Security Consultant Resume Profile
Summary of Experience:
- Information Security Consultant with 10 years of experience in implementing solutions in RSA eGRC Archer Framework including Vendor Management, Risk Management, Enterprise Management, Deals and Save Management, Policy Management for a large insurance company.
- Designed developed solutions to setup Vendor Management, Control Assessments process as per industry standards, Vendor Exit Strategies, Strategic Vendor Reporting, Vendor Risk Rating and Vendor Financial Viability Assessments for vendor governance team
- Designed implemented Deal and Pipeline management system for Sourcing and Procurement teams, this solution has 600 calculations for reporting. Reporting was based on business groups and regions Americas, EMEA, AsiaPac and Japan
- For CITI Bank implemented Third Party Governance, AML Workflow Application, and Privileged User Access Management Solution
- For Sony Electronics designed and built Vendor Management, Enterprise Risk Management and Enterprise Management Solutions on RSA Archer GRC Tool
- For a Bank of America designed and implemented Archer solutions, to capture Business Continuity Test Results and Third Party Vendor Survey Management in RSA Archer GRC Tool
- For Ameriprise Financials, performed Business Impact Analysis, Application Mapping, Gap Assessment, and provided DR recommendations and engaged with Technology Groups on Gap Closure by implementation of Disaster Recovery solutions.
- Performed Penetration Testing, White box Testing and Vulnerability Assessment with IBM AppScan, Cenzic and Fortify for Publishing House Telecom Company.
- Performed Compliance Internal Auditing to assess ISO 27001 PCI DSS Compliance for a Services organization
- Designed developed an in-house Application Security Tool in J2EE for Infosys Research Institute
- Network Security Scanning Vulnerability Assessment was performed using QualysGuard Appliance
- Worked as Internal Training Coordinator to present topics on Archer SmartSuite, Top Ten Application Security Vulnerabilities and BCP/DR solution approach for service offerings
Accomplishments:
- Successfully setup a Vendor Management System and built the vendor portals in different languages to support vendors from different companies.
- Successfully developed Archer GRC solution for our practice and trained entry level engineers on this Framework. Performed administration activities, designed implemented solutions in RSA Archer GRC Tool.
- Managing BCP/DR program from onshore 2 years to gather data implement Disaster Recovery solution for a financial organization
- Managing acting as a SME on a 10 member team from offshore for a Business Continuity Plan building project for a major US bank
- Building application security tool prototype similar to App Scan for internal training institute and building application security solution at our practice
Product Level Skills:
| Archer GRC | : | Archer 4.3.4, Archer 4.5, Archer 5.3, Archer 5.5 |
| BCP/DR Plan Build Management | : | Stroll System's Living Disaster Recovery Planning System |
| QualysGuard - Network Scanner | : | QualysGuard |
| Application Security Black Box Penetration Testing | : | IBM App Scan, Cenzic |
| Application Security White Box Testing | : | Fortify |
| Ariba Contracts Pro SAP | : | Ariba, SAP |
Project Experience
Confidential
Responsibilities
- As an architect assist in gathering requirements
- Design solutions integrated with enterprise solutions and clarify any limitations
- Define Archer standards and procedures of implementation
- Coordinate with business and technology teams to implement solutions
- Work with offshore resources for development and support
- Archer hardware administration and support issue resolution
- Provide data feed support for all solutions
Confidential
Project Description:
- Setup out of box Archer vendor management solution for EVRGP team and manage a team to gather requirements, design and implement them. Customize vendor risk management based on AIG's needs, like build Vendor Financial Viability solution, Contract Exit Strategy solution, Semi- annual strategic vendor assessments, Vendor Control Assessments, Sourcing On-boarding Risk Tool, and other solutions like Deal and Saves Management solution. Integrate Archer with Ariba, SAP and other AP systems.
- Design and Build Vendor portals and Supplier Enablement Form in multiple languages English, French, Greek, Spanish, Italian, Japanese, German
Responsibilities
- Assist in understanding and gathering requirements
- Design Implement Archer solutions
- Define Archer standards and procedures of implementation
- Coordinate with business and technology teams to implement solutions
- Work with offshore resources for development and support
- Archer hardware administration and support issue resolution
- Provide data feed support for Ariba, SAP and AP systems
- Manage a team of business analysts to gather and provide operational support to vendor management solution
- Document data dictionaries, functional requirements, implementation plan and other change related documents.
Confidential
Responsibilities:
- Gather business requirements convert them to Archer requirements
- Design Implement Archer solutions
- Coordinate with business offshore resources for development and support solutions
- Demonstrate solutions to business teams
- Manage a team of business analysts to gather and provide operational support to vendor management solution
Confidential
Responsibilities:
- GRC Process redesign in Archer framework solutions
- Build and Implement Archer applications, questionnaires
- Configure dashboard, reports and notifications
- Documentation of functional requirements, implementation plan and other change process documents.
Confidential
Responsibilities:
- Assisting in responding to RFI's and RFP's of Archer Framework implementation in different environments
- Training entry level and mid-level engineers
- Setup training schedule, course and perform assessments
- Setup of Archer sandbox and implementation of GRC out of box solutions with customizations
- Training on documentation for Archer projects
Confidential
Responsibilities:
- Gather requirements from vendor business governance team
- Design, build and implement vendor management, assessments
- Build reports and dashboards for contracts, relationship managers and governance team
- Setup data feeds from Dunn Bradstreet
Confidential
Responsibilities:
- Manage 40 member team to convert documents to LDRPS solution
- Prepare and manage project plan to migrate 11000 records to LDRPS application and build a BCP/DR call tree
- Communicate with business team to collect requirements and provide progress update
Confidential
Responsibilities:
- Identifying the security controls implemented in the AS-IS systems
- Implementation of the security control on various platforms
- Manage licenses for Pfizer organization
Confidential
Responsibilities:
- Defining DR processes based on Disaster Recovery Plan
- Requirement gathering validation
- Coordination with business teams, application technology owners and data center managers to implement a DR solution for tier-1 applications
- Manage implementation of the solution
- Disaster recovery plan testing or Implementation Acceptance Testing for tier-1 applications.
Confidential
Responsibilities:
- Identification of Vulnerabilities and implementation of SSL authentication and authorization for the Application.
- GAP Analysis for all the identified vulnerabilities in the application
- Security Recommendations for the vulnerabilities found in GAP analysis
Confidential
Responsibilities:
- Analyze the WOOSH application for vulnerabilities
- Create an impact analysis for implementation of the solutions
- Remediation for all the identified vulnerabilities were suggested
- Unit testing was done on all the remediation's suggested
- Used Oracle 9i, Perl, and C
Confidential
Responsibilities:
- Database tables and fields were evaluated as per the SOX, HIPPA and GLB Compliance Laws.
- Evaluation of SOX, HIPPA and GLB compliant Data Masking tools
Confidential
Responsibilities:
- Database Installation, configuration and connection setup
- Application design, coding, unit testing and integration testing.
- SQL Server , Java1.4 and Apache Tomcat Web Application Server
Confidential
Responsibilities:
- Impact Analysis of APD Decommissioning
- Analysis of requirements and recommendations on APD decommissioning.
- Defect Prevention Activities.
