It Security Resume Profile
2.00/5 (Submit Your Rating)
Professional Summary:
- Total of 6 years 2 months of experience in Information Technology with Implementation of IT Security, Identity and Access Management and Support, IT Security and SOX controls and Technical Support
- Over 6 years of experience with Mainframe RACF ACF2, AS400, IBM Z Series, Unix, Windows, IMAC's and Technical Support.
- Worked extensively with Mainframe Security Administration using RACF ACF2 application access provisioning Role Based Access Control RBAC
- Experience in implementing RBAC, preparing scripts using JCL, Enhancement of Security by implementing authentication using RACF ACF2.
- User Admin. Manage User IDs in AS/400, Active directory, Unix Linux, AIX , LDAP windows 2008 servers, Citrix and other web applications
- Have good understanding on LDAP light weight directory protocol and worked on Add, modify, delete, bind unbinding of user ID's
- Extensively worked with sever teams in developing scripts for automation of user admin activities on windows and Unix flavours.
- Worked with ZOS platform support and operations teams for any changes for system level change management
- Worked extensively in Support projects by providing On Call support, Disaster Recovery and involvement in development of security using RACF and ACF2
- Maintaining SOX Controls including Daily, Weekly, Monthly, Quarterly, Semi-Annual and Annual Audits.
- Good understanding of VPN, LAN and network topologies TCP/IP
- Worked on PIP's process improvement plans with teams or in person.
- Actively worked with RSA Archer GRC in compliance management team to understanding the risks and maintaining the compliance across all the teams in the pool.
- Expert in designing, implementing, distributing and maintaining security audit controls using the reports obtained SAFR, MEF files, remediation reports and others .
- Creating and maintaining documentation for in-scope ID Administration procedures
- 3 years 8 months of experience in Team management including shift rosters, leave management, providing 24 7 support Client engagement.
- Provided resolutions for issues on call and emails.
- Outstanding communication and interpersonal skills, ability to learn quickly, good analytical reasoning and high compliance to new technologies and tools.
- Perform IT Control Assessments/Reviews to ensure Compliance with established policies, standards, regulations etc.
- Worked with windows platform support team to implement SSO single sign-on basing SAML Security Assertion Markup Language using CA SiteMinder
- Consulting, Advising and Participating in design of various IT processes and controls to support compliance with policies, standards, regulatory requirements, etc.
- Identify and evaluate business and technology risks, internal controls which mitigate risks and related opportunities for internal control improvement.
- Help establish Annual Audit Plan for core areas using risk assessment methodologies.
- Coordinate with various departments to create remediation plans for defects found during audit.
- Build the security controls and maintain it throughout the SDLC Software development life cycle
- Actively worked with PMP's and PMO's in mitigating the PMLC during the transition
- Coordinate with auditors during internal external audits.
- Highly skilled in performing business analyst related activities which include creating specification, requirements and generating test scripts as well as test data
- Responsible for maintaining implementation documentations as well as SOP documents and tracking changes in those.
- Worked with the quality assurance teams to understand and design the project and also study the growth of the account understanding SLA's and SLO's
- Actively worked on presenting the project growth and statistics in MS share point and other VB's visual boards
- Responsible for system maintenance and adherence to compliance rules and also check the user level accesses via sail point.
- Develop and deliver various trainings related to Security and Compliance
- Primary spoc single point of contact for customers, auditors, and account management and delivery organizations.
- Prepare and manage RCA root cause analysis for any audit findings.
- Coach, mentor, motivate and supervise team members and influence them to take positive action and accountability for their assigned work
- Ability to multi-task and work under extreme pressure in a deadline driven environment
Technical Skills:
|
|
|
|
|
|
|
|
|
|
|
|
Confidential
Responsibilities
Technical Responsibilities:
- Creating and Managing PSV LID's, Super Tracs LID's, Started Tasks, Scope Lists, Session Managers, Nodes, CICS, Nonstandard LID's, Rules, Backup directory, UID strings, Batch jobs on Production and SQA Testing Servers
- Creation, Recovery, Modification and deletion of Rules/User ID's on Production and Test LPARs.
- Remove a user, group, or security rule while ensuring the integrity of the Security Server's database.
- Performing weekly Reorganization process on different LPARs.
- Access provisions to special Privileges.
- Updating users UID strings.
- Access Management to Datasets, Libraries and Application screens
- Provide access on Mainframes , ACF2 Unix AIX, Linux HP as requested
- Modify and Revoke access on the above mentioned platforms as requested by the approver
- Create Macros scripts on Mainframes for bulk requests, setup RACF, CICS, TRACS, Datasets, Groups, Installation data, USR, Classes, Alias etc., and Modify access on them accordingly on Production and Testing servers
- Giving access to TRMS, IMS, CICS etc., Provisioning access to Resource rules, POPIMS, TRACAS, RASTAR etc.,
- Work on getting the requested reports audit and compliance reports
- Creating Session Managers, Adding IMS access, Session Manager and definitions
- Performing Quaterly SOX Sarbanes Oxleys Reporting for privileges, remediations and revalidations, QEV's, CITA Exceptions and LID review Audit by providing 2 way audit and providing Artifacts
- Perform TLO's Temporary lay off's tasks and keep the system updated
- Performing Monthly Interactive LID Review Audit
- Performing IT Security Audit for System Adherence and Health Checking and provide data of IT Security Audits through Lotus Notes
Management Responsibilities:
- Transitioned the project from Caterpillar Inc. USA Belgium and established the project successfully in India. Transition was in an Onsite/Offshore model with a target time of 90 days. Lead the transition in parallel training a team of 8 members without service impact.
- Single point of Contact for on call support and escalation management.
- Attend daily status calls with the client and update the client with the status of the queues and ongoing issues.
- Ensuring SLA's are met and no breaches.
- Provisioning of Level 3 requests which include user administration, ACF2 Rule Writing, JCL scripting, rectifying Job failures, Transaction creation and access provisioning for users and groups to requested applications or rules.
- Introduced new strategies to implement LAM Logical Access Management .
- Provided support to a mission critical project MACH1 which is for migration of applications from ACF2 to SAP.
- Involved in creating support models and knowledge transfer for new hires and estimates for new enhancements.
- Making sure to keep the team abreast of the client's quality and security requirements.
- Working on user requirements and new enhancements.
- Preparing deployment documents for the deliveries.
- Understand IBM security documents and identify gaps in processes
- Educate account team and other delivery teams and ensure all policies are enforced
Confidential
Responsibilities:
- User Admin. Manage User IDs in AS/400, Active directory, Mainframe, Unix linux, windows 2008 servers, citrix and other web applications Password resets/Create/Suspend/Delete and Modify users and Privileges .
- Fixing Server Access, Folder access or Permission related issues and worked on more than 1500 servers.
- Create user id's in LDAP and administration.
- Administration of business critical issues using Problem tickets Tools Manage Now
- Handling CIRATS, Health Checks, Audits, PAR Privilege access revalidations and QEVs Quarterly Employee Verification ,revalidation, security violation.
- Perform compliance audit and help the organization meets its quality standards and performance goals
- Worked with windows server team to integrate LDAP and AD.
- Worked on SOX audits , CritSit's and SA D tasks over severs windows and Unix
- Worked in automating the manual processes under scope of user admin for bulk requests.
- Participate in IT audits by providing information and documentation in a timely manner where required
- Open exposure documents CIRATS and manage to completion ensuring security compliance
Confidential
Responsibilities:
- Provisioning and maintaining access rights on Windows, Unix, Linux, Solaris platforms, reviewing and verifying appropriate approvals are present for user requests
- Facilitating the creation and maintenance of workflows for in-scope account creation, modification and disable/deletions
- Responding to requests from IBM Security for corrective actions related to Quarterly Employment Validation QEV , Continued Business Need CBN and privileged access
- Perform 2nd level support for id related problems
Confidential
Responsibilities:
- Performing L1 Tasks like resetting Users Password on Hitachi, Windows AD, along with troubleshooting the issues on call.
- Resolving the issues in coordination with onsite people, root cause /problem analysis in case of severity 1 or Adhoc issues
- Creating tickets for the emails sent to the group mailboxes and also assigning the tickets to the respective teams
- Getting IMAC tickets assigned to the new heirs.
