cloud resources to design, build, test and evaluate functional components and technologies.
  • Working noledge with Windows Servers administration and Windows troubleshooting
  • Performed the penetration testing of mobile (Android and iOS) applications, specifically, APK reverse engineering, traffic analysis and manipulation, dynamic runtime analysis was performed.
  • Implemented HP ArcSight ESM including, correlation rules, data-monitors, reports, event annotation stages, case customization, active lists, and pattern discovery.
  • Performed pen testing of both internal and external networks. The pen testing scope included O/S (Windows and Linux) and external facing web apps and database servers that store customer confidential information.
  • Participated in Web Application Security Testing including the areas covering Mobile, Network, security, WIFI.
  • Conducted pen testing for the Web Services (SOA) used by various external vendors.
  • Skilled using Burp Suite, Checkmarx, HP Fortify, WebInspect, SecureAssist, WAS, NMAP, Havij, DirBuster for web application penetration tests.
  • Conduct penetration tests of enterprise information security systems, cloud platform infrastructure, and high risk applications.
  • Penetration Testing of web, infrastructure and mobile applications
  • Perform vulnerability assessment and Penetration Testing on Networks and Applications.
  • Strong experience of Web Application Vulnerability assessments, penetration testing. Ability to conduct penetration testing for well-non technologies and non security flaw concepts SQL injection, XML injection, XSS, CSRF, IDOR, Path Traversal, etc. Ability to exploit recognized vulnerabilities.
  • Experience in vulnerability assessment and penetration testing using various tools like Burp Suite, DirBuster, OWASP ZAP proxy, NMap, Nessus, HP Fortify, IBM App Scan enterprise, Kali Linux, Metasploit.
  • Provided guidance on data network system selection, remediation policies, and best practices for HIPPA, PCI, SOX and CDM compliance/deployment for the organization.
  • Experience and also has strong working noledge on various information security standards and compliances such HIPPA, HITRUST, PCI-DSS, FISMA, GLBA, SOC2, NIST and other GRC's. Additionally, passionate in Enterprise Data Classification, Identity and Access Control management (IAM) deployment solutions, IT Risk Management, Governance, Security Compliance Methodologies.
  • Create processes/procedures for environment compliance to PCI, SOX, and HIPPA & ISO27002.
  • Assist with SOX & HIPAA audits and compliancy issues. Also performed evaluations to ensure compliance with stated corporate security stance and goals.
  • Architect enterprise-wide wireless rollout using latest secure implementations.
  • Advise many internal divisions on security/firewall/network related scenarios/questions.
  • Generated and presented reports on Security Vulnerabilities to both internal and external customers.
  • Security assessment of online applications to identify the vulnerabilities in different categories like Input and data Validation, Autantication, Authorization, Auditing & logging.
  • Vulnerability Assessment of various web applications used in the organization using Burp Suite,and Web Scarab, HP Web Inspect.
  • Experience with Identity and Access Management (IAM) and development of user roles and policies for user access management.
  • Knowledge of SAN-20 and ISO 27001 Security controls and Mapping with NIST.
  • Monitor, analyze and respond to network incidents and events. Participate in disaster recovery implementation and testing under NIST framework, PCI standards.
  • Security auditing accountability for recording and reporting access in RACF.
  • Security assessment of online applications to identify the vulnerabilities in different categories like Input and data Validation, Autantication, Authorization, Auditing & logging.
  • Engineering Owner responsible for the firmwide Cyber Security Data Protection Standards, Procedures & Assurance Processes, and critical Cyber Security Data Protection applications.
  • Led and completed the uplift of Cyber Security Data Protection Standards & Procedures by consolidating more TEMPthan 30 standards and more TEMPthan 100 Control Procedures into 3 standards and about 30 Control Procedures.
  • Contributed and reviewed the critical Data Protection and Key Management related sections of the standards on Public Cloud Security Standards for firmwide adherence.
  • Coordinated and managed annually the review of Application Risk Control and Application Control.
  • Assessment questionnaire as applied to Data Protection Controls, as part of the Data Protection Standards and Control Assurance processes.
  • Led the deliverance of AO responsibilities for 3 of the critical Data Protection applications such as IronKey Enterprise Console, Symantec End Point Encryption, Symantec Data Insight applications. The responsibilities included ensuring that the Products are adhering to all the Control Compliance requirements expected of all the Cyber Security critical applications.
  • Working on specifications for implementing Data Protection Controls in the form of standardized modules and API’s for ease of integration with various applications across the firm theirby alleviating the risk of implementation errors and in simplifying the periodic compliance validation processes.
  • Analyzed correlation rules developed for Security Incident and Event Management (SIEM) system. Reviewed the solution implemented for “log forwarding” from various network devices to ArcSight central logging for alerting and security monitoring.
  • Training the development team on the most common vulnerabilities and common code review issues and explaining the remediation.
  • Follow up and ensure the closure of the raised vulnerabilities by revalidating and ensuring 100% Closure.
  • Update with the new hackings and latest vulnerabilities to ensure no such loopholes are present in the existing System

Sr. Security Engineer

Confidential, Las Vegas, NV

Responsibilities:

  • Extensive Interaction with Onsite Coordinator in understanding the business issues, requirements, doing exhaustive analysis and providing end-to-end solutions.
  • Conducting Web Application Vulnerability Assessment & Threat Modeling, Gap Analysis, secure code review on the applications.
  • Worked on Migration projects from IIS 6.0 to 7.5 and IIS 6.0 to IIS 8.5 and IIS 7.5 to IIS 8.5.
  • Working on setting up SSO policies on policy server side. Successfully implemented Site minder.
  • Hands on experience in configuration of Single Sign on (SSO), LTPA and User Registries.
  • Configured AWS Identity and Access Management (IAM) Groups and Users for improved login autantication
  • Solid noledge and experience in Identity and Access Management (IAM), Single Sign-on solution design and implementation.
  • Managed client relationship and project delivery for IAM migration project in Microsoft Azure cloud environment, working closely with the client business managers to plan, prioritize and execute software maintenance requests, leading a team of six developers and two test engineers.
  • Analyzed IAM migration impacts on availability, performance and future production support process.
  • Installed and cloned Azure Active Directory (AD) Office 365 Connector using Application Onboarding (AOB) method, configured schema, validation groovy scripts, developed migration documents.
  • Interacted with other component leads and architects for comprehensive design, Code and Unit test plans.
  • Managed client relationship and project delivery for IAM migration project in Microsoft Azure cloud environment, working closely with the client business managers to plan, prioritize and execute software maintenance requests, leading a team of six developers and two test engineers.
  • Analyzed IAM migration impacts on availability, performance and future production support process.
  • Data driven GRC, Privacy access security models to align with PCI-DSS with tokenization and NIST through standardized microservices architecture.
  • Azure AD - Implemented Azure AD using AD connects configured SSO and multifactor Autantication. Also configured SSO from Window 10 based computer which is joined to Azure AD. Implemented and managed AD synchronization.
  • Extensive experience in Windows AZURE(IaaS) migrating like creating AZURE VMs, storage accounts, VHDs, storage pools, migrating on premise servers to AZURE and creating availability sets in AZURE.
  • Conducted security assessments of firewalls, routers, VPNs, Switches, Bluecoat Proxy, IDS/IPS and verified its compliance to internal and external security standards.
  • Experience with ISO 27001/27002 Certification for ISMS, Sarbanes Oxley (SOX) Compliance
  • Doing multiple level of testing before production to ensure smooth deployment cycle.
  • Creation of Generic Scripts for testing and reusability.
  • Application Security Review of all the impacted and non-impacted issues.
  • Providing guidance to Development team for better understanding of Vulnerabilities.
  • Assisting customer in understanding risk and threat level associated with vulnerability so that customer may or may not accept risk with respect to business criticality
  • Identifying the critical, High, Medium, Low vulnerabilities in the applications based on OWASP Top 10 and SANS 25 and prioritizing them based on the criticality for remediation.
  • Assisting in review of solution architectures from security point of view which helps avoiding security related issues/threats at the early stage of project
  • Ensuring compliance with legal and regulatory requirements.

Software Developer (Java/J2EE)

Confidential

Responsibilities:

  • Designed and developed a suite of applications used by the internal security department, including BPlanner, OATS.
  • Design and implementation of SOAP, RESTful Web services.
  • Developed application presentation layer, which is based on Spring MVC framework involving JSP, Servlets and HTML, CSS
  • Developed dis web application to store all system information in a central location. dis was developed using Spring MVC, jQuery, JSP, Servlet, Oracle 10g, HTML and CSS
  • Developed Servlets and Utilized JQuery to create a fast and efficient chat server.
  • Implemented the Scrum Agile methodology for iterative development of the application.
  • Developed server side business components using Java Servlets, JSPs, and Enterprise Java Beans (EJBs)
  • Involved in system design, enterprise application development using object-oriented analysis in Java/JEE6.
  • Used Spring Framework for Dependency injection and integrated with the Hibernate framework for interacting with the Oracle database.
  • Automated code deployment to production environment by creating tasks using ANT, Maven deployment tools.
  • Developed stored procedures, views and triggers using Oracle PL/SQL.
  • Analyzed performance issues in the application, related system configuration and developed solutions for improvement.
  • Involved in WebLogic and Tomcat application server installation and configuration in production, development and QA environments.
  • Conducted training sessions to the rest of the development team on advanced technologies, code reviews and discussion sessions to ensure that coding standards are followed.

We'd love your feedback!