Lead Information Security & Cloud Compliance Resume
5.00/5 (Submit Your Rating)
Cumberland, RI
SUMMARY
- Around 10 years of work experience.
- Consistently recognized for leadership and high service levels impacting project successes; works independently with high standards of technical design and strategic approach.
- Information security analyst with diversified experience in telecom, banking, finance & health industries
TECHNICAL SKILLS
Devices: Routers, Switches, Firewalls, IDS/IPS, VPN
Audits: Technical, Process, ISO, Vendor & 3rd party
Compliance: ISO 27001:2013, ISO 31000, PCI DSS, NIST, SOX, HIPAA
Tools: Wireshark, Nessus, Qualys Guard, Kali Linux, Sys Internals, VMware, MBSA
Projects: Risk Register, DLP, MDM, SSO, SIEM, IPV6, RSA, Syslog, Config Backup
PROFESSIONAL EXPERIENCE
Confidential, Cumberland, RI
Lead Information Security & Cloud Compliance
Responsibilities:
- Part of internal audit team & Lead vulnerability mgmt team for entire organization.
- Report the IT security risks & threats to the management.
- Responsible for managing PII & PHI data adhering to HIPAA compliance.
- Act as liaison to all departments for closing risks on cloud and in - house.
- Evaluate & assess SSAE16 SOC2 reports based on CVS Care mark policies.
Confidential, Bellevue, WA
Senior Information Security Consultant
Responsibilities:
- Define a risk register for all the identified / unidentified risks across the organization based on industry standards.
- Due diligence & security assessment for AWS & Amazon EC2 cloud providers.
- Implemented SIEM and syslog to adhere to the compliance.
- PCI DSS 3.1 implementation and auditee for the external audit.
- Security reviews for all C, C++, Java etc. IoT applications.
- Security awareness programs for employees.
Confidential
Information Security Officer
Responsibilities:
- Re-define and maintain ISMS policies & SOPs for all departments.
- Implement projects DLP, MDM, VDI & SSO.
- Conduct BCP meetings with department personnel for BCP drills.
- Key role in upgrading to ISO 27001: 2013 certification.
Confidential
Security Specialist
Responsibilities:
- SPOC for device related issues and security incidents closure.
- Performed IT risk assessment for all departments of the bank.
- IPV6 migration for DC & DR internet gateways.
- Participate and co-ordinate with all departments during DR drill for all locations.
- Member of the audit team to ensure closure of external audit findings.
Confidential
Network Engineer
Responsibilities:
- Working hands-on experience on Cisco routers & switches, Cisco ASA, Checkpoint, Juniper and fortigate firewalls.
- Managing DATA CENTER network operations to ensure connectivity at all locations.
- Vulnerability assessment on critical data center servers (VA) using Nessus and nmap.
