Sr. Security Engineer
•Security architecture planning and implementation.•Security threat response, hunting and discovery, investigation, analysis, isolation, and remediation.•SIEM: Hands-on Arcsight managing and Arcsight certified. Splunk Enterprise Security. Configuration, management and troubleshooting. Detect anomalous activity, automate log processing and monitoring, development of custom correlation rules and trigger. Clear false positive, whitelist/blacklist maintenance. Client agent installs. •Firewalls: Hands-on Check Point Firewall-1 and Cisco ASA, configuration, management and troubleshooting. Conduct firewall policy assessment, firewall rule sets consolidation, creation, modification and deletion. Incident Respond, alerts, outages, firewall logs, support case handling, escalation and documentation. •Web Application Firewall (WAF): Hands-on Imperva SecureSphere configuration, management and troubleshooting. Configure rule sets, custom alert, server groups and custom exceptions. •IPS/IDS: Hands-on McAfee Intrushield, TrendMicro Broadweb and IBM ISS RealSecure configuration, management and troubleshooting. Conduct IPS/IDS policy tuning, customise, pattern customise, clearly false positive, whitelist/blacklist maintenance.•Vulnerability scanners: Experienced in NESSUS and Dragon Soft. Vulnerability risks assessment. CVE & Exploit Research. Assurance of service delivery, reporting & remedies of site issues. •Other hands-on: Proxy (McAfee WebShield), Wireless monitor (ARUBA), Sniffer (NiKSUN, Sniffer pro, Wireshark), IP Mac binding, Load Balancer (F5 BIG-IP), SSL VPN (Juniper), Network efficiency analysis management (DENIKA), etc. Key Achievements•Build up CSIRT, Security Operations Centre (SOC) in a state-owned bank.•Clear false positive (false alarm) to reduce the huge availability alerts from a variety of event log sources less than 90%.•Found and remedy all high-risk vulnerabilities in one month.