AWS Certified Solution Architect with 11+ years in Cloud Security, Network Security, and Automation. Expert in IaC, threat detection, and incident response for enhanced organizational resilience.
PROFESSIONAL EXPERIENCE
Senior Security Engineer
Microsoft | Jan 2023 - Present
Devised Cloud Workload Protection strategies for AWS, Azure, and GCP, ensuring compliance with security standards and best practices.
Implemented network security measures using Azure Virtual Network Manager, Azure firewalls, and network segmentation to protect critical workloads.
Developed and maintained secure CI/CD pipelines with IaC, ensuring consistent and secure infrastructure deployments.
Created and executed security automation scripts using Python, enhancing operational efficiency and incident response capabilities.
Senior Cybersecurity Engineer
Visa | Jan 2022 - Nov 2022
Designed, deployed, and managed global Public and Hybrid Cloud security infrastructure, including assessment, implementation, and automation.
Integrated cloud platforms with various security services, including CSPM, CASB, SIEM, and vulnerability management, to enhance security posture.
Developed Guard Rails and custom Lambda Scripts for CIS Benchmark testing on AWS services, improving compliance and security oversight.
Conducted vulnerability scans and reported findings, collaborating with stakeholders to address misconfigurations and track remediation.
Cloud Security Engineer
Various Projects | Sep 2013 - Jan 2022
Conducted comprehensive security reviews and threat modeling for AWS, Azure, and GCP, including container and microservice architectures.
Implemented secure design patterns for cloud security, container security, and Infrastructure as Code (Terraform), and developed security tools and processes.
Provided technical guidance for addressing security risks, managed AWS infrastructure security, and focused on security engineering, DevSecOps, and application security.
Developed threat models, security design guidance, and utilized Suricata Network IDS for improved threat detection and minimal false positives.
Implemented Security Incident Management, addressing incidents with tools like Crowdstrike and SIEM, and performed network analysis using Wireshark.
Authored incident reports, compliance documentation, and runbooks, and led statistical analysis for continuous improvement and operational effectiveness.
Troubleshot and optimized server/network performance across Yahoo!'s global infrastructure, collaborated with teams for issue resolution, and used Unix/Linux for system management.