Cloud Security Architect
2020 - 2021Citrix- Strengthened the company's security posture by collaborating with the red and blue product security teams to reduce the attack surface.
- Collaborated with the cloud operations team to harden the infrastructure.
- Worked with the engineering team to bake security into the product design.
- Assisted customers in migrating from on-premise to cloud infrastructure and alleviated their concerns about data location, data access, and security threats.
Technologies: SOC 2, NIST, GDPR, ISO 27001, ISO 27002, Databases, XenApp, Citrix XenApp, Azure, Azure Cosmos DB, AWS, OWASP Top 10, Amazon Web Services (AWS), Application Security, Web Applications, Development, Software Development Lifecycle (SDLC)Head of Cloud Security
2018 - 2020Apptio- Migrated infrastructure from a private to a public cloud.
- Designed security with in-depth defense concepts, multiple tiers from IPS, and a web gateway, application server, and database server.
- Conceptualized and drove the upgrade from Alert Logic IDS to Palo Alto IPS.
Technologies: Security Architecture, Oracle, Java, Hibernate, JavaScript, Puppet, Shell, Ansible, Python, MySQL, AWS, Palo Alto Networks, Azure, Intrusion Prevention Systems (IPS), Firewalls, Kubernetes, Amazon EKS, AWS ECS, Amazon Web Services (AWS), Linux, SIEM, Site Reliability Engineering (SRE), Software Development Lifecycle (SDLC), Application Security, Web Applications, Cloud Security, LeadershipHead of Security Engineering
2016 - 2018Digital Fuel- Improved security by incorporating OWASP principles and resolved gaps found in SAST and DAST analysis tools.
- Reduced cloud infrastructure costs by 78% while migrating from a fixed asset plan to a flexible asset plan.
- Cordoned off the infrastructure with Cisco ASA firewalls.
- Increased resiliency by successfully testing disaster recovery at a geographically distant data center.
Technologies: Java, JavaScript, Oracle, Hibernate, AWS, Amazon EC2, AWS RDS, AWS CloudWatch, AWS S3, AWS ALB, Web Application Firewall (WAF), SQL Injection Protection, Malware Removal, DDoS, IDS/IPS, ASA Firewalls, Cisco, Intrusion Detection Systems (IDS), Identity & Access Management (IAM), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Penetration Testing, Threat Modeling, OWASP, Nimble, Software Development Lifecycle (SDLC), Web Applications, LeadershipSecurity Manager
2006 - 2016VMware- Led the vRealize Enterprise product to increase customer satisfaction and integrated it with the vRealize Cloud product for seamless public and private cloud computing.
- Managed development teams and mentored offshore teams in Armenia, Bulgaria, and India.
- Reduced costs by scaling CapacityIQ in PostgreSQL to handle 8,000 objects per VM, scaled up the Capacity Planner infrastructure 40x (from 100 to 4,000 customers), and improved performance with fine-grained transactions in vCenter products.
- Conceptualized version 1.0 of vRealize Cloud from scratch. It heralded a new era of cost visibility in cloud computing with the fastest time to value—from installation to insights in less than one hour.
- Drove the release of vCenter Operations, the management business unit's flagship product.
- Integrated the in-house CapacityIQ product with the acquired Alive product for a seamless release of vCenter Operations Manager.
Technologies: VMware, VMware vCenter, VMware vCloud, VMware ESXi, Oracle, SQL, Data Modeling, Erwin, Visio, PostgreSQL, HP Fortify, Static Application Security Testing (SAST)Lead Architect
2003 - 2006McAfee- Played a pivotal role in scaling up the consumer database by 200%, from less than five million reads per second to 15 million reads per second.
- Redesigned the auto-renewal process to run 10x times faster, thus generating more revenue than the entire consumer website.
- Coordinated design and development projects with offshore teams in Bangalore, India.
- Designed new payment methods, such as bank transfers and Switch/Solo cards for the consumer database.
- Coded an alerts module to monitor sales volume and transactions by product and region.
- Tuned the stored procedures to increase concurrency and reduce deadlocks, added missing indexes, and removed redundant and unused indexes to improve performance.
- Developed standards and methods to streamline cross-functional development.
Technologies: .NET, SQL Server 2000, Databases, SQL Server Integration Services (SSIS), Crystal Reports, BI ReportsDirector of Data Warehousing
2002 - 2003Visa- Led the data warehousing solutions team to develop applications using MicroStrategy, Cognos, Crystal, VB, ASP, MTS, and SQL Server.
- Enabled Visa and banks to track and measure the success of the Visa Extras rewards program.
- Developed the MicroStrategy architecture for Visa Extras metrics reports and designed attributes, facts, metrics, filters, prompts, hierarchies, drill maps, and cubes.
- Pioneered Verified by Visa (VbV) reports, allowing Visa to do exception analysis and performance reporting, which reduced exceptions by 5%. I also designed MicroStrategy reports.
- Launched Commercial Card Enhanced Data (CCED) for Visa to monitor the validity of sales tax exempt transactions. The solution highlighted 100% of merchants over thresholds.
- Collaborated with commercial solutions in launching Visa Information Source (VIS) to increase commercial card market share by 1%.
- Spearheaded vendor relationships with Exodus for data center operations.
Technologies: MicroStrategy, Crystal Reports, IBM Cognos, C#, VB, SQL, Oracle, IBM Db2, Visual BasicDatabase Architect
2000 - 2002Noosh- Designed and architected one of the earliest B2B information services in the industry. The service was built using Java, WebLogic, and Oracle.
- Worked with the development team on performance tuning of database queries.
- Modified the business logic to reduce the load on infrastructure by coordinating with the development and operations teams.
Technologies: Oracle, SANs, NAS Servers, Web Logic, Firewalls, Failover Solutions