Application Security Developer
Ike is a senior cloud security engineer with 12 years of experience and a solid knowledge of the National Institute of Standards and Technology (NIST) and International Organization for Standardization (ISO) publications, cybersecurity, cloud, and DevSecOps tools. Deployed multiple security tools to monitor and mitigate attacks on the infrastructure. Strong knowledge of infrastructure as code, managing a CI/CD pipeline and protecting applications, websites, cloud networks, and infrastructure.
ExperienceWindows - 10 yearsApplication Security - 10 yearsLinux - 10 yearsPython - 8 yearsCloud Security - 8 yearsAzure - 4 yearsDevSecOps - 2 years
Windows, Linux, Amazon Web Services (AWS), Azure, Jenkins, Application Security, Cloud Infrastructure, Cloud Security, Secure Containers, DevSecOps, Documentation, Okta, Endpoint Security, FedRAMP
The most amazing...
...DevSecOps project I've worked on is the integration of security into the CI/CD process and building the entire process within the AWS Cloud.
Security Architect for a multinational services company
Ricoh USA, Inc
- Design secured infrastructure with PCI and HITRUST certified.
- Defined security controls for PCI / HITRUST certified system and mapped those control matrix to security tools deployed within Ricoh AWS infrastructure.
- Provided AWS cloud cost estimation for cloud application migration and infrastructure deployment in AWS from On-Perm.
- Disaster Recovery and High Resiliency design for Ricoh infrastructure in AWS.
Cloud Security Engineer
Hospitality Digital GmbH - Main Hospitality Digital GmbH
- Performed a security gap analysis for the CI/CD process and procedure.
- Reviewed Kubernetes container security scanning, performing DAST, SAST, API security, and SCA.
- Created a playbook to support incident response and requirement definition for SIEM deployment.
- Created a playbook and requirement definition for an IDS deployment and GCP Security Center.
- Did the PCI and HITRUST compliance audit and control implementation.
Security Operations Engineer (Hourly/PT/FT)
Anjuna - Main
- Deployed and managed Okta, an Identity management service for clients which provided a trusted platform to secure identity with SSO, multi-factor authentication, lifecycle management, and Identity governance.
- Configured SSO on applications using Okta identity management.
- Reviewed security gaps with client infrastructure and provided a guideline for compliance.
Security Engineer | Analyst
ASU Pocket - Main
- Reviewed the architecture of applications/systems deployed within the client infrastructure for security flaws.
- Managed the proof of concept for multiple system engineering deployment efforts with the university infrastructure.
- Was the subject matter expert on incident response issues affecting the university infrastructure.
Senior Cloud Security DevOps
Digital Swiss Gold
- Migrated applications and created mobile apps in Azure.
- Deployed a web application firewall (WAF), Microsoft Defender for Identity, Sentinel, Microsoft Azure Security Center, a virtual private cloud (VPC), security groups, and subscriptions.
- Reviewed Federal Information Security Management Act (FISMA) compliance requirements—NIST SP 800-53 and PCI. Ran security scans to determine the security vulnerabilities in the network.
Senior Cloud Security Engineer
- Reviewed security concepts and the architecture of applications and systems deployed with the infrastructure.
- Developed and reviewed functional requirements with end-users to determine if the systems met defined standards (NIST, SOX, and ISO 27001) and proposed enhancements.
- Supported evidence collection regarding various SEC compliance frameworks, such as NIST and ISO 27001.
- Updated changes within Firewall (Palo Alto and Juniper), WAF, and the IPS system (Firepower).
- Monitored the daily performance of networking systems, servers, and cloud application infrastructure with SolarWinds and Nagios.
- Implemented and configured DevSecOps tools, such as Git, GitHub, and Jenkins. Used a Python script to automate the infrastructure resource and monitoring and serverless and container infrastructure deployment with Python.
- Managed security alerts and reports from Prisma, AWS Cloud, Azure Security Center CloudWatch, and CloudTrail. Used AWS GuardDuty, Amazon Inspector, Amazon Macie, AWS Config, and Aqua Security (container security).
Senior Cloud Security DevOps
OneZero Solutions, LLC
- Implemented security in all phases of the CI/CD pipeline for secure application development within the cloud.
- Designed and architected the AWS network using VPC, subnets, route tables, and security groups.
- Ensured code development and applications adhered to security compliance frameworks, including NIST, SOX, PCI-DSS, and ISO 27001.
- Tested services and architecture required to build secure cloud computing platforms, especially using encryption for data at rest and in transit.
- Monitored the networking system, servers, and cloud application infrastructure with tools like Datadog and SonarQube.
- Integrated Checkmarx and Fortify (static and dynamic analysis) in the SDLC process. Reviewed code and application for possible OWASP vulnerability (XSS and injection), CVSS, and CWE.
- Used Python scripts to automate the infrastructure resource and monitor, and handled serverless and container infrastructure deployment with Python.
Senior Security Engineer
- Deployed multiple threat management, security event and correlation monitoring, and IDS and NAC devices for a client.
- Deployed applications within AWS Cloud, including AWS CloudTrail, AWS Firewall Manager, and Amazon GuardDuty.
- Managed the application scanning and vulnerability management for the entire enterprise.
- Managed the monitoring of the networking system, servers, and cloud application infrastructure.
- Managed the Crowdstrike Endpoint Protection Platform for protecting Cloud workload, data, and endpoints, providing next-generation antivirus, endpoint detection and response (EDR), and a 24/7 threat hunting service.
Senior Security Ops Engineer
- Provided technical assistance for the security threat management with infrastructure.
- Performed the administration and management of complex application security tools, including Sourcefire, FireEye, Splunk, NetWitness, Nessus, Palo Alto, ForeScout, RSA Security Analytics, and malware and APT analysis tools.
- Installed and configured operating systems to meet hardening requirements and standards, such as ISO 20071, NIST, CIS, and HIPAA.
- Configured and updated changes within the firewall.
Information Security Consultant
- Managed security risk assessment audit for multiple clients' IT infrastructure (PaaS and AWS managed services). Managed development, design, and implementation of a large enterprise security architectural detailed design.
- Deployed multiple threat management, security event and correlation monitoring, IDS, and WAF devices and application tools.
- Managed enterprise-level configuration management and vulnerability assessment.
- Managed the evidence collection with regards to various security compliance frameworks, including NIST, PCI-DS, and ISO 27001.
- Provided support on ongoing compliance activities and monitored different regulations and GRC standards like SOX, HIPAA, PCI, FedRAMP, and ISO.
- Designed and implemented complex enterprise anti-virus and malware architecture, detailed design, security information, and event management.
Security Operations Engineer
State of Maryland
- Performed application and code scanning to identify vulnerabilities.
- Conducted threat management procedures, vulnerability scans, and penetration testing to identify system vulnerabilities.
- Managed security operations, reviewing and analyzing malicious traffic.
- Reviewed and tracked security patch levels of the servers, workstations, and network devices.
Security Automation in CI/CD
Security Architect on a Platform as a Service (PaaS) Project
Cloud Security Engineer
Application migration to Azure Cloud.
Researched vulnerabilities discussed on the system and pushed out patches from Automox.
Provided the documentation of vulnerability CVEs and the level of effort to remediate affected devices.
Nessus, Jenkins, Git, Splunk, Prisma, GitLab, McAfee ePolicy Orchestrator (ePO), Source Code Control System (SCCS), SonarQube, Elastic, Kibana, Amazon CloudFront CDN, Azure Application Gateway, Terraform, Azure Kubernetes Service (AKS), Google Kubernetes Engine (GKE)
Windows, Linux, Azure, Amazon Web Services (AWS), Ubuntu, Kubernetes, Google Cloud Platform (GCP), Docker
Cybersecurity, IT Security, Security
Application Security, Scanning, Vulnerability Management, Vulnerability Assessment, NIST, Documentation, System Administration, IT Networking, Cloud Infrastructure, Cloud Security, Secure Containers, Firewalls, Intrusion Prevention Systems (IPS), AWS Certified Solution Architect, Network Access Control, SIEM, ISO 27001, Threat Analytics, Threat Intelligence, Palo Alto Networks, ISO 9001, SOX Compliance, PCI, Web Application Firewall (WAF), Platform as a Service (PaaS), IaaS, Okta, Endpoint Security, FedRAMP, Data Loss Prevention (DLP), Server Security, SecOps, Hacking, Certified Ethical Hacker (CEH), Content Delivery Networks (CDN), Azure VDI, Web Applications, Infrastructure as Code (IaC), Antivirus Software, Identity & Access Management (IAM), Single Sign-on (SSO), Authentication, Identity, SAML-auth, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), APIs, Open Source, Incident Response, Containerization, CI/CD Pipelines, Cloud, Vulnerability Identification, PCI DSS, HITRUST Certification, Incident Management, PCI Compliance, Security Architecture
DevSecOps, Automation, HIPAA Compliance, Penetration Testing, DDoS, DevOps
Azure Cloud Services
Master's Degree in Cybersecurity
University Of Maryland - Adelphi, Maryland
AZ-900 Microsoft Azure Fundamentals
AWS Certified Security
Amazon Web Services
AWS Certified Solutions Architect Professional
AWS Certified Solutions Architect Associate
Certified Ethical Hacker (CEH)
Splunk Certified Power User