Summary
Overview
Work History
Education
Skills
Languages
Certification
Timeline
Generic

Bhargav Reddy Alla

Summary

Strong technical background covering industry standards and frameworks like ISO/IEC 27001, and MITRE ATT&CK; dynamic and results-driven application security analyst. Competent in carrying out security reviews throughout the software development lifecycle, guaranteeing unwavering adherence to rules and guidelines. Seasoned in overseeing and arranging penetration tests, secure code reviews, and vulnerability assessments for a range of applications, including cloud-based, mobile, and web-based ones. Skilled at simplifying procedures and strengthening early security control gates while incorporating security controls into development pipelines.

Overview

5
5
years of professional experience
1
1
Certification

Work History

Application Security Analyst

First National Financial
06.2023 - Current
  • Developed, tested and implemented security policies, plans and procedures for organizational protection.
  • Educated and trained users on information security policies and procedures.
  • Drafted security reports and metrics to track security performance and strategize improvements.
  • Conducted thorough audits to assess the effectiveness of implemented security controls, recommending improvements when necessary.
  • Partnered with IT teams to ensure seamless integration of new applications without compromising existing security infrastructure.
  • Reduced false positives in alert systems through fine-tuning rule sets, resulting in more efficient resource allocation during incident investigations.
  • Administered and monitored firewalls, intrusion detection systems and anti-virus software to detect risks.

Cybersecurity Analyst Intern

RBC
09.2022 - 01.2023
  • Performed risk analyses to identify appropriate security countermeasures.
  • Aided in developing an inventory management system that tracked hardware assets throughout their lifecycle, reducing procurement errors and equipment obsolescence.
  • Analyzed security incidents and provided recommendations for appropriate action to mitigate future threats.
  • Collaborated with cross-functional teams for the successful implementation of cybersecurity projects.
  • Proactively search for threats and suspicious behavior within the enterprise.
  • Undertook preprocessing of structured and unstructured data.

Application Security Engineer

Amazon.in
03.2020 - 08.2021
  • Collaborated with cross-functional teams to address software security risks, improving overall product safety.
  • Maintained and updated documentation for compliance with SOC1 and SOC2 reporting standards.
  • Conducted regular security assessments and audits to maintain ISO/IEC 27001 certification requirements.
  • Managed and resolved security incidents, conducting root cause analysis and implementing corrective actions.
  • Leveraged consultative approach to collaborate with cross-functional teams and stakeholders, providing strategic guidance on architecture design and implementation.
  • Resolved system test and validation problems to provide normal program functioning.

Cybersecurity Analyst

Techgene
08.2019 - 02.2020
  • Developed and maintained backup and disaster recovery plans for critical systems and data.
  • Collaborate closely with various business units to identify, prioritize, and mitigate internal and external vulnerabilities, focusing on their severity and potential impact.
  • Utilize sophisticated email gateway filtering and web content filtering platforms to effectively block spam, malware, and phishing emails, as well as restrict access to potentially harmful content, thereby minimizing the risk of security breaches.
  • Oversee the configuration and maintenance of Syslog/event forwarders to ensure seamless log management, facilitating the timely detection and response to security incidents.
  • Install, configure, and manage DHCP and DNS servers in a Windows environment, ensuring the reliable and secure operation of essential network services.
  • Managed Active Directory, including user and group management, GPO configuration, and security policies.

Education

Post Graduation - Wireless Information Networking

Fleming College
Peterborough, Canada
04.2023

Bachelor of Technology - Instrumentation & Control Engineering

Manipal Institute of Technology
Karnataka, India
06.2019

Skills

Industry Standards/ Frameworks: ISO/IEC 27001, PCI, SOC1 & SOC2, PCI SSC, ITIL, MITRE ATT&CK, OSI, NIST CSF, OWASP, SSDLC

Operating Systems: Windows, Linux, Mac OS

Database Engines: PostgreSQL, MySQL, SQL Server

Query Languages: KQL, SQL, Cypher

Programming Languages: HTML, CSS, Javascript, Python, VHDL

Internet Protocols: TCP/IP, WANs, LANs, SMTP, HTTP/HTTPS, FTP, POP, LDAP, SSH, SSH

SIEM Tools: Splunk, LogRhythm, Lumberjack, Microsoft Azure Sentinel

Scripting Languages: Bash, PowerShell

IAM Tools: CyberArk, Auth0, Okta

Languages

English
Full Professional
Telugu
Full Professional

Certification

  • https://www.credly.com/badges/58cf7cb5-3cc1-492d-8c8b-4677312bc3c0/public_url
  • https://www.credly.com/badges/2836b97f-1b9b-4cd4-a63d-2f2405ed45df/public_url
  • https://www.credly.com/badges/891f828c-6c94-474c-84e4-8caf92571c7d/public_url

Timeline

Application Security Analyst

First National Financial
06.2023 - Current

Cybersecurity Analyst Intern

RBC
09.2022 - 01.2023

Application Security Engineer

Amazon.in
03.2020 - 08.2021

Cybersecurity Analyst

Techgene
08.2019 - 02.2020

Post Graduation - Wireless Information Networking

Fleming College

Bachelor of Technology - Instrumentation & Control Engineering

Manipal Institute of Technology
Bhargav Reddy Alla