Senior Consultant
CurrentResposibities :Having experience in the following areas of Information Security Audit and Risk Management, Third party audits with internal and external customer’s viz., Banking, Insurance, Transport and Product Clients: • Perform Information Risk Assessments and Vulnerability Assessments• Security Governance and Compliance• Security testing and pen test for all the web applications which are hosted on UAT, • Ensure compliance for the security policies under the frame works of PCI DSS and ISO• Exposure to security methodologies • Performing Internal Technical Audits and Assisting ISO 27001 Audits and Management• Documentation of Security Policies and Procedures • Monitor Network monitoring tools, identify and report on malicious/suspicious events which are generated from firewall , IDS/IPS• Define, Design and implement the security processes and requirements• Operating System and Application Hardening• Cyber Security monitoring• Development and implement proper controls to mitigate the gaps and provide for approver sign off • Patch Management• Alerts management which are generated from Firewall ,IDS/IPS • Exposure in Change management, User Account Management, Incident Management. • Generate weekly and monthly reports and provide same with clients• Publish K-shop on companies internal portal to educate employees as well as security team on information security policies, laws and regulations• Published Case study and Internal Tutorial on SAS 70, Cloud security in PCI DSS , Cyber law in Indian economy• Check RFP’s (Request for Proposals) from security & compliance perspective & Provided inputs for RFP preparation • Perform gap assessment and maintain compliance level• Event analysis of all the critical servers, applications, network devices and Security Infrastructure• Exposer in Security and Antivirus Monitoring • Exposer in Technical Compliance Review