Consultant Security Practice Resume
4.00/5 (Submit Your Rating)
Austin, TX
SUMMARY
- 11+ years’ experience in various aspects of Infrastructure management, majorly in teh field of Compliance, Information Security & Network security.
- 9+ years’ experience as a Security Consultant - Risk assessment, Security standards validation, Enterprise Security assessment, Network security DC Implementation - FW IPS, Datacenter Built for security services, Security operations, Compliance and service delivery. Understanding on designing principals.
- Well organized individual wif technical knowledge on implement standards, service transition, SOC mgmt., procedures, and processes aligning to service quality and needs.Roles performed representing security services & practice
- Network Security Technical Lead, Technical Project Management, Operational reviews & Security assessment as Information security officer, Migration & Security Transition Engineer role, DC Build implementation & Transformation, Onsite/Offshore service transitions, Security Manager (IT & Network security services).
- Control / Process reviews, Transformational strategies & service improvements plans.
TECHNICAL SKILLS
- Experienced at implementing DC deployment for shared distributed infrastructure as a security engineer involving Netscreen, CISCO ASA, IPS, checkpoint, Palo Alto, and CSM.
- Network security refresh: Replacement from checkpoint to Palo Alto firewalls / Hardware Upgrading of PaloAlto 2000 series to 3000 & 5000 series / Migration of VPN concentrator to Cisco ASA VPN / Netscreen built, implemented and support ISG - 2000 /NS -5200 / SSG Firewall.
- Implementation: Palo Alto Firewall, Cisco ASA (FW-Active/Passive,S2S VPN ), Juniper Net screen (Active/Passive) - ISG, SSG series of firewall (UTM & VSYS), Checkpoint VSX.(Active/Active through VSLS), ACS 5.1, 4.2, PKI - Windows CA, Juniper SA SSL VPN.
- Cisco IDS/IPS - 4270(IDS), IME, Palo Alto threat Module (IPS), Cisco ACS, CSM implementation Integration for Cisco Firewalls & IPS devices.
- VPN - Router & Firewall based IPSEC S2S VPN / Cisco – Client to site VPN / PaloAlto – Global protect.
- In-depth knowledge of TCP/IP, IPSEC, Cisco Client to Site, Cisco Site to Site VPN, NAT/PAT, AAA, PKI.
- Basic understanding of LAN Switching (L2 -L3) including VLANs, Private VLANs, Trunking, EtherChannel, VTP, and Spanning Tree.
- Worked on static Routing, EIGRP environment, basic understanding on OSPF, BGP used at security devices.
- Experience working wif enterprise class switches-router management (Cisco switch 6509, 4506, 3850 stacking switches, worked on Nexus 2K,5500,7K)
- Threat prevention through - PaloAlto thread modules – AV, URL, Spyware, Dos prevention, Zoning features, SEPM risk logs, VPN (Firewall+ IPS) logs, AD authentication logs, Vulnerability assessment reports.
- Security assessments & improvement addressing teh risks through Technical & administrative controls. Participated in SOX audits and designed controls to ensure compliance.
- Security Event Monitoring (SIEM): Event analysis for security incident handling & Data analytics. CINXI – Log storm, Netforensic (Netforensic Agent), Arcsight products for teh SIEM monitoring.
- Vulnerability assessment: McAfee Foundstone 7.5. Baseline & preproduction scans.
- Proof of concepts: Advance persistent threat product evaluation (APT): Wildfire, Fireeye, Cyphort Malware detection. PGP email encryption, S/MIME for secure mail.
- PKI: Microsoft Certificate enrolment for domain users for VPN authentication, enrolling non-domain users, Revocation through OCSP,CRL, Managed an environment wif NDES auto enrollment for wireless users /Mobile users authentication.
- BCM: BCP- Review on BIA, DRP, DRT.
- Data Leakage Prevention (DLP): Bit9, Websense Data Security.
- Endpoint Security: MBAM, Symantec AV, Cylance Next generation Security.
PROFESSIONAL EXPERIENCE
Confidential, Austin TX
Consultant Security Practice
Responsibilities:
- Currently handling teh role of IT Security Lead for Security domain for a global semiconductor customer in Austin, TX.
- Security assessments & improvement addressing teh risks through Technical & administrative controls.
- Audit & Compliance: compiling to SOX & ISO 27001standard for internal and external audits, BCP for security services.
- IT security services – MS Certificate authority, SEPM, Bit locker/MBAM, Bit9, SIEM, Wildfire (APT), IBM ISS & Palo Alto IPS, ISA.
- Security Incident handling improvements & enhancement.
- Network security – Pala Alto, ASA, RSA, ACS 5.1, CISCO VPN.
- Project handled: IPS migration IBM ISS to Palo Alto, CINIX log storm, Hardware upgrade Palo Alto migration, Migration of PKI from 2003 to 2012 CA.
- Recent major activities / issues: Risk assessment on DDOS threats / Vulnerability assessment reviews / Firewall performance issues /Virus out break handing (Virus: W32.Conflicker) / IPS Migration issues / SIEM alert fine tuning.
- Played teh role in data center design and build activity at Frankfurt / Manchester for security track handling teh implementation of Netscreen firewall wif VSYS/Threat filtering / Checkpoint VSX/Cisco IDS/ACS.
- Part of DC migration team for a US client at onshore (Dallas) – ACS 5.1, Cisco IPS 4270, Websense DLP Data Monitor.
- Onsite Transition resource for security tracks - Handled multiple onsite Knowledge transfer for Global (UK/US) customer to teh HCL.
Confidential
LAN/WAN Analyst
Responsibilities:
- Maintaining and administrating Accenture’s technical infrastructure services –Implementing & Handling in Firewall, VPN & switching and Routing operations.
- Handled Netscreen firewall upgrade and troubleshooting on teh performance, interoperability issues.
- Migration activities and Network restructuring activities in Manila.
- Validating network infrastructure devices for Security baselines, Resiliency test, evaluating Port- analysis on access request and vulnerability scans.
- Part of Change, problem and Incident Management team
- Involved in Backup continuity plan (BCP) and availability management activities & documentation for ISO certifications.
