Karl M.

Karl M.

London, United Kingdom
Hire Karl M. Hire Karl M. Hire Karl M.

About Me

With over 15 years of experience in Information Technology, I have developed expertise in various areas including Cloud Engineering, Product Security and Compliance, Solution Architecture, Cybersecurity, System Automation, DevSecOps, Auditing and Compliance, Business Continuity, Cloud Management (AWS, Azure, Google), Database, Linux & VMware Admin. I'm also proud to have contributed to the second edition of 'CISA' published by Packt.

AI, ML & LLM

Secure Containers Containers Container Orchestration Blockchain & Cryptocurrency SAML

Backend

APIs API Gateways Rapid7 Solutions Go

Database

DevOps

Amazon Web Services (AWS) Kubernetes Azure Google Cloud Platform (GCP) Amazon S3 (AWS S3) Cloud Security Cloud AWS DevOps CI/CD Pipelines AWS Certified Solution Architect Cloud Computing AWS IAM Azure Key Vault Jenkins

QA & Testing

Fuzz Testing Penetration Testing Security Testing

Workflow

GitHub Actions Github

Other

DevSecOps Security Software Development HIPAA Compliance .NET Security Model Sharepoint QualysGuard CyberSecurity Data Centers Information Security Network Security Vulnerability Management CISSP Identity & Access Management (IAM) Security Authentication Vulnerability Identification IT Security IT Audits IT Systems Architecture Disaster Recovery Plans (DRP) Migration Security Architecture Software Development Lifecycle (SDLC) Middleware Architecture Compliance Monitoring ISO 27001 CyberArk Information Audits NIST Software Architecture Vulnerability Assessment Risk Management Threat Modeling Solution Architecture SecOps Application Security Network Protocols Networks Security Analysis Access Control OWASP SIEM SOC 2 Single Sign-on (SSO) Asset Management Endpoint Security Security Audits OAuth Security Management Security Engineering IT Governance Business Continuity Information Asset Protection Information Gathering Hacking Cryptography Information System Audits Information Security Management Systems (ISMS) PCI DSS PCI Compliance HITRUST Certification Online Banking Core Banking Systems Know Your Customer (KYC) Host-based Security Systems (HBSS) Data Center Migration IT Automation Web Security System Design Communication CISO Assets Coding Ethical Hacking Information Systems Acquisitions Development Implementation Operations IT Management Web Applications Wireless Networking Okta Security Assessment Risk GRC IDS/IPS Antivirus Software C#.NET OpenID Python Splunk SonarQube .NET Windows PowerShell

Work history

Cyberassuranze
Information Security Architect
2023 - Present (2 years)
Remote
Lloyds Banking Group
Information Security Architect
2023 - 2023
Remote
Genesys
Product Security and Compliance Manager
2021 - 2022 (1 year)
Letshego Microfinance Bank
Technical Consultant
2017 - 2021 (4 years)
Nedbank Group
Solution Architect
2015 - 2017 (2 years)
Bancabc
Consultant
2012 - 2015 (3 years)

Showcase

Privileged Access Management Product
  • Developer led the design and development of the Privileged Access Management (PAM) product catered to critical administrative users

  • The PAM solution features a robust password vault and sophisticated workflow user management capabilities

  • It integrates seamlessly with prominent platforms such as LDAP, AWS, Azure, and various network and database tools

AWS System Design
  • Strategically designed and migrated on-premises system to AWS validating system's functionality

  • Deployed the CIS benchmark standards enhancing the AWS monitoring services

  • Included services such as CloudTrail, CloudWatch, Security Hub, and the web application firewall (WAF)

DevSecOps
  • Executed the integration of DevSecOps using CD/CI Jenkins pipeline

  • Deployed CheckMarx, Black Duck, OWASP ZAP, Nessus, and PrismaCloud for implementing SAST, DAST, container scan, network scan, and vulnerability management within the Business As Usual framework

  • Worked closely with the development team to proactively address and resolve key vulnerabilities

Cloud Security
  • Spearheaded the creation of microservices policies, DevSecOps tooling standards, and security incident management, and successfully integrated GCP Security Command Center with Jira.

  • Implemented Lacework for threat detection and compliance monitoring, and deployed SonarQube for code quality assessment; also managed third-party library scans through Graye and implemented Reblaze's WAF technology.

  • Managed log data with DataDog for monitoring and incident response, and showcased proficiency in managing GRC and ISO27001 controls for regulatory compliance.

Ops Sec
  • Oversaw operational security for platforms including Datadog, GCP security command center, and SonarQube

  • Executed ISO 27001 implementation and proficiently managed risk assessment and mitigation

  • Contributed to diverse projects integrating DevSecOps tools and vulnerability in the CI/CD pipeline, conducting comprehensive code reviews using SonarQube and manual tests with Burp Suite

Risk-based Vulnerability Management
  • Automated integration of vulnerability sources into a central repository and implemented automation via the Jira ticket system for risk-based vulnerability management project

  • Collaborated with client risk management for establishing mapping, identified control weaknesses through this mapping and prioritized vulnerabilities based on risk assessment

  • Ensured compliance with company policies and worked with asset owners and cross-functional teams to remediate vulnerabilities

DevOps Pipeline Setup With GCP and GitHub
  • Established and managed a GitHub repository as a centralized location for project’s source code and configurations, also controlled developer access permissions.

  • Integrated a CI/CD pipeline using GitHub Actions, setting up distinct workflows for development, testing, and production while upholding code quality and reliability.

  • Utilized Google Cloud Platform services for project integration, using GCP Cloud Run for deployment and scaling of applications and GCP Cloud Build to automate processes, along with an engineered approval workflow for controlled code promotion.

Education

Education
B.Tech
Madras University
2000 - 2003 (3 years)