Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

MANNAN FAROOQUI M ABDUL

Naperville,IL

Summary

Experienced IT professional with 12 years of industry experience, including 6 years specializing in information security, vulnerability management, and Governance, Risk, and Compliance (GRC) functions. Currently working for a Fortune 50 company, applying expertise in information security and vulnerability analysis to protect critical assets and ensure regulatory compliance. Proven track record in effectively safeguarding organizations against cyber threats and ensuring compliance with industry regulations such as NIST, ISO 27001, CCPA, and HIPAA. Experienced in carrying out extensive risk assessments for on-premises legacy assets, cloud deployments, third-party solutions, web applications, and cloud deployments to identify vulnerabilities and implement mitigation strategies. Experienced in vulnerability management, utilizing industry-standard tools and methodologies to assess, prioritize, and remediate vulnerabilities across various systems and environments. Strong expertise in cloud security, specifically with Azure and AWS, implementing robust security controls and best practices to protect cloud environments. In-depth understanding of risk and compliance frameworks and regulations, ensuring adherence to industry standards. Collaborative team player with excellent communication and leadership skills, capable of driving cross-functional initiatives to enhance security posture.

Overview

11
11
years of professional experience
1
1
Certification

Work History

Senior Cybersecurity Risk and Vulnerability Analyst

Farm Mutual Automobile Insurance Company
10.2018 - Current
  • Responsibilities include providing high quality risk assessments with a focus on early identification of security requirements/controls for quality assurance in support of regulatory requirements (e.g., PCI-DSS, NIST, ISO-27001, HIPAA, CCPA) utilizing available Governance Risk Compliance (GRC) technology tools
  • Influence the integration of security best practices and design earlier in the solution development lifecycle
  • Identification of potential security vulnerabilities based on the results of DNR checks, design review observations, code scans, IAM scans, penetration testing results, cloud maturity assessments and the corresponding security consulting on risk mitigation options
  • Proactively engage with business partners to aid in the identification of information security and privacy risks, vulnerability mitigation, and understanding solutions of business partners
  • Collaboration with business partners to complete highest priority risk assessments and to influence mitigations rather than risk acceptance
  • Utilize DAST (Burpe Suite) and SAST tools (Snyk) for conducting scans, identifying vulnerabilities, and engaging in communication and dialogue with business partners regarding potential remediation
  • Conduct security audits to identify vulnerabilities
  • A significant part of my role involves supporting the entire vulnerability lifecycle, from discovery to assessment, reporting, remediation, and validation and analyze them to determine their severity, likelihood of exploitation, and potential impact on the organization to remediate them
  • Collaborate with governance teams in formulation of enterprise security policies and technical standards related to vulnerability management, securing assets and data in alignment with industry standards and frameworks
  • Facilitate and track remediation and corrective action plans, using ServiceNow, Jira and Archer, for identified vulnerabilities during assessments and audits
  • Monitor and evaluate effectiveness of enterprise cybersecurity safeguards, using Nessus Tenable, to ensure they provide intended level of protection
  • Partner with vulnerability management teams to maintain an enterprise vulnerability management platform and scanning architecture
  • This involves configuring the platform to scan for specific vulnerabilities based on organizational priorities, managing scanning schedules, analyzing scan results, and generating reports for senior leadership
  • It also involves ensuring that the platform is continuously updated with the latest threat intelligence feeds to stay ahead of emerging threats
  • Work closely with information security engineers to develop cybersecurity architecture components that address evolving threats
  • Stay vigilant in recognizing and sharing information on both existing and new security risks
  • Evaluate compliance/gaps/remediation assessments against Payment Card Industry Data Security Standard (PCI DSS)
  • Closely work with the incident response team to identify the root cause of security incidents, contain any damage, remediate any vulnerabilities that were exploited, and prevent similar incidents from occurring in the future
  • It also involves providing regular updates to senior leadership on the status of incident response efforts.

Infrastructure Analyst

State Farm Mutual Automobile Insurance Company
08.2017 - 09.2018

• Supported Cloudera Distribution of Hadoop Eco system and managed Hadoop clusters in Production, dev and DR environments.
• Integrated Windows Active Directory with Hadoop Application.
• Integrated LDAP authentication and Azu MFA Authentication for Hadoop Clusters using MS Azure.
• Disabled deprecated protocols, weaker Cipher suites and hashing algorithms on our application services.
• Integrated Hardware security module (HSM) with Hadoop Keytrustee service for our clusters for managing keys and controlling Encrypt and decrypt operations on EZ zones.
• Managed the TLS certificates for our application and ensuring all the deprecated traffic/protocols are disabled from platform to ensure security and stability of our consumers.
• Worked with in-house cyber security and defense control team to create alerting and monitoring for our non-hum admin accounts and its operations.
• Implemented Kerberos Authentication for all services within Hadoop cluster.
• Responsible for actively monitoring Audits to measure denied accesses, deletions, update to crucial files and fold
• Was responsible for creating and managing user, groups and entitlement roles to manage access within our area maintain least privilege access model.

Linux/Unix System Administrator

Office Depot
05.2014 - 07.2017
  • Was Responsible for installation of OS Patches, hardware, software and firmware upgrades
  • Installation of SSL certificates on Linux servers
  • Maintained network and data security, maintained security compliance policies on OS for SOX andinternal audits
  • Responsible for storage, Disk management, Logical Volume management
  • Responsible for managing User accounts, system security, change management and performance tuning
  • Set up and maintained NFS, NIS and TCP/IP network, configured the systems for TCP/IP networking withthe existing LAN, setting up SSH and SCP features between SUN systems and RedHat/Unix Hosts
  • Integrated Linux Environment with Active directory and SSO
  • Configuration and administration of LDAP and NIS in Linux and also implemented SAMBA for sharingresources between Windows and Linux.

Windows System Admin

Thomson Reuters
08.2013 - 05.2014

Involved in installation and configuration patching and maintenance of windows 2008/2003 on HPservers

  • Involved in up gradation of Active Directory 2003 to 2008 and troubleshooting AD problems
  • Involved in building and installing servers and managed them remotely for software upgrades and patches
  • Tested Anti-virus updates, OS patches in test environment before deployment
  • Provided support to application teams on IIS configuration, ensure availability and capacity of key services such as file, print, DHCP and DNS.

Education

Master of Science - Computer Engineering

International Technological University (ITU)
San Jose, California
2012

Bachelor of Computer Applications -

Osmania University
2007

Skills

  • NIST 800-53 (R4/5)
  • NIST CSF
  • ISO 27001
  • HIPPAA, CCPA, 23 NYCRR 500
  • MITRE TTP's, SOC1 and SOC2
  • POA&M Management
  • System Security Plan (SSP's) and SSR's
  • Compliance / Configuration Management (STIG)
  • And SCAP scan
  • OWASP top 10
  • RSA Archer, ServiceNow GRC, Vanta and Drata
  • Tenable Nessus Professional (ACAS)
  • Rapid7 Nespose
  • Burpe Suite, Synk and Pmapper
  • Qualys
  • Good Knowledge on Firewalls, traffic patterns
  • VLAN's, subnets, proxy, ingress/egress rules

Certification

CompTIA Security+

Certified Information Systems Auditor (CISA)

Microsoft Azure Fundamentals 900

Timeline

Senior Cybersecurity Risk and Vulnerability Analyst

Farm Mutual Automobile Insurance Company
10.2018 - Current

Infrastructure Analyst

State Farm Mutual Automobile Insurance Company
08.2017 - 09.2018

Linux/Unix System Administrator

Office Depot
05.2014 - 07.2017

Windows System Admin

Thomson Reuters
08.2013 - 05.2014

Master of Science - Computer Engineering

International Technological University (ITU)

Bachelor of Computer Applications -

Osmania University
MANNAN FAROOQUI M ABDUL