Summary
Overview
Work History
Skills
Accomplishments
Timeline
Generic

MUHAMMAD NASAR

Brooklyn

Summary

Results-driven SecOps Engineer with expertise in implementing security controls across identity, endpoint, network, and data protection domains. Specializes in deploying multi-factor authentication, automating workflows with PowerShell and Azure Runbooks, and managing SIEM platforms for threat detection. Excels in configuring security policies via GPO, Intune, and application allowlisting, while enhancing security posture through patch management and network device hardening.

Overview

6
6
years of professional experience

Work History

SecOps Engineer

USAA Insurance
02.2021 - 01.2026
  • Executed deployment and configuration of MFA solutions (DUO, Azure MFA) with Active Directory/Entra integration to secure administrative and remote access points.
  • Created and maintained PowerShell scripts and Azure Runbooks to automate account lifecycle management, including dormant account disabling and default account handling.
  • Designed and enforced privileged access controls through dedicated administrator account separation and role-based access restrictions.
  • Managed endpoint security policies via GPO and Intune, enforcing session timeout policies, firewall rules, and baseline security configurations across Windows devices.
  • Configured and maintained host-based firewalls and Windows Defender Firewall rules on servers and workstations for enhanced security.
  • Deployed application allowlisting tools such as ThreatLocker, managing policies to prevent unauthorized applications and control access to removable media devices.
  • Hardened network devices and endpoints by disabling insecure protocols, updating firmware, and applying OS patches regularly.
  • Led SIEM implementation and management, including log source setup, forwarding, retention policies, and regular monitoring for security events.
  • Automated patch management workflows for operating systems and third-party applications, reducing manual intervention and patching windows.
  • Managed anti-malware solutions, ensuring continuous updates and real-time threat mitigation.
  • Set up data encryption and access controls on end-user devices, and engineered automated backup solutions, including immutable storage options for disaster recovery.

Engineer

Blue Cross Blue Shield
03.2020 - 01.2021
  • Led the deployment and configuration of multi-factor authentication (MFA) solutions such as DUO, integrated with Active Directory/Entra, ensuring secure user enrollment for administrative and remote access.
  • Developed automation scripts using PowerShell and Azure Runbooks to disable dormant accounts and manage default accounts, enhancing identity security posture.
  • Implemented privileged access restrictions and dedicated administrator account separation to mitigate insider threats.
  • Configured Group Policy Objects (GPO), Intune, and MDM policies to enforce session locking, firewall rules, and secure baseline configurations across Windows endpoints.
  • Managed Windows Defender Firewall and host-based firewalls on end-user devices and servers, ensuring consistent security enforcement.
  • Deployed application allowlisting solutions such as ThreatLocker and tuned USB/removable media controls to prevent unauthorized data transfer.
  • Hardened network infrastructure and endpoints by disabling insecure management protocols like HTTP, Telnet, and WinRM, and ensured firmware and OS updates were consistently applied.
  • Deployed, configured, and migrated SIEM platforms for centralized log management, including setting up log forwarding, data retention, and archive policies.
  • Automated patch management processes for operating systems and applications, reducing vulnerability exposure.
  • Managed anti-malware deployment, ensuring automatic signature updates and real-time threat detection.
  • Configured data encryption and access control lists on end-user devices, and built automated backup solutions with immutable and air-gapped recovery options.
  • Implemented DNS filtering solutions such as DNSFilter and maintained automatic updates for applications and browsers.
  • Collaborated with subject matter experts and data stewards to define PII standards and develop data strategies, policies, and controls, ensuring accuracy and security of enterprise data.
  • Reviewed data needs and driving data solutioning decisions. Ability to build data masking configurations in the data masking tools.
  • Improved processes for preventing and detecting data security incidents. for preventing, detecting, identifying, analyzing and responding to data security incidents
  • Supported the data security management program across Adobe through realization of Adobe’s Data Management Policies and Standards
  • Facilitated discussion, decision making, and conflict resolution to ensure consistent progress
  • Monitored key performance metrics to support team success. that are important to the team in order to deliver success and continuous improvement
  • Involved in creating a duplicated version of a dataset, containing fully or partially masked data.
  • Modified sensitive information as it was transferred between environments, ensuring that sensitive information is masked before it reached the target environment.
  • Developed views and templates with Python and Django's view controller and templating language to create user-friendly website interface
  • Used Python and Django to interface with the jQuery UI and manage the storage and deletion of content
  • Developed dashboard reports to facilitate data-driven decision-making, establishing Key Performance Indicators (KPIs) for performance monitoring.
  • Used Alteryx to blend data from multisource and generate TDE for FE Tableau

Skills

  • SIEM management
  • MFA deployment
  • AD integration
  • Application Allowlisting Tools (ThreatLocker, AppLocker)
  • PowerShell automation
  • Firewall Management (Windows Defender Firewall, Network Firewalls)
  • Anti-Malware Solutions (Windows Defender, Malwarebytes, Sophos)
  • Patch management
  • GPO administration
  • Data Encryption and Access Control (BitLocker, EFS)
  • Device hardening
  • DNS filtering
  • Disaster recovery

Accomplishments

  • Tableau Public Profile: https://public.tableau.com/profile/awais.nasar#!/

Timeline

SecOps Engineer

USAA Insurance
02.2021 - 01.2026

Engineer

Blue Cross Blue Shield
03.2020 - 01.2021
MUHAMMAD NASAR