Accomplished Senior Cyber Security Specialist with a proven track record at Wells Fargo, enhancing organizational security through expert vulnerability assessments and strategic incident response. Skilled in Microsoft Azure and Splunk, adept at multitasking and problem-solving. Significantly improved threat detection and compliance, demonstrating professionalism and a keen ability to address complex security challenges.
Overview
9
9
years of professional experience
1
1
Certification
Work History
Senior Cyber Security Specialist
Wells Fargo
06.2023 - Current
Performed security and privacy assessments, including vulnerability assessment and penetration
testing, to determine compliance and strengthen organizational security posture.
Led security incident responses and investigations, identifying root causes and consulting with
teams to implement solutions within SLA timeframes.
Implemented Azure Sentinel, Azure Security Center, and Application Gateway to enhance moni-
toring and incident response capabilities.
Successfully established and tested Azure AD Tenant for production, ensuring secure deployment
and scalability.
Hands-On experience with security tools, such as Splunk, QRadar, and Symantec Endpoint Protec-
tion.
Conducted thorough vulnerability assessments of applications using tools like Nessus and manual
techniques, adhering to OWASP standards.
Automated security controls, processes, and metrics to streamline operations and enhance or-
ganizational security.
Reviewed and created firewall rules while monitoring logs in Checkpoint and Net Screen Firewalls
to ensure compliance with security standards.
Managed onboarding projects for security hardware/software implementations and updates, en-
suring seamless deployment across systems.
Conducted event correlation and analysis using tools like Wireshark, Nessus, and TCP dump to
identify patterns and mitigate potential risks.
Designed, tested, and implemented security infrastructure including centralized logging, IDS, and
HIDS systems.
Played a key role in maintaining PCI DSS compliance for critical applications, securing payment
card data and meeting industry standards.
Proactively participated in threat hunting initiatives to identify advanced threats and mitigate
risks before breaches occurred.
Collaborated with third-party penetration testers to identify vulnerabilities and plan effective re-
mediation strategies.
Researched and implemented cutting-edge application security technologies, enhancing the se-
curity posture of critical applications.
Developed and refined cybersecurity policies, procedures, and playbooks to align with organiza-
tional goals and industry best practices.
Senior Consultant( Soc Analyst)
EBay Inc
09.2022 - 05.2023
Configured and managed Azure AD Connect, Microsoft Azure Active Directory, and Azure Single Sign-On to streamline user authentication and access.
Monitored and analyzed security events using SIEM tools (LogRhythm, McAfee ePO, Palo Alto, Mimecast).
Provided real-time threat detection, incident response, and security monitoring to protect against cyber threats.
Monitor security events and alerts generated by Microsoft Sentinel, and respond to incidents in a timely and effective manner.
Conducted risk assessments and updated System Security Plans (SSP) using NIST 800-18 guidelines to ensure regulatory compliance.
Identified and addressed vulnerabilities based on client security policies and regulations such as GDPR, PCI DSS, and HIPAA.
Managed email security solutions, including Proofpoint and Mimecast, to prevent phishing attacks and malware infiltration.
Supported the deployment and monitoring of compliance dashboards in Office 365 Tenant, aligning with organizational security policies.
Developed cloud incident response plans and playbooks, enabling rapid and effective response to security incidents.
Utilized secure software development practices and OWASP Top 10 guidelines to identify and mitigate common vulnerabilities.
Conducted proactive vulnerability management for cloud applications, automating remediation processes for efficiency.
Assisted in the integration of cloud-based security solutions with on-premises infrastructure to ensure seamless operations.
Collaborated with stakeholders to assess cloud security risks and implement mitigation strategies tailored to the organization’s needs.
Leveraged Power BI and Azure Security tools to provide management with detailed insights and actionable metrics on security posture.
Maintained expertise in cloud trends, Azure updates, and best practices to keep security measures aligned with evolving technologies.
Cybersecurity Consultant
Cognizant Technologies Solutions
05.2016 - 09.2020
Successfully managed Security Operations Center (SOC) operations, monitoring network traffic and responding to potential threats.
Played a pivotal role in analyzing complex security issues, identifying root causes, and proposing effective solutions.
Conducted thorough web application penetration tests, identifying vulnerabilities and recommending security enhancements.
Led efforts in maintaining PCI DSS compliance for critical applications, securing payment card data.
Actively participated in threat hunting initiatives, proactively identifying advanced threats and potential breaches.
Involved in weekly and monthly meetings with other teams to review and discuss upcoming production changes and policy modifications.
Create Policies, Procedures, Reports, Metrics, and provide network and host-based security to each host within the organization.
Utilized SIEM (QRadar) systems to monitor and analyze security events, promptly escalating potential threats for further investigation.
Collaborated with L2 analysts to conduct in-depth investigations into complex incidents, providing insights into attack vectors and mitigation strategies.
Assisted in the development of incident response playbooks, streamlining response processes.
Successfully managed Security Operations Center (SOC) operations, monitoring network traffic and responding to potential threats.
Played a pivotal role in analyzing complex security issues, identifying root causes, and proposing effective solutions.
Engaged with clients to understand their security needs, delivering clear and concise documentation and recommendations.
Utilized SIEM systems to monitor and analyze security events, escalating potential threats for further investigation.
Collaborated with senior analysts to contribute to in-depth investigations into complex incidents.
Assisted in refining incident response processes and documentation.
Used PowerPoint to conduct training sessions on new cybersecurity measures and protocols.
Email & Endpoint Security: Proofpoint, Mimecast, Microsoft Defender for Office 365, Microsoft Defender for Endpoint, Symantec Endpoint Protection, CrowdStrike Falcon
Additional Skills: SOP and Playbook Creation, Log Analysis, Security Incident Management, Phishing and Spam Email Analysis, Security Operations Monitoring
Soft Skills: Multitasking, Professionalism, Problem-Solving, Self-Direction, Time Management, Reliability
Certification
Sentinel One Incident Response
Certified Ethical Hacker (CEH).
CompTIA Security
Microsoft SC 200.
Microsoft Defender XDR SC 900.
Mastercard Cyber Security (Forage Internship)
Pwc Switzerland (Forage Internship)
Accomplishments
SIEM (Microfocus sentinel, Splunk, LogRhythm, IBM Qradar consoles
Have a deep knowledge in identifying and analyzing suspicious events
Versatile,bilingual professional and ability to manage sensitive materials
Able to use various security tools to perform logs and packet analysis as well as performing Security SIEM Operational tasks - Analysis, Filters, Active channels, Reports, Dashboards and Suggestion of fine-tuning on existing rules
Have good Knowledge on TCP/IP, security concepts, WAN and LANconcepts, routing protocols, Firewall security policies and good understanding on different types of attacks
Finally, can perform malware analysis, phishing analysis with the overall objective to ensure Confidentiality, Integrity and Availability of the systems, networks and data.
Cyber Security Foundation Professional Certificate
Financial Accounting Associate/ Alteryx SME at Wells Fargo International Solutions Private LTD (Wells Fargo)Financial Accounting Associate/ Alteryx SME at Wells Fargo International Solutions Private LTD (Wells Fargo)
Vice President, Lead Control Management Officer at Wells Fargo International Solutions Private LTDVice President, Lead Control Management Officer at Wells Fargo International Solutions Private LTD