With over 15 years of experience in Information Technology, I have developed expertise in various areas including Cloud Engineering, Product Security and Compliance, Solution Architecture, Cybersecurity, System Automation, DevSecOps, Auditing and Compliance, Business Continuity, Cloud Management (AWS, Azure, Google), Database, Linux & VMware Admin. I'm also proud to have contributed to the second edition of 'CISA' published by Packt.
DevSecOps
Security Software Development
HIPAA Compliance
.NET Security Model
Sharepoint
QualysGuard
CyberSecurity
Data Centers
Information Security
Network Security
Vulnerability Management
CISSP
Identity & Access Management (IAM)
Security
Authentication
Vulnerability Identification
IT Security
IT Audits
IT Systems Architecture
Disaster Recovery Plans (DRP)
Migration
Security Architecture
Software Development Lifecycle (SDLC)
Middleware
Architecture
Compliance
Monitoring
ISO 27001
CyberArk
Information Audits
NIST
Software Architecture
Vulnerability Assessment
Risk Management
Threat Modeling
Solution Architecture
SecOps
Application Security
Network Protocols
Networks
Security Analysis
Access Control
OWASP
SIEM
SOC 2
Single Sign-on (SSO)
Asset Management
Endpoint Security
Security Audits
OAuth
Security Management
Security Engineering
IT Governance
Business Continuity
Information Asset Protection
Information Gathering
Hacking
Cryptography
Information System Audits
Information Security Management Systems (ISMS)
PCI DSS
PCI Compliance
HITRUST Certification
Online Banking
Core Banking Systems
Know Your Customer (KYC)
Host-based Security Systems (HBSS)
Data Center Migration
IT Automation
Web Security
System Design
Communication
CISO
Assets
Coding
Ethical Hacking
Information Systems
Acquisitions
Development
Implementation
Operations
IT Management
Web Applications
Wireless Networking
Okta
Security Assessment
Risk
GRC
IDS/IPS
Antivirus Software
C#.NET
OpenID
Python
Splunk
SonarQube
.NET
Windows PowerShell
Executed the integration of DevSecOps using CD/CI Jenkins pipeline
Deployed CheckMarx, Black Duck, OWASP ZAP, Nessus, and PrismaCloud for implementing SAST, DAST, container scan, network scan, and vulnerability management within the Business As Usual framework
Worked closely with the development team to proactively address and resolve key vulnerabilities
Spearheaded the creation of microservices policies, DevSecOps tooling standards, and security incident management, and successfully integrated GCP Security Command Center with Jira.
Implemented Lacework for threat detection and compliance monitoring, and deployed SonarQube for code quality assessment; also managed third-party library scans through Graye and implemented Reblaze's WAF technology.
Managed log data with DataDog for monitoring and incident response, and showcased proficiency in managing GRC and ISO27001 controls for regulatory compliance.
Oversaw operational security for platforms including Datadog, GCP security command center, and SonarQube
Executed ISO 27001 implementation and proficiently managed risk assessment and mitigation
Contributed to diverse projects integrating DevSecOps tools and vulnerability in the CI/CD pipeline, conducting comprehensive code reviews using SonarQube and manual tests with Burp Suite
Automated integration of vulnerability sources into a central repository and implemented automation via the Jira ticket system for risk-based vulnerability management project
Collaborated with client risk management for establishing mapping, identified control weaknesses through this mapping and prioritized vulnerabilities based on risk assessment
Ensured compliance with company policies and worked with asset owners and cross-functional teams to remediate vulnerabilities
Established and managed a GitHub repository as a centralized location for project’s source code and configurations, also controlled developer access permissions.
Integrated a CI/CD pipeline using GitHub Actions, setting up distinct workflows for development, testing, and production while upholding code quality and reliability.
Utilized Google Cloud Platform services for project integration, using GCP Cloud Run for deployment and scaling of applications and GCP Cloud Build to automate processes, along with an engineered approval workflow for controlled code promotion.