Sr. Security Advisor - SunLife - Toronto
(2020-08)
Sun life analytics team is responsible for collection of logs from various sources to support breach analysis and monitoring for security incidents to derive insights.
- Analysis of security incidents.
- Security use cases. Derive insights from data to analyze breaches for internal analytics team.
- Designed and implemented a log source system to gather logs from Office 365, Win 10, Azure Cloud (AIP, RMS), SharePoint, DLP to populate the data storage S3. Supported Win 2016 and RHEL/Unix environment.
- Used Java and Python to split the logs in AWS.
- Cleansing and parsing data to data tables to enable BI analytics.
Security Specialist – Consultant - Price Waterhouse Coopers (PWC) - Toronto
(2021-02 - 2023-06)
Business Information Security and Network Information Security
- Advanced knowledge skills with Information Security Operations practices, approaches and best practices.
- Security operations, incident management.
- Demonstrated understanding of diverse operating systems (Microsoft Windows, Linux, Unix), service-oriented architectures and middleware, firewalls, scanners, security policies, physical security, encryption, PKI, directory services, RDP, VPN and aspects of information security.
- Demonstrated extensive experience in network protocol and firewall knowledge with in-depth understanding of VLAN and tunnelling configurations, in addition to training in security related technology, risk mitigation, and techniques.
- Excellent knowledge of security operational and incident response tools and approaches.
- Demonstrated knowledge of up-to-date IT security technology to ensure the enterprise security policies and practices meet operational needs.
- Strong communication and interpersonal skills to present information, conduct meetings, and the development of reports; communicate with all levels of staff, elected officials, and the public.
- Demonstrated organizational, analytical, problem solving, and time management skills to handle multiple deadlines and priorities in a fast-paced environment.
- Ability to work in a team environment, liaise with key external and internal stakeholders and work effectively with minimal supervision.
- Ability to work outside of regular business hours when necessary.
- Collaborated with multi-functional teams, IT, HR, Legal, and compliance weekly to ensure security strategies align with regulatory and compliance needs.
- Reviewing ISO 27001 policies for audit and maintaining them with the other team members.
Security Advisor - Prosecure Group
(2020-01 - 2020-07)
- Designed and implemented a security awareness and training solution.
- Penetration testing for network and web security of client websites and networks.
- Setting up AWS cloud security from ground up.
Information Security Analyst - Canada Guaranty - Toronto
(2018-03 - 2019-12)
Canada guaranty is a mortgage insurance provider previously AIG.
- Expertise with starting security from ground up.
- Installation, design, maintenance and monitoring of security infrastructure such as SIEM, DLP network, DLP email, DLP endpoint and end point antivirus Symantec. Integration of CASB with Symantec DLP.
- Performed vulnerability scans using Nessus, Splunk, solar winds.
- Expertise with OWASP top 10 security concepts and common application security risks, such as XSS, XSRF and SQL Injection with penetration testing. Provided security solutions for Win 10 and Office 365.
- Incident Response and Investigation for insider threats with DLP, SPLUNK.
- Performed Python and shell scripting; Threat intelligence analysis, correlation regex's with IDPS, SIEM, Firewall logs, Application firewall, Radius, VPN logs using SPLUNK.
- Provided changes for Cisco ASA firewall, improved DNS feeds.
- Hardening OS standards, CIS benchmarks.
- Tracking and monitoring of software viruses and malware.
- Worked with infrastructure group and other cross functional teams with building relationships. Strong understanding of IP, TCP/IP, IPSEC, HTTPS, and other network administration protocols to troubleshoot network, server and application issues.
- Worked in a Win 2012/2016 and Unix/RHEL environment.
- Worked with external auditors for SOC1 and OSFI audit and penetration testing of network and applications.
- Experience in reviewing and improving Business Continuity Plans and Disaster Recovery Plans for SOC1 audit and PCI compliance.
- Worked with Firewalls, IPS/IDS, Malware/Zero day detection and protection, Host based AV/IPS/Application White listing and SIEM.
- Review reports for PAM solution, interface with vendors and teams for configuring, changes to workflow.
Security Engineer, R&D - Symantec. Cloud - Toronto
(2012-03 - 2018-02)
Symantec is a world leader in providing network security products. They provide managed security solutions, secure messaging solutions, PKI certificates, digital certificates etc.
- Implemented Symantec DLP network, email, end point for financial client. Augmented CASB/cloud solution for Symantec DLP.
- Asset protection with role based access control, windows permissions (Win 10) and Azure RMS (rights management). Supported Win 2012 environment.
- Coordinating tickets and data flow from customers to SIEM.
- Working with AWS EC2 servers to analyze the data for telemetry in environments.
- Implemented Azure RMS for access control of files and assets
- Security access controls for AWS, cloud security, access control.
- Consultant support for customers to configure and monitor the network traffic.
- Analyze allow, block rules for customer traffic with the Symantec products ATP, Proxy SG, DLP.
- Subject matter expert for DLP managed service, Web security solutions and email security solutions.
- Worked with Qualys for vulnerability detection; resolved incidents related to vulnerability of applications across email, web security enterprise architectures.
- Access control reviews for enterprise architecture in Cloud environments using AWS and data centers.
- Implementing security policies, security controls across groups, security best practices, network defense policies, along with strong understanding of Cisco firepower firewalls and networking protocols.
- Risk assessments, Asset classification, gap analysis.
- Key contributor to Symantec web security, Email security groups for applying security remediation patches.
- Maintaining compliance for PCI –DSS, HIPPA –health industry, GLBA and ITAR.
- Apply patches to remediate the vulnerabilities to the applications.
SQA Developer - Symantec - Toronto
(2007-03 - 2012-02)
Proxy SG: Proxy SG is a web security solution engine to integrate in to the existing cloud infrastructure to detect rule based violations, compliance violations and targeted attacks to the customer.