Sr. Manager, Information Security
Box Hill, Victoria, Au
I was mentoring, leading, and enhancing teams of cyber security professionals working on VAPT, threat hunting and prevention, perimeter security, IDS/IPS, ISFW, threat modelling, endpoint protection while working with the Enterprise Risk and Security team on policy formulations and implementation, client audits, PCI-DSS, ISO27001:2013, SOC2 audits and compliance, DR, and BCP. • Implemented agent-based scan (Rapid7). Achieved 89% reduction in open vulnerabilities within 2 quarters, starting Q4-20 • Proposed, budgeted and set up a 24/7 Security Operations Centre. • Led the COVID-19 response on behalf of the entire organization. Created pandemic response playbook encompassing India, Europe and Australia. Achieved WFH readiness for 85% of accounts within first week of March, 2020 and 100% by 3rd week of March, 2020 • Successfully prevented 17 potential incidents by enhancing monitoring of infrastructure using Darktrace threat models, adding O365 DLP Policies, enhanced OS level hardening, and by upgrading McAfee Endpoint solution • Led successful virtual audit completions and certifications for the organization, including ISO 27001:2013, SOC2, PCI-DSS, and client audits. Proven improvements - • Weekly monitoring of firewall rules introduced as a process. Zero deviations in firewall rule configurations from what is approved by change manager achieved within 6 weeks of process initiation. • Revamped employee on-boarding and off-boarding process to align it with with ISO27001:2013 and SOC 1 Type 2 controls achieving 56% reduction in sample based observations • Observations provided ensured information technology team’s risk register was enhanced to current standards • Drafting, reviewing and enhancing policies and procedures for organizational InfoSec controls, BCPs, data centers; vendor/client MSA/SOW evaluations • Awarded the Best Business Enabler and Best Business Contributor annual awards