Director Of Perimeter, Offensive And Application Security
Current• Handpicked by the CIO to enhance the company's security posture and ratings by identifying and mitigating enterprise vulnerabilities to cyber threats.• Established the Vulnerability Management, Pen Testing, Application Security, Perimeter Security, Offensive Security (war gaming), Threat Hunting, Red and Purple teams in the enterprise• Drove internal initiatives to promote a strong security culture across the enterprise. Organized lunch and learn events, coordinated phishing exercises, and security training and awareness for employees• Improved company's BitSight security score from 500 to 770 in 18 months• Certified in the Verizon Cyber Risk Certification program in 9 months• Led an effort to eliminate all active critical CVEs on externally facing systems in less than one year.• Responsible for Intrusion Prevention System (IPS), Intrusion Detection System (IDS), and on-premise and cloud firewall security• Defined and integrated security policies into existing SDLC lifecycle processes• Orchestrate regular external and internal adversary attack simulations. 5 successful exercises resulted in comprehensive lessons learned.• Lead collaborative exercises among red & blue teams by running tabletop exercises built off the MITRE ATT@CK framework. Lead purple team exercises using AttackIQ & SafeBreach.• Lead and implement deception deployment within the enterprise environment by setting up Honeypots• Initiated practice of reverse engineering malware to produce internal reports, which are presented to C-level executives.• Oversee the technical implementation of PCI-DSS compliance requirements• Foster a culture of "Trust, but Verify" by identifying, recording and validating vulnerabilities through risk assessments• Lead threat hunting & threat modelling activities regularly• Experienced in using NIST, ISO and SOC controls• Fostered a Zero Trust policy at the enterprise level using Zscaler technology (ZIA & ZPA)