Senior Security Consultant
Current•Possessing extensive knowledge and experience in Identity and Access Management (IAM).•Designed and executed Client compliance pattern analysis using the Secure Software Assurance Maturity Model, facilitating seamless integration of new products and ensuring adherence to security standards.•Proficient in adversary tools, techniques, and procedures, enabling proactive threat mitigation strategies.•Responsible for conducting detailed root cause analysis reports to inform decision-making processes.•Served as an ISO27001 Lead Implementer, developing policies, procedures, and guidelines aligned with framework standards.•Demonstrated expertise in offensive security, vulnerability scanning, penetration testing, and Data Loss Prevention (DLP) tools.•Utilized vulnerability management tools such as Qualys, implemented system hardening techniques, and applied patches based on vulnerability scores.•Collaborated with key stakeholders to monitor and enhance cyber security improvement plans.•Experienced with SIEM platforms including Sentinel and Rapid7 for real-time security alert monitoring.•Conducted Vulnerability assessments, including SAST (SonarQube) and DAST (WebInspect), and penetration testing across various business units.•Developed internal control systems and audit logs to maintain information access levels and security clearances.•Established effective security governance principles, standards, and procedures.•Conducted IT control audits including PCI compliance, ISO27002 (ISMS), and infrastructure/web application audits.•Identified and addressed operational gaps in investigations, fine-tuning use cases, thresholds, and tools.•Demonstrated a proactive and systematic approach to problem-solving.•Created policies, standards, and security frameworks including NIST and CIS, with expertise in formal documentation.•Investigated phishing, spam, and spoofed emails using Proofpoint email gateway, implementing filtering rules.