With a solid background as an Information Risk Executive, I bring 4 years of relevant experience and a comprehensive understanding of the GRC Domain, ISO27001, ISO27701, ISO9001, SOC2, and SOC1. My expertise extends to Barracuda WAF, various security tools such as AV, DLP, HIDS, SIEM management, and networking technologies. This unique skill set allows me to effectively analyze, implement, and provide support in the field. Additionally, I possess experience in information security, customer audit and RFP's, project management, incident analysis and recovery, as well as BCP and DR.
Ensuring Compliance with Information Security Policies and Controls. Reviewing and updating Security Policies as necessary, engaging with management to address audit findings. Conducting security awareness training for new employees during the onboarding process. Investigating security breaches and other cyber security incidents.
1. Monitor the organization's networks to detect security breaches and investigate any violations that occur.
2. Evaluate the current technology architecture for vulnerabilities, weaknesses, and opportunities for upgrades or enhancements.
3. Review security tools such as firewalls and data encryption to safeguard sensitive information.
4. Utilize compliance dashboards for monitoring critical projects.
5. Engage in SOC monitoring activities.
6. Conduct SIEM external threat monitoring and correlation.
7. Implement perimeter and network security tools and controls.
8. Oversee the implementation of ISO 27001 ISMS and ISO 27701 PIMS across the organization.
9. Keep the team informed about the latest security news and recommend tools to improve security posture.
10. Provide awareness training on data privacy and rights during employee inductions.
11. Prepare daily, weekly, and monthly dashboards to track project progress.
12. Review and update policies as required by ISO standards.
13. Collaborate with other departments to gather and share information on new requirements.
14. Participate in customer audits and RFP submissions by providing necessary evidence.
1. Conducting daily checks on Barracuda WAF servers
2. Regularly monitoring Azure dashboards
3. Gathering data and information for SSAE SOC2 TYPE2 audit
4. Participating in ISO 27001 audit for compliance
5. Monitoring FortiClient EMS Console for antivirus
6. Updating company policies such as ISMS, SOP's and Change Management
7. Resolving blocked URL issues on WAF as needed
8. Having a basic understanding of Microsoft Azure
9. Weekly monitoring of SIEM dashboards
10. Addressing banking audit requirements
11. Handling customer audits and RFPs
12. Setting up new SMS templates on SMS DLT panel
13. Identifying security issues, conducting RCAs, and ensuring resolutions are implemented
14. Monitoring security access to server rooms, WiFi, firewalls, and other areas.
1. Established and managed incident response procedures to minimize impact and liability in the event of security breaches. Ensured company-wide adherence to industry standards like ISO 27001. Led internal cyber security audits using ArcSight and SIEM Tool to identify vulnerabilities within the organization.
2. Initiating incidents with relevant teams, promptly addressing incidents and service requests, and coordinating resolution efforts.
3. Conducting follow-ups and closing tickets based on client feedback.
4. Monitoring and responding to all essential operational support network events.
5. Supervising inbound and outbound traffic for firewall activities and conducting investigations to deliver comprehensive customer reports.
6. Identifying suspicious logs, generating reports and charts for client comprehension, and engaging with clients to address issues.
7. Producing Daily, Weekly, and Monthly reports and charts.
8. Monitoring Active channel/Dashboard and creating annotations.
9. Leading initiatives to minimize threats to personnel and infrastructure, decrease risks, and enhance access to critical information.
10. Collaborating with third-party partners for Payment Card Industry (PCI) compliance.
11. Providing recommendations for enhancing security systems and procedures.
12. Developing cybersecurity best practice communications to educate staff on recognized threats and potential attack vectors.
1. Established workstations for employees by configuring hardware, devices, and software.
2. Addressed security concerns and safeguarded data by applying software patches and installing updated versions.
3. Conducted analysis of virus and malware problems to determine appropriate troubleshooting techniques for swift resolution.
4. Ensured the smooth operation of ERP software and customer service database through regular maintenance and updates.
5. Communicated technical details in a concise manner to non-technical individuals, fostering improved comprehension.
6. Provided suggestions for revamping the information technology infrastructure.
1. Successfully executed seamless training sessions by overseeing all aspects of the seminar, such as selecting the venue, creating schedules, implementing marketing strategies, making reservations, managing materials, and ensuring smooth event operations and follow-up.
2. Conducted thorough interviews with clients to gain a comprehensive understanding of their event requirements, establish budgets, and set realistic timelines for selecting the venue, finalizing the guest list, and organizing rehearsals, ceremonies, and receptions.
3. Efficiently coordinated various vendors and participants, including florists, photographers, videographers, musicians, officiants, and ceremony contributors, throughout the entire event process, from rehearsals to pre-ceremony, ceremony, and reception events.
4. Effectively handled all administrative logistics related to event planning, such as contract negotiations, fee collection, event bookings, and promotional activities.
5. Provided supervision and guidance to a dedicated on-site team of over 100 professionals, including caterers, audio-visual technicians, and facility management personnel.
6. Skillfully resolved conflicts and facilitated negotiations to achieve mutually beneficial agreements between involved parties.
7. Achieved remarkable success by generating over 10,000 leads for special events, resulting in revenues exceeding 1 crore.
1. Created ticketing software solutions for MSRTC, UPSRTC, BMTC, and Siddhi Vinayak Temple.
2. Engineered software components for automation hardware, including micro-controllers and sensors.
3. Collaborated with teams of software, firmware, and hardware engineers to deliver comprehensive embedded solutions.
4. Developed embedded hardware, firmware, and interfaces tailored for the State Transport industry.
5. Authored technical scripts for routine maintenance tasks, such as indexes and tables analyses.
6. Collaborated with software development and testing teams to devise robust solutions meeting client needs for functionality, scalability, and performance.
7. Conducted testing on troubleshooting methods, formulated creative solutions, and documented resolutions for integration into the knowledge base utilized by the support team.
ISO27001:2022
undefinedISO 27701:2019 Privacy Information Management System Lead Implmenter
ISO 27701:2019 Privacy Information Management System Lead Implmenter
ISO 27001:2022 Information Security Management System Internal Auditor
Certified Cloud Security Professional (CCSP)
Barracuda Self Paced
Certified Information Security and Ethical Hacking