Experienced IT professional with 12 years of industry experience, including 6 years specializing in information security, vulnerability management, and Governance, Risk, and Compliance (GRC) functions. Currently working for a Fortune 50 company, applying expertise in information security and vulnerability analysis to protect critical assets and ensure regulatory compliance. Proven track record in effectively safeguarding organizations against cyber threats and ensuring compliance with industry regulations such as NIST, ISO 27001, CCPA, and HIPAA. Experienced in carrying out extensive risk assessments for on-premises legacy assets, cloud deployments, third-party solutions, web applications, and cloud deployments to identify vulnerabilities and implement mitigation strategies. Experienced in vulnerability management, utilizing industry-standard tools and methodologies to assess, prioritize, and remediate vulnerabilities across various systems and environments. Strong expertise in cloud security, specifically with Azure and AWS, implementing robust security controls and best practices to protect cloud environments. In-depth understanding of risk and compliance frameworks and regulations, ensuring adherence to industry standards. Collaborative team player with excellent communication and leadership skills, capable of driving cross-functional initiatives to enhance security posture.
• Supported Cloudera Distribution of Hadoop Eco system and managed Hadoop clusters in Production, dev and DR environments.
• Integrated Windows Active Directory with Hadoop Application.
• Integrated LDAP authentication and Azu MFA Authentication for Hadoop Clusters using MS Azure.
• Disabled deprecated protocols, weaker Cipher suites and hashing algorithms on our application services.
• Integrated Hardware security module (HSM) with Hadoop Keytrustee service for our clusters for managing keys and controlling Encrypt and decrypt operations on EZ zones.
• Managed the TLS certificates for our application and ensuring all the deprecated traffic/protocols are disabled from platform to ensure security and stability of our consumers.
• Worked with in-house cyber security and defense control team to create alerting and monitoring for our non-hum admin accounts and its operations.
• Implemented Kerberos Authentication for all services within Hadoop cluster.
• Responsible for actively monitoring Audits to measure denied accesses, deletions, update to crucial files and fold
• Was responsible for creating and managing user, groups and entitlement roles to manage access within our area maintain least privilege access model.
Involved in installation and configuration patching and maintenance of windows 2008/2003 on HPservers
CompTIA Security+
Certified Information Systems Auditor (CISA)
Microsoft Azure Fundamentals 900