Information Security Specialist Resume
5.00/5 (Submit Your Rating)
SUMMARY:
- Highly personable and seasoned Information Security & Governance Consultant with 6+ year’s intensive experience providing IT Governance, Compliance, Risk evaluation, and enforcement within diverse, fast paced environments.
- Demonstrated competence in pro - actively administering Regulatory Compliance, SLA Monitoring Audits, Operations Management Audit, Security and Compliance Audit and Operations and Management Audits.
- Possesses first-rate communication skills to collaborate on all business levels while effectively directing systems, processes, projects and operating procedures on-site and for remote locations.
- Proficient in implementing the IT Security Policy Framework, Planning and executing IT Security audits and reviews of IT processes, IT related projects, IT systems and IT service providers.
- Proactively identify gaps / conflicts / areas of improvements in existing processes and develop scalable solutions
- Hands on experience in SOX based IT internal Auditing.
- Strong analytical, problem solving and synthesis skills.
- Strong drive to take full responsibility, prioritize projects and deliver quality results on time.
PROFESSIONAL EXPERIENCE:
Confidential
Responsibilities:
- Established Security Risk Management program for various client ODC.
- Performed pen test for their various web applications.
- Implemented and managed Security Dashboard for Business Unit to impart security governance, Spot check procedure for verification and validation of security controls.
- Proposed secured solutions based on Risk Assessment for Work from Home, Wireless Security, DLP, Network Architecture, Hosting Applications, Data Privacy, Physical and Personnel Security
Confidential
Information Security Specialist
Responsibilities:
- Designed Information Security Management System framework and implemented security controls for a client of CTS, adhering to contractual (MSA), legal and regulatory security requirements
- Established Security Risk Management program for various client ODC’s at CTS. Performed multiple Security Risk Assessment based on FAIR methodology, highlighting open and residual risk to Client and Leadership team.
- Initiated PCI DSS Audit for a client, based on Risk Assessment and contractual requirement. Reviewed projects data flow across various applications/interfaces and defined the scope of PCI DSS . Instrumental in driving PCI DSS with external vendor
- Conducted scenario-based security awareness sessions based on Security Incidents. Involved in creating many Client specific security awareness program based on contractual (MSA) & regulatory requirements
Confidential
Responsibilities:
- Audited the overall Physical and IT infrastructure management processes as per ISO 27000 framework including Monitoring, Maintenance and Management of the entire Data Centre, along with providing Helpdesk services and provide recommendations to the State.
- Reviewed and analyzed the services provided through SDC and its delivery mechanisms to different line departments & post analysis of the same, would submit a report with recommendations to the Client. It would review the Change Management, communication plan, configuration management, availability management, service level management etc. to ensure proper processes are in place for SDC operation and maintenance.
Confidential
Security and compliance Audit
Responsibilities:
- Performed Application risk assessments for HR, Finance and People soft applications. Analysis & Identification of critical business processes containing sensitive information
- Reviewed the security measures followed by the Data Centre Operator to ensure that the application is free of vulnerabilities at the time of hosting.
- Proposed secured solutions based on Risk Assessment for Work from Home, Wireless Security, DLP, Network Architecture, Hosting Applications, Data Privacy, Physical and Personnel Security
- Conducted vulnerability assessment & penetration testing on the identified components and share the results with respective client.
- Prepared Guidelines and Procedures for conducting Internal Audits of ISMS as per the requirements of ISO 27001 and conduct internal audits for Security.
- Involved with installations and configurations: Alien Vault Server, VM ware, windows agents, and desktop agents
- Escalated Critical DLP incidents to the management, initiating the investigations as per requirements
Confidential
Security Analyst
Responsibilities:
- Conducted ISO 27001 Audits for Internal corporate functions and PCI-DSS & SSAE-16 Audits for customers
- Involved with Facility level Risk Assessments like conducting monthly spot checks across all locations
- Responsible for approving firewall requests with the support team based on the criticality
- Being part of Cognizant’s core technical team involved in various activities like Data Leakage Prevention (DLP), Vulnerability Assessments and Configuration Audits
- Front ended Disaster recovery test for DLP.
- Installed and configured the required policies/rules for DLP components across the locations
- Policy fine tuning, implementing blocking/fingerprinting/discovery activities for IT accounts
Confidential
Jr. Security Auditor
Responsibilities:
- Involved with installations and configurations: Alien Vault Server, VM ware, windows agents, desktop agents, etc.
- Managed AD and firewall logs for BFS accounts
- Handled SIEM tools including Splunk, Alient Vault
- Produced reports of security incidents handled and escalate any suspicious events/incidents to the client
- Task allocation to the team and updating shift schedule and shift handover documents in regular interval of time
- Regular interaction with the vendor for new updates/changes as per requirement
Assistant Supervisor
Responsibilities:
- Supervised the production and management tasks.
- Task allocation to the team and updating shift schedule and shift handover documents in regular interval of time
- Regular interaction with the vendor for new updates/changes as per requirement
Confidential
Responsibilities:
- Provided reviewers with written, explicit instructions on the journal’s expectations for the scope, content, quality, and timeliness of their reviews to promote thoughtful, fair, constructive, and informative critique of the submitted work.
- Ensured that all involved in the publication process understand that it is inappropriate to manipulate citations by, for example, demanding that authors cite papers in the journal.
- Disclosed sources (e.g., authorship, journal ownership, and funding)
