Accomplished enterprise security architect with 15 years of extensive experience in designing and implementing comprehensive security architecture & frameworks for large-scale organizations. Expertise in aligning security strategies with business objectives, ensuring robust protection of critical assets while facilitating operational efficiency. Proficient in evaluating complex IT environments, conducting risk assessments, and developing tailored security solutions that address evolving threats and compliance requirements.
Demonstrated success in security policy development, leading cross-functional teams to drive security initiatives, foster a culture of security awareness, and enhance organizational resilience against cyber threats. Skilled in leveraging cutting-edge technologies and best practices, including Zero Trust Architecture, cloud security, and identity and access management, to fortify enterprise security postures.
- Led the design and implementation of Bank's enterprise-wide security architecture, improving overall security posture by 40%.
- Conducted risk assessments and vulnerability analyses, providing actionable recommendations that reduced security incidents by 30%.
- Developed and enforced security policies and procedures, ensuring compliance with regulatory standards such as APRA, and PCI-DSS.
- Collaborated with Bank's other IT and engineering teams to integrate security solutions into cloud environments (AWS, Azure, Google Cloud), enhancing data protection and access controls.
- Managed security architecture for multi-tier applications, including network segmentation, firewall configuration, and intrusion detection/prevention systems (IDS/IPS).
- Provided leadership and mentorship to junior security professionals, fostering a culture of continuous improvement and knowledge sharing.
|• Identity solutions - Azure AD, One Identity, Ping, SailPoint, Okta
• Protocols - HTTP/HTTPS, Citrix ICA, Tuxedo, RTA, ESB
• TCP/IP protocols – SMTP, SNMP, FTP, HTTP, HTTPS, SSH, SSL
• Operating System - Linux, Windows
• Languages - Java, Python, C#, C/C++, SQL, HTML5, JavaScript, CSS, XML, JSON
• Cloud Technologies - AWS, Azure, GCP
• SIEM Tools - Azure Sentinel, Splunk
• Network security monitoring tools - Nagios, Pof, Splunk, and OSSEC.
• Encryption tools - Tor, KeePass, NordLocker, and TrueCrypt.
• Web vulnerability scanning tools - Burp Suite, Nikto, Paros Proxy, and SQLMap.
• Penetration testing - Metasploit, Kali Linux, Netsparker, and Wireshark.
• Antivirus software - Norton 360 AV, Bitdefender Antivirus, Kaspersky Anti-Virus, and McAfee Total Protection.
• Network intrusion detection - Snort, Security Onion, SolarWinds Security Event Manager, Kismet
• Packet sniffers - Wireshark, Tcpdump, and Windump.
• Firewall tools – Palo Alto, AlgoSec
• GRC Solution – ServiceNow, Archer