Security Architect
Falls Church, Va, Us
• Increased application security by implementing DevSecOps methods, including DAST/SAST analysis• Reduced the time and resources needed for repetitive tasks by automating security and network functions using Python, Ansible, and Terraform.• Closed security gaps by creating threat models and working cross-functionally to implement controls• Monitored security tools across the environment, conducting log review and analysis, and continuously tuning and enhancing security parameters.• Led incident response management, developing and enforcing strategies for incident communications, IR exercises, and drills.• Led collaboration with cross-functional teams and business units effectively to ensure alignment with security policies and procedures.• Improved cloud security by implementing AWS and Azure best-practices and leveraging security tools• Implemented and maintained enforceable Information Security policies aligned to industry best practices, NIST-CSF, and ISO 27001.• Leveraged Threat Vulnerability Management tools to conduct automated scheduled scans and reports, working with IT and Engineering on remediation actions.• Ensured full transparency and awareness by maintaining strict security baselines and change logs• Maintain and enhance GRC tools and processes within information security to enhance visibility and transparency.• Optimized firewall and IAM policies