Cloud Security Architect
2021 - 2022SSENSE- Delivered security architectures for cloud native and distributed systems. Ran applications on microservices and serverless based environments hosted on AWS Cloud.
- Used Jira as a project tracking tool. Used SonarQube, Security Hub, and Guardduty for several static application and security testing (SAST) and CSPM tools. Used AWS for security.
- Carried out the opportunity of building cloud security competency and practice with needed skills in the security domain.
- Delivered security standards and technical controls implementation for ongoing customer data protection initiatives. Assisted various teams in adapting them.
- Built a cloud security roadmap with goals matching cross-functional teams and organizational objectives. Continued to work on the ambitious goals of the cloud security team.
- Drafted security standards and controls. Worked with cross-functional teams to enforce them across cloud systems, applications, and data stores with a shared security responsibility model and "shift left" mindset.
- Executed threat modeling activities to identify the security. Generated security architectural requirements for software development and product teams for remediation.
- Proposed and enforced the implementation of security controls at every layer of architecture and applications. Set up a thorough defense strategy.
- Participated in compliance initiatives as needed to achieve and maintain continuous compliance. Protected the customer's sensitive data. Promoted strong identity and access (IAM) policies and practices.
- Worked closely with the data engineering teams. Built secure data applications and data pipelines. Adapted industry-standard data governance practices with the principle of least privilege, encryption, auditing, and monitoring controls in place.
Technologies: Cloud Security, Amazon Web Services (AWS), Security, Application Security, Microservices Architecture, Static Application Security Testing (SAST), Secure SDLC, GDPR, Web Security, APIs, Full-stack, Security Architecture, Dynamic Application Security Testing (DAST), Vulnerability Management, DevSecOps, SOC 2, Management, Big Data Architecture, Big Data, DevOps, CI/CD Pipelines, OWASP Top 10, Security Operations Centers (SOC), SIEM, Tenable, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset ManagementInformation Security/Cloud Security Operations (Principal)
2018 - 2021Ingram Micro- Performed architectural reviews of hybrid cloud infrastructure and applications. Validated architecture, design and data flow diagrams for the company’s cloud business unit.
- Used Jira, Azure, and AWS as native cloud security posture management tools. Utilized Azure Sentinel as a SIEM and SonarQube as an SAST.
- Led auditing, monitoring, and improving the security posture of cloud enterprise workloads. Developed CSPM and CWPP programs and worked with cross-functional teams to enforce them.
- Worked with different engineering leads and managers for adoption and improvements in matured DevSecOps processes. Built pipelines for security testing automation methodologies like SAST, dynamic application security testing (DAST), and SCA.
- Mentored juniors and first security-incident responders during proof-of-concept (PoC) activities, incident investigations, and escalations. Developed security metrics, reports, KRIs, and KPIs for management and executive teams as needed.
- Performed vendor risk assessments for the different CSPs and third-party application vendors. Maintained a risk register with a risk score. Maintained practices as a cloud security team Agile practitioner.
- Researched trends, best practices, and tools in the different domains of the security industry. Developed security solutions for technical and reference architectures.
- Aligned and translated business requirements into secure solutions. Reviewed technical architectures of applications and products to ensure they met modern security standards. Promoted zero-trust architectures.
- Researched security industry trends and best practices to share with the organization through presentations. Hosted security training and awareness programs.
- Collaborated with solution architects within the organization. Used Microsoft, AWS, and other multi-sided platforms (MSPs) and cloud vendors.
Technologies: Dynamic Application Security Testing (DAST), Security, Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), Application Security, Static Application Security Testing (SAST), Full-stack, Security Architecture, Vulnerability Management, ISO 27001, GDPR, DevSecOps, SOC 2, Cloud Security, Management, Microservices Architecture, Secure SDLC, Web Security, APIs, Big Data Architecture, Big Data, DevOps, CI/CD Pipelines, OWASP Top 10, Security Operations Centers (SOC), SIEM, Tenable, Qualys, Veracode, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset ManagementSenior Security Engineer
2018 - 2018Zapr Media Labs- Orchestrated the delivery of DevSecOps, big data apps, and cloud security aspects for the organization. Defined the organization’s IT security policies.
- Used Jira as a project tracking tool. Used AWS native security tools like Trusted Advisor, ConnectWise, SonarQube, Jenkins, and CI/CD pipelines.
- Evaluated the current security posture, cloud environment, and on-premise data center. Conducted immediate and quarterly audits. Published the recommended missing best practices and security controls.
- Organized and carried out vulnerability scans for web, mobile, APIs and other cloud hosted solutions.
- Managed validation, authentication, authorization methods, and data flow. Enforced best practices with encryption in place.
- Evaluated DevOps workflows, tools, methods, and components of CI/CD pipelines. Supervised them in adapting a shared security responsibility model.
- Facilitated recognizing, adopting, and integrating industry-leading security practices in the security engineering unit of the organization. Participated in the investigation and reporting of security incidents and events.
- Developed and maintained documentation and diagrams outlining data flows, endpoints, ports, protocols, and incident response plans.
- Deployed hardened base Amazon machine images (AMI). Hardened web server and application server configurations as per respective benchmarks.
Technologies: Security, Application Security, Amazon Web Services (AWS), Static Application Security Testing (SAST), Cloud Security, Full-stack, Big Data Architecture, Big Data, Security Architecture, Dynamic Application Security Testing (DAST), Vulnerability Management, DevSecOps, SOC 2, C, Management, Microservices Architecture, Secure SDLC, Web Security, APIs, DevOps, CI/CD Pipelines, OWASP Top 10, Security Operations Centers (SOC), Java, SIEM, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset ManagementSenior Software Engineer
2017 - 2018EPAM Systems- Consulted technical personnel. Managed client requirements on industry-best practices. Discussed, persuaded, and agreed on the most innovative approaches applicable in the customer landscape.
- Worked closely with the management and development organizational units. Secured enterprise-level software applications and solutions that met or exceeded client demands with an eye for the most efficient and cost-effective solutions.
- Supported the organization’s offshore unit. Improved the end-to-end stability and security posture of environments and tools.
- Led technology research, solution budgeting, feasibility, and evaluation. Spearheaded proof of concepts (PoC) to make imperative decisions. Trained the development teams on secure software development lifecycle (SDLC) practices.
- Contributed as part of an interview panel. Reviewed DevOps Profiles in the market for the requirements and initial screening. Mentored junior engineers on the company culture, solutions, and tools.
- Conducted internal audits. Led IT and cloud security policy reviews. Identified, fixed, and presented compliance related improvements to senior management.
Technologies: DevOps, DevSecOps, Secure SDLC, CI/CD Pipelines, Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Amazon Web Services (AWS), Azure, Cloud Security, Security, Security Architecture, Application Security, Vulnerability Management, ISO 27001, GDPR, SOC 2, C, Management, Microservices Architecture, Web Security, APIs, Full-stack, OWASP Top 10, Security Operations Centers (SOC), Java, SIEM, Tenable, Qualys, Veracode, Software Development Lifecycle (SDLC), Architecture, SecOps, Cybersecurity, IT Security, Asset ManagementSenior Software Engineer
2013 - 2017Progress- Led all DevOps Operations. Deployed, automated, maintained, and troubleshot. Tuned multi-tier and distributed cloud-based application components hosted on AWS.
- Troubleshot issues in real-time across the whole stack. Conducted audit trails and account access reviews. Worked on compliance assignments related to SOC 2.
- Facilitated and provided support (for internal and external parties). Ensured cyber security incident management and response for the alerts and events triggered by SIEM, and IDS/IPS solutions.
- Worked closely with the other teams to assess risk and provide recommendations for improving our security posture.
- Served as the point of contact and escalation for all cloud security operations center events for the offshore unit in Hyderabad.
- Assisted lower-level software engineers and new recruits to the team. Educated them about the security knowledge, tools, and processes.
- Kept up to date with knowledge of current standard system security practices.
Technologies: DevOps, DevSecOps, Cloud Security, Security Operations Centers (SOC), Security, Software Development Lifecycle (SDLC), Static Application Security Testing (SAST), Veracode, Qualys, Tenable, SIEM, Java, OWASP Top 10, CI/CD Pipelines, APIs, Web Security, Secure SDLC, Amazon Web Services (AWS), Management, SOC 2, Vulnerability Management, Dynamic Application Security Testing (DAST), Application Security, SecOps, Cybersecurity, IT Security, Asset Management