Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Tovus Gulomkadirova

Cyber Security Engineer
Chicago,IL

Summary

Adept Cyber Security Engineer with a proven track record at Slalom and Morningstar, specializing in Zero Trust and IAM. Excelled in securing cloud infrastructure and leading incident response, demonstrating strong analytical skills and a collaborative approach. Achieved significant improvements in security posture through innovative automation and vulnerability management.

Overview

4
4
years of professional experience
1
1
Certification
4
4
Languages

Work History

Cyber Security Engineer

Slalom
02.2022 - Current
  • Secured Cloud Infrastructure: Designed and implemented security solutions for cloud environments, focusing on Azure and AWS, ensuring data protection and compliance with industry standards.
  • Vulnerability Management: Conducted regular vulnerability assessments using Nessus, identifying and remediating security risks across client systems and applications.
  • Incident Response & Threat Hunting: Investigated security incidents, analyzed attack vectors, and provided actionable recommendations for improving security posture. Led proactive threat hunting activities using SIEM-Microsoft Sentinel.
  • Zero Trust Architecture: Implemented Zero Trust security models for client organizations, ensuring that only authenticated users and devices could access critical resources.
  • Identity & Access Management (IAM): Managed and optimized IAM solutions to enforce least-privilege access, ensuring secure and compliant user authentication across systems.
  • Security Automation: Automated security monitoring and reporting using tools like Azure Security Center, Defender for Cloud, and PowerShell scripts, improving detection and response time.

Security Analyst

Morningstar
07.2020 - 01.2022
  • Incident Response: Led investigations into security incidents, working with teams to resolve issues and document actions taken.
  • Vulnerability Management: Regularly scanned systems with tools like Nessus to identify and fix vulnerabilities.
  • Malware & Phishing Detection: Investigated suspicious emails and malware, collaborating with IT to implement preventative measures.
  • Managed Security Tools: Administered Defender for Endpoint to protect systems and automate threat detection.
  • Reviewed Security Logs: Analyzed firewall and IDS/IPS logs to detect unauthorized access and improve security controls.
  • Security Training: Delivered security training to employees to reduce risks from human errors and improve awareness.
  • Collaborated Across Teams: Worked closely with IT, Risk, and Compliance teams to ensure strong data protection and reported security updates to senior management.

Education

BBA - Management of Organization

Russian-Tajik Slavonic University
Dushanbe, Tajikistan
05.2001 -

Skills

    IAM

    Azure WAF

    Azure Sentinel

    Defender for Endpoint

    Defender for Cloud

    Azure Policy

    Conditional Access

    Zero Trust

Certification

Az-500

Timeline

Cyber Security Engineer

Slalom
02.2022 - Current

Security Analyst

Morningstar
07.2020 - 01.2022

BBA - Management of Organization

Russian-Tajik Slavonic University
05.2001 -

Az-500

Tovus GulomkadirovaCyber Security Engineer