Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Yash Deep Sodhi

Ottawa,Canada

Summary

CISSP-certified Security Professional with over 7 years of experience in technical vulnerability management, network security administration, and infrastructure hardening across enterprise environments. Proven track record of designing secure enclave architectures, enforcing Zero Trust access controls, and translating complex security control policies into actionable engineering mitigations. Adept at leading cross-functional risk alignment, automating workflows with Python/Bash, and conducting technical security assessments to maintain continuous compliance readiness

Overview

1
1
Certification
8
8
years of professional experience

Work History

Information Security Analyst II

AMD
Ottawa, Ontario
09.2022 - Current
  • Technical Security Validation & Enclaves: Engineered and validated secure enclave architectures and isolated networks for R&D teams, translating strict security isolation guidelines into concrete infrastructure controls. Supported security controls across hybrid environments including Azure and GCP firewall infrastructure.
  • Zero Trust & Access Control: Administered transition from a traditional perimeter architecture (Palo Alto Firewalls and GlobalProtect VPN) to hybrid enterprise architecture introducing Zero Trust Network Access (ZTNA) with a focus on Zscaler Private Access (ZPA), enforcing granular, least-privilege access policies across hybrid infrastructure.
  • Risk Profiling & Security Assessments: Conducted technical exposure assessments and security risk profiling for newly acquired network assets and firewall configurations, authoring comprehensive risk evaluation reports for executive stakeholders.
  • Emergency Threat Mitigation: Coordinated cross-functional mitigation strategies for high-severity zero-day exploits (including CVE-2026-0257 and CVE-2024-3400), significantly shrinking the organization's external attack surface.
  • PKI & Compliance Governance: Governed end-to-end PKI certificate lifecycles for hundreds of mission-critical production assets including amd.com, maintaining continuous service availability and encrypted communications.
  • Lifecycle Management: Executed complex end-to-end, zero-downtime hardware migration of legacy firewalls, conducting architectural analysis to guarantee an elevated security posture.
  • Continuous Control Auditing: Performed quarterly technical audits of site-to-site IPsec tunnels and firewall rulebases, validating compliance against internal policies and SOX controls. Demonstrating knowledge of interpreting compliance standards – understanding the security requirement > implementing technical controls > validation > risk remediation > quarterly review.

Security Operations Analyst

Xilinx, Inc
Hyderabad, India
05.2019 - 08.2022
  • Vulnerability Management Operations: Led vulnerability management operations using Rapid7 InsightVM by identifying, reporting, and driving remediation of critical and zero-day vulnerabilities (including SolarWinds/FireEye) assessing exploitability against internal asset inventory and prioritizing remediation by actual attacker reach rather than raw CVSS score, reducing overall network risk by 20%.
  • Workflow Automation & Reporting: Developed automated Python and Bash scripts to extract security metrics from external databases(PostgreSQL) , engineering custom vulnerability reporting pipelines (Rapid7 > Database > excel> email ) for technical and non-technical stakeholders.
  • Patch and risk mitigation: Led monthly cross-functional remediation meetings with IT team leads to prioritize vulnerabilities, coordinate patching efforts, and ensure the timely mitigation of risks.
  • Threat Modeling: Applied OWASP Top 10 risk standards to systematically categorize and prioritize application security vulnerabilities, delivering actionable mitigation guidance to engineering teams to accelerate targeted remediation.
  • Application Security Testing: Executed Dynamic Application Security Testing (DAST) using Rapid7 InsightAppSec to detect web application vulnerabilities, partnering with product teams to embed remediations into early SDLC stages.
  • OS Hardening & Compliance: Performed system compliance scans and provided actionable Linux and OS hardening guidance to engineering leads based on CIS Benchmarks.
  • Incident Response & Threat Containment: Partnered with the SOC to execute real-time threat containment during active incidents, such as rapidly neutralizing identity-based password spray attacks to prevent unauthorized access.

Security Operations Intern

Xilinx, Inc
Hyderabad, India
06.2018 - 05.2019
  • Administered McAfee Vulnerability Manager as a global administrator, leading monthly cross-team reviews to communicate asset vulnerabilities and drive timely remediation across affected systems.
  • Developed vulnerability risk reports to support monthly remediation planning and drive risk-based decision-making.
  • Coordinated inventory migration of critical devices during data center relocation, ensuring asset tracking and minimal operational disruption.

Education

Master of Applied Computing -

University of Windsor
Windsor, Canada
12-2023

Bachelor of Technology - Information Technology

SRM University
Chennai, India
12-2018

Skills

  • Network Security and Zero Trust - Palo Alto NGFW, GlobalProtect VPN, Zscaler (ZPA/ZIA), IPSEC, PKI, Network Segmentation, Enclave architecture
  • Vulnerability Management, Threat Modelling & OS hardening - Rapid7 InsightVM, Rapid7 Insight Appsec, McAfee Vulnerability Manager, Vulnerability Scanning & Detection, Risk Assessment, Risk based prioritisation of remediation - CVSS v3/v4, OWASP top 10 (Threat Modelling) , CIS benchmarks
  • Reporting and Automation - Excel, ServiceNow, Splunk, PostgreSQL, Python scripting, bash scripting
  • Compliance & Risk Governance - SOX controls auditing, risk-based remediation prioritization, executive risk reporting

Certification

Certified Information Systems Security Professional (CISSP), Cisco Certified Network Associate (CCNA), Cisco Certified Entry Networking Technician (CCENT)

Timeline

Information Security Analyst II

AMD
09.2022 - Current

Security Operations Analyst

Xilinx, Inc
05.2019 - 08.2022

Security Operations Intern

Xilinx, Inc
06.2018 - 05.2019

Master of Applied Computing -

University of Windsor

Bachelor of Technology - Information Technology

SRM University
Yash Deep Sodhi