Summary
Overview
Work History
Education
Skills
Websites
Certification
Accomplishments
Technical Stack
Personal Information
Awards
Languages
Timeline
Generic

Santanu Roy

Seattle,WA

Summary

Accomplished enterprise security architect with 15 years of extensive experience in designing and implementing comprehensive security architecture & frameworks for large-scale organizations. Expertise in aligning security strategies with business objectives, ensuring robust protection of critical assets while facilitating operational efficiency. Proficient in evaluating complex IT environments, conducting risk assessments, and developing tailored security solutions that address evolving threats and compliance requirements.

Demonstrated success in security policy development, leading cross-functional teams to drive security initiatives, foster a culture of security awareness, and enhance organizational resilience against cyber threats. Skilled in leveraging cutting-edge technologies and best practices, including Zero Trust Architecture, cloud security, and identity and access management, to fortify enterprise security postures.

Overview

16
16
years of professional experience

Work History

Enterprise Security Architect

NEXTZEN SECURITY - Client ANZ Bank
Seattle, Washington
07.2021 - Current

- Led the design and implementation of Bank's enterprise-wide security architecture, improving overall security posture by 40%.

- Conducted risk assessments and vulnerability analyses, providing actionable recommendations that reduced security incidents by 30%.

- Developed and enforced security policies and procedures, ensuring compliance with regulatory standards such as APRA, and PCI-DSS.

- Collaborated with Bank's other IT and engineering teams to integrate security solutions into cloud environments (AWS, Azure, Google Cloud), enhancing data protection and access controls.

- Managed security architecture for multi-tier applications, including network segmentation, firewall configuration, and intrusion detection/prevention systems (IDS/IPS).

- Provided leadership and mentorship to junior security professionals, fostering a culture of continuous improvement and knowledge sharing.

Senior Security Architect

NEXTZEN SECURITY - NBN Australia
Melbourne, Australia
09.2020 - 06.2021
  • Successfully led multiple transformation programs for NBN Australia, focusing on active network security and cloud security adoption projects and reduced security breach attacks by 45% on NBN network
  • Designed and developed NBN cyber security strategy and roadmap with appropriate controls, security patterns and guidelines to NBN Co as per Government regulations
  • Performed threat & vulnerability assessment for various critical NBN systems and applications and made recommendations for business case
  • Performed risk assessment and security assessment for existing legacy system to migrate to SaaS solutions
  • Implemented security controls, risk assessment framework, and program that aligned to regulatory requirements, ensuring documented and sustainable compliance that aligns and advances NBN business objectives
  • Evaluated risks and developed NBN security standards, procedures, and controls to manage risks
  • Implemented processes, such as GRC (governance, risk, and compliance), to automate and continuously monitor information security controls, exceptions, risks, testing
  • Defined and documented business process responsibilities and ownership of the controls in GRC tool
  • Performed and scheduled regular assessments and testing of effectiveness and efficiency of controls and created GRC reports
  • Provided remediation guidance and prepared management reports to track remediation activities

Senior Security Architect

NEXTZEN SECURITY
Brisbane, Australia
10.2019 - 08.2020
  • Designed and implemented security solutions for a variety of clients, including financial institutions, healthcare providers, and government agencies.
  • Conducted security audits and penetration testing, identifying and mitigating vulnerabilities in applications and network infrastructures.
  • Implemented and managed security information and event management (SIEM) systems, improving incident detection and response times.
  • Worked with development teams to incorporate security best practices into software development lifecycle (SDLC) and DevOps processes.
  • Coordinated with external auditors and regulatory bodies to ensure compliance with security frameworks and standards.

Principal Architect

NEXTZEN SECURITY
Brisbane, Australia
03.2019 - 09.2019
  • Worked on Driving License system security projects for Victoria State Govt in Australia.
  • Assessed and delivered VicRoads DLS systems remediation strategies for critical security gaps, including incident response, risk assessment, data encryption, and identity and access management.
  • Coordinated and assisted in internal and external Cyber Security reviews, assessments, penetration tests, and audits.
  • Provided consistent support to product development.
  • Designed, and implemented information security policies & controls to ensure the confidentiality, integrity, and availability of VicRoads driving license system

Principal Architect

NEXTZEN SECURITY - Client RACQ Bank
Brisbane, Australia
09.2018 - 03.2019
  • Worked on RACQ Bank's Cloud migration project and their IAM initiative
  • Designed and developed new solutions for security services with a focus on Federation, Governance, Identity or Access Management
  • Provide security services in vulnerability assessment, penetration testing and threat detection
  • Designed and implemented Single Sign on Solutions using market leading products with industry standards like SAML 2.0, WS Federation, OAUTH
  • Developed best practices defined by Vendor, Regulatory, Compliance and Corporate policies
  • Managed, troubleshooting of CyberArk PVWA, CPM, PSM, EPV (Vault), AIM & DNA scans
  • Maintained and developed Cyber Security Controls: Governance, Policies, Procedures, Standards and Registers

Lead Security Architect

NEXTZEN SECURITY - Client DHS, ATO, DSS
Melbourne, Australia
02.2016 - 08.2018
  • Worked on Australian Government API security projects under MyGov initiatives to bring multiple departments under one platform increasing security posture by over 60%
  • Developed, and matured MyGov’s API security, policies, standards and practices
  • Inducted as a key member of the security leadership team driving the API Security Architecture for the enterprise wide implemenation
  • Increased Government's operational efficiency and reduced call time by 40% through automation

Senior Consultant

Nimble Australia
Melbourne, Australia
10.2014 - 02.2016

Senior Consultant

Optus Telecom
Melbourne, Australia
10.2013 - 07.2014

Senior Security Consultant

FTI Consulting Inc.
Melbourne, Australia
03.2013 - 09.2013

Technology Consultant

CUA Credit Union
Melbourne, Australia
06.2008 - 02.2013

Education

Master of Business -

University of South Australia
Australia

Bachelor of Commerce -

University of Calcutta
India

CISM - Certied Information Security Manager

ISACA
Los Angeles, CA

CISA - Certified Information Systems Auditor

ISACA
Los Angeles, CA

Skills

  • SABSA
  • NIST
  • Application security
  • Security Protocols
  • Network Security
  • Penetration Testing
  • Incident Response
  • Compliance Management
  • Intrusion Detection
  • Firewall configuration
  • Disaster Recovery
  • Business continuity planning
  • Goal Setting
  • Problem-solving aptitude
  • Data Encryption
  • Teamwork and Collaboration
  • Critical Thinking
  • Risk Assessment
  • Analytical Thinking
  • Adaptability
  • Organizational Skills

Certification

  • CISM – Certified Information Security Manager
  • CISA – Certified Information Systems Auditor

Accomplishments

  • More than 15+ years of Australian industry experience as a senior security architect within multiple domains like retail, insurance, consulting, banking etc. including many federal government departments (ATO, DHS, Defence, DSS)
  • Experience in assessing and working with multiple Security frameworks such as ISO 27000 family of standards, NIST, SABSA, COBIT, IRAP and key legislative, regulatory, and industry-based compliance (e.g., PCI-DSS, APRA Privacy Act)
  • Experience in developing security architectures for cloud and hybrid cloud-based systems (SaaS, PaaS, IaaS)
  • Possess a firm understanding of the security offerings within both Azure and AWS platforms and office 365 security
  • Highly experienced in assessing risk and implementing cloud-native architectures with appropriate security controls required for E8 (Essential 8) maturity uplift
  • Deep Technical knowledge in routing, firewall policy, Anti-DDoS, WAF, IPS, IDS, SIEM, etc.
  • Working knowledge in hybrid cloud architecture and security focusing on vulnerability assessment, privacy and data protection, identity & access management, and threat management
  • Developed cloud Optimisation and cloud transformation initiatives by cost reduction, automations, and governance
  • Highly experienced in interacting with C-level executives and IT Leadership team to add value proposition in cloud first area and provide ideas or strategies to reach customer’s cloud migration goal

Technical Stack

|• Identity solutions - Azure AD, One Identity, Ping, SailPoint, Okta

• Protocols - HTTP/HTTPS, Citrix ICA, Tuxedo, RTA, ESB

• TCP/IP protocols – SMTP, SNMP, FTP, HTTP, HTTPS, SSH, SSL

• Operating System - Linux, Windows

• Languages - Java, Python, C#, C/C++, SQL, HTML5, JavaScript, CSS, XML, JSON

• Cloud Technologies - AWS, Azure, GCP

• SIEM Tools - Azure Sentinel, Splunk

• Network security monitoring tools - Nagios, Pof, Splunk, and OSSEC.

• Encryption tools - Tor, KeePass, NordLocker, and TrueCrypt.

• Web vulnerability scanning tools - Burp Suite, Nikto, Paros Proxy, and SQLMap.

• Penetration testing - Metasploit, Kali Linux, Netsparker, and Wireshark.

• Antivirus software - Norton 360 AV, Bitdefender Antivirus, Kaspersky Anti-Virus, and McAfee Total Protection.

• Network intrusion detection - Snort, Security Onion, SolarWinds Security Event Manager, Kismet

• Packet sniffers - Wireshark, Tcpdump, and Windump.

• Firewall tools – Palo Alto, AlgoSec

• GRC Solution – ServiceNow, Archer

Personal Information

  • Title: Senior Security Architect
  • Work Permit: USA work authorization via E2 Visa – Australian Citizen (USA and Australia E2 Treaty Visa)

Awards

  • Top Security Architect Award for the Bankers Digital Tribe, ANZ Bank, 12/2022
  • Active Network Security Architect Award, NBN Australia

Languages

English
Full Professional
French
Limited
Bengali
Native/ Bilingual
Hindi
Native/ Bilingual
Spanish
Elementary

Timeline

Enterprise Security Architect

NEXTZEN SECURITY - Client ANZ Bank
07.2021 - Current

Senior Security Architect

NEXTZEN SECURITY - NBN Australia
09.2020 - 06.2021

Senior Security Architect

NEXTZEN SECURITY
10.2019 - 08.2020

Principal Architect

NEXTZEN SECURITY
03.2019 - 09.2019

Principal Architect

NEXTZEN SECURITY - Client RACQ Bank
09.2018 - 03.2019

Lead Security Architect

NEXTZEN SECURITY - Client DHS, ATO, DSS
02.2016 - 08.2018

Senior Consultant

Nimble Australia
10.2014 - 02.2016

Senior Consultant

Optus Telecom
10.2013 - 07.2014

Senior Security Consultant

FTI Consulting Inc.
03.2013 - 09.2013

Technology Consultant

CUA Credit Union
06.2008 - 02.2013

Master of Business -

University of South Australia

Bachelor of Commerce -

University of Calcutta

CISM - Certied Information Security Manager

ISACA

CISA - Certified Information Systems Auditor

ISACA
Santanu Roy