Results-driven Cyber Security & NW Security Specialist with over 16 years of comprehensive experience in IT security, specializing in Web Application Firewalls (WAF), application-aware firewalls, and advanced network infrastructure hardening. Highly proficient in the networking stack, web services, and web application load balancing, with a proven track record of designing and implementing robust security architectures. Demonstrated expertise in PKI rollout and certificate management, as well as authentication frameworks including mutual authentication and Single Sign-On (SSO) via Kerberos. Adept at deploying and managing both forward and reverse proxy solutions to secure enterprise environments. Recognized for technical excellence, strategic problem-solving, and the ability to deliver resilient, scalable security solutions in complex, fast-paced organizations.
Designed and managed enterprise-wide infrastructure security solutions to safeguard access and protect data both at rest and in transit, ensuring robust authentication and data integrity.
Installed, configured, and maintained commercial Application Aware firewalls, proxies, WAFs, MDM and DDoS mitigation solutions; collaborated with teams and security vendors to implement best hardening practices for all security systems with timely software updates.
Designed, deployed, and configured end-to-end (Layer 4–Layer 7) infrastructure security controls to enable secure remote connectivity.
Spearheaded the integration of multi-factor authentication systems to bolster access control measures across the organization.
Ensured business continuity by developing disaster recovery strategies and backup plans for critical systems.
• Configuring ASA 5510 with CSC SSM module for content filtering
• Configuring IPSec VPN between branch office, and Remote Access VPN using Cisco VPN Client 4.6 for remote users with split-tunneling and monitoring it with logs.
• Use of CBAC, IOS Firewall, IDS for security policies enforcement.
• Use of Vulnerabilities scanners like Nesses and Penetration testing using Nmap.
• Plan, design, and configure routing and switching environment using routers 1700, 2600, and switches CE 500, catalyst 2950 switches.
• Dividing the network into different broadcast domains using Vlans, and configuring inter-Vlan routing with router-on a stick.
• Configuration of OSPF with areas and redistribution with Static subnets.
• Reporting to enterprise team on bi-weekly enterprise call.
• Configuration of ACS for AAA.
• Working on Active Directory domains & trust with GPO implementation.
WAF, Reverse Proxy, Forward Proxy, MDM, Firewalls, Sandbox
ECSAv10 (EC-Council Certified Security Analyst)
Going to swimming, playing soccer, table tennis
New learning in areas of science, technology like Quantum Computing driving the AI etc.
Resident Of :- Doha, Qatar
Nationality :- India
Passport Number :- W6057263
ECSAv10 (EC-Council Certified Security Analyst)
CNDA (Certified Network Defense Architect)
CEH (Certified Ethical Hacker)
CCIE Security Written