We provide IT Staff Augmentation Services!

Delete This

4.00/5 (Submit Your Rating)

SUMMARY OF QUALIFICATIONS

  • Around 7 years of experience in Information Technology with Implementation of IT Security, Identity and Access Management and Support, IT Security controls, Change Management, Business Analysis, Project Management and Technical Support.
  • Experience with Mainframe - RACF ACF2, AS400, IBM Z Series, UNIX, Windows, IMAC's, IAM tools ISAM, Novell IDM, TIM, CA IDM and Security Controls SOX, HIPAA, PCI .
  • Worked extensively with Mainframe Security Administration using RACF ACF2 application access provisioning Role Based Access Control RBAC .
  • Have complete understanding in ID GRC Governance, Risk and Compliance .
  • Experience in implementing RBAC, preparing scripts using JCL, Enhancement of Security by implementing authentication using RACF ACF2.
  • Expert in handing audits both internal and external .
  • User Admin. Manage User IDs in AS/400, Active directory, UNIX Linux, AIX , LDAP Windows 2008 servers, Citrix and other Web applications.
  • Have good understanding on LDAP lightweight directory protocol and worked on Add, modify, delete, bind unbinding of user ID's.
  • Worked extensively in Support projects by providing On Call support, Disaster Recovery and involvement in development of security using RACF and ACF2.
  • Worked with ZOS platform support and operations teams for any changes for system level change management .
  • As IAM administrator there is always a pre assessment post assessments done in access rules given to users , admin rules given to system admins and application accesses.
  • THREE years and FIVE months of experience working on Novell Identity Manager 4 and its modules Novell IRS - Identity Reporting System, Role Mapping .
  • THREE years and FIVE months of experience working on Novell Access Manager Add, modify and delete of users and user accesses.
  • Extensively worked with sever teams in developing scripts for automation of user admin activities on Windows and UNIX flavours.
  • Maintaining SOX IT Controls including Daily, Weekly, Monthly, Quarterly, Semi-Annual and Annual Audits.
  • Good understanding of VPN, LAN and network topologies TCP/IP.
  • Worked on PIP's process improvement plans with teams or in person.
  • Have excellent understanding and experience in preparing reports management and technical .
  • Actively worked with RSA Archer GRC in compliance management team to understanding the risks and maintaining the compliance across all the teams in the pool.
  • Expert in designing ID governance rules and policies.
  • Expert in designing, implementing, distributing and maintaining security audit controls using the reports obtained SAFR, MEF files, remediation reports and others .
  • Creating and maintaining documentation for in-scope ID Administration procedures.
  • THREE years EIGHT months of experience in Team management including shift rosters, leave management, providing 24 7 support Client engagement.
  • Provided resolutions for issues on call and emails.
  • Have worked in CRITSIT environment and worked with project leads to drive the incompliant rules to closure.
  • Outstanding communication and interpersonal skills, ability to learn quickly, good analytical reasoning and high compliance to new technologies and tools.
  • Perform IT Control Assessments/Reviews to ensure Compliance with established policies, standards, regulations etc.
  • Worked with Windows platform support team to implement SSO single sign-on basing SAML Security Assertion Markup Language using CA Site Minder.
  • Consulting, Advising and Participating in design of various IT controls processes to support compliance with policies, standards, regulatory requirements, etc.
  • Identify and evaluate business and technology risks, internal controls which mitigate risks and related opportunities for internal control improvement.
  • Over FIVE years of experience in analyzing the system level, application level and user level access entitlements and have quarterly review plans ERP - entitlement review process for remediation if any as part of IT security and compliance team.
  • Help establish Annual Audit Plan for core areas using risk assessment methodologies.
  • Coordinate with various departments to create remediation plans for defects found during audit.
  • Have done 2 transitions both Primary controls and secondary controls in user administration and have excellent skill in stream lining the process and designing work flow of an account process .
  • Implemented the SOX controls for the accounts.
  • As part of internal information compliance security team, worked on RSA Archer GRC for governing and maintaining compliance across the accounts and preparing the mitigation plan, remediating the false positives and maintaining compliance and proposing future plans to maintain compliance and adhere to security standards and controls.
  • Have great understanding in LAM - Logical Access Management activities.
  • Also worked on Disaster Recovery tasks in ACF2.
  • Worked on TAM Tivoli Access Manager and TIM Tivoli Identity Manager for provisioning.
  • TAM configuration on LDAP and wintel.
  • Build the security controls and maintain it throughout the SDLC System development life cycle .
  • Have experience working in agile environment.
  • Have end to end design, transition, operation and continuous improvement expertise in access management and privilege entitlements RBAC .
  • Actively worked with PMP's and PMO's in mitigating the PMLC during the transition .
  • Coordinate with auditors during internal external audits.
  • Highly skilled in performing business analyst related activities which include creating specification, requirements and generating test scripts as well as test data.
  • Responsible for maintaining implementation documentations as well as SOP documents and tracking changes in those.
  • Have understanding about the ERP Enterprise Resource Planning system on HRMS in SAP.
  • Worked with the quality assurance teams to understand and design the project and also study the growth of the account understanding SLA's and SLO's .
  • Very good understanding on KPI's Key performance Indicators and different metrics improvement methods.
  • Actively worked on presenting the project growth and statistics in MS share point and other VB's visual boards .
  • Have implemented password storage policies using ITIM vault across the accounts in the pool for high confidentiality and system security.
  • Expert in designing and preparing data models and flowcharts.
  • Responsible for system maintenance and adherence to compliance rules and also check the user level accesses via sail point.
  • Develop and deliver various trainings related to Security and Compliance.
  • Primary SPOC single point of contact for customers, auditors, and account management and delivery organizations.
  • Prepare and manage RCA root cause analysis for any audit findings.
  • Coach, mentor, motivate and supervise team members and influence them to take positive action and accountability for their assigned work.
  • Ability to multi-task and work under extreme pressure in a deadline driven environment even with limited direction from supervisors.

TECHNICAL SKILLS

  • Operating Systems: Windows 9X/NT/XP, Vista Windows 7, UNIX, Linux, OS400, IBM Z Series.
  • Languages: PL/SQL, C/C , Java, HTML.
  • Databases: MS Access, MS SQL, DB2.
  • Security Packages: Mainframes RACF ACF2.
  • Tools Utilities: CA Unicenter Global Service Desk, CA Service Center, CA Site Minder, CA Identity Manager, HP Service Desk HPSD , Request Management Workflow, Manage Now, sail point, Remedy, Maximo, clarity, lotus notes, outlook, OFC, Lotus Symphony, RSA- Archer GRC, LDAP, IMAC, Hitachi P-Sync, MS SharePoint, Novell Identity Manager 4, ISAM, ITIM.
  • Domain Knowledge: Technical Support, Information security, Industry/Risk Management/Audit and Compliance, Logical Access Management both primary secondary controls , Identity and Access management, Problem Change management and IT security controls reports SOX,PCI, HIPAA,SSAE16 SOC1 2 .

PROFESSIONAL EXPERIENCE

Confidential

Technical Responsibilities:

  • Creating and Managing PSV LID's, Super Tracs LID's, Started Tasks, Scope Lists, Session Managers, Nodes, CICS, Nonstandard LID's, Rules, Backup directory, UID strings, Batch jobs on Production and SQA Testing Servers.
  • Creation, Recovery, Modification and deletion of Rules/User ID's on Production and Test LPARs.
  • Remove a user, group, or security rule while ensuring the integrity of the Security Server's database.
  • Performing weekly Reorganization process on different LPARs.
  • Access provisions to special Privileges.
  • Updating users UID strings.
  • Implemented and performed security controls on privileged security controls.
  • Access Management to Datasets, Libraries and Application screens.
  • Provide access on Mainframes, ACF2 UNIX AIX, Linux HP as requested.
  • Modify and Revoke access on the above mentioned platforms as requested by the approver.
  • Create Macros scripts on Mainframes for bulk requests, setup RACF, CICS, TRACS, Datasets, Groups, Installation data, USR, Classes, Alias etc., and Modify access on them accordingly on Production and Testing servers.
  • Giving access to TRMS, IMS, CICS etc., Provisioning access to Resource rules, POPIMS, TRACAS, RASTAR etc.
  • Work on getting the requested reports audit and compliance reports .
  • Responsible for security risk assessments for information systems and associated business processes and recommending measures to mitigate risk.
  • Creating Session Managers, Adding IMS access, Session Manager and definitions.
  • Performing Quarterly SOX Sarbanes Oxley's Reporting for privileges, remediations and revalidations, QEV's, CITA Exceptions and LID review Audit by providing 2 way audit and providing Artifacts.
  • Perform the risk assessment and mitigating the identified risks using CVSS methodology.
  • Perform TLO's Temporary layoff's tasks and keep the system updated.
  • Performing Monthly Interactive LID Review Audit.
  • Performing IT Security Audit for System Adherence and Health Checking and provide data of IT Security Audits through Lotus Notes.

Management Responsibilities:

  • Single point of Contact for on call support and escalation management.
  • Attend daily status calls with the client and update the client with the status of the queues and ongoing issues.
  • Acted as liaison between the external auditors during the transition of the security controls.
  • Ensuring SLA's are met and no breaches.
  • Provisioning of Level 3 requests which include user administration, ACF2 Rule Writing, JCL scripting, rectifying Job failures, Transaction creation and access provisioning for users and groups to requested applications or rules.
  • Introduced new strategies to implement LAM Logical Access Management .
  • Provided support to a mission critical project MACH1 which is for migration of applications from ACF2 to SAP.
  • Involved in creating support models and knowledge transfer for new hires and estimates for new enhancements.
  • Making sure to keep the team abreast of the client's quality and security requirements.
  • Working on user requirements and new enhancements.
  • Preparing deployment documents for the deliveries.
  • Liaise between the PM project management team BA business analyst and auditors both internal and external during the transition and audits.
  • Educate account team and other delivery teams and ensure all policies are enforced.

Environment: Tools: Mainframes ACF2, IBM Lotus Notes. O/S: IBM Z Series, Windows 7 Linux.

Confidential

Responsibilities:

  • User Admin. Manage User IDs in AS/400, Active directory, Mainframe, UNIX, Linux, Windows 2008 servers, citrix and other Web applications Password resets/Create/Suspend/Delete and Modify users and Privileges .
  • Administration on TAM 6.0 Tivoli Access Manager for Web portal management for the vendors supporting ABC.
  • Integrating the HR portal with ISAM basing TAM and provisioning of ID's are done through it.
  • Updating the PeopleSoft ID's via TAM.
  • ITIM vault configuration on ITIM vault.
  • Work on Access entitlements on TAM.
  • Fixing Server Access, Folder access or Permission related issues and worked on more than 1500 servers.
  • Create user ids in LDAP and administration.
  • Administration of business critical issues using Problem tickets Tools Manage Now .
  • Handling CIRATS, Health Checks, Audits, PAR Privilege access revalidations and QEVs Quarterly Employee Verification , revalidation, security violation.
  • Perform compliance audit and help the organization meets its quality standards and performance goals.
  • Worked with Windows server team to integrate LDAP and AD.
  • Worked on SOX audits, CritSit's and SA D tasks over severs Windows and UNIX .
  • Worked in automating the manual processes under scope of user admin for bulk requests.
  • Participate in IT audits by providing information and documentation in a timely manner where required.
  • Worked on RSA Archer eGRC for gathering and presenting the compliance reports to the higher management.
  • Presenting the audit reports to in housing and external audit teams.
  • Open exposure documents CIRATS and manage to completion ensuring security compliance.

Environment: Tools: Windows, UNIX Linux, AIX , OS400, LDAP, and Mainframe - RACF, Secure Web, SAP console, clarity and sales force.

Confidential

Responsibilities:

  • Provisioning and maintaining access rights on Windows, UNIX, Linux, Solaris platforms, reviewing and verifying appropriate approvals are present for user requests.
  • Facilitating the creation and maintenance of workflows for in-scope account creation, modification and disable/deletions.
  • Worked on TIM Tivoli Identity Manager for user creation in the applications Wintel integration.
  • Manage provision and policies accessing AD .
  • Responding to requests from IBM Security for corrective actions related to Quarterly Employment Validation QEV , Continued Business Need CBN and privileged access.
  • Perform 2nd level support for id related problems.

Environment: Tools: Windows, UNIX Linux, AIX, HP Servers, and Solaris , SAP console and RACF - Mainframe.

Confidential

Responsibilities:

  • Performing L1 Tasks like resetting Users Password on Hitachi, Windows AD, along with troubleshooting the issues on call.
  • Resolving the issues in coordination with onsite people, root cause /problem analysis in case of severity 1 or Adhoc issues.
  • Creating tickets for the emails sent to the group mailboxes and also assigning the tickets to the respective teams.
  • Getting IMAC tickets assigned to the new heirs.

Environment: Tools: Windows, Street-smart, IMAC and Hitachi Web tool.

We'd love your feedback!