Azaz Ahmed, Technical Lead

Azaz Ahmed

Technical Lead

STMicroelectronics

Location
India - Delhi
Education
Bachelor's degree, INFORMATION SYSTEM & CYBER SECURITY
Experience
14 years, 6 Months

Share My Profile

Block User


Work Experience

Total years of experience :14 years, 6 Months

Technical Lead at STMicroelectronics
  • India - Delhi
  • My current job since December 2014

The group ICT Risk Management, Compliance & Information Security - In-Charge of making sure that ICT-related risks are identified & kept within accepted limits, ICT Compliance with Sarbanes Oxley and ISO/TS, PCIDSS & information security management in ST.
•Manage the solutions in place for IT Infrastructures, AWS Cloud - Security Vulnerabilities and Compliance.
•Run the security testing service for IT infrastructures, DevOps.
•Run the compliancy service for IT infrastructures, DevOps.
•Internal IS Auditor.
•Performing- Internal Security Assessments Projects i.e for GSMA -STMicroelectronics Becomes First Chip Maker Accredited by the GSMA to Personalize eSIMs for Mobiles and Connected IoT Devices.
•Define and maintain technical compliancy policies to controls for Sarbanes Oxley.
•Define and maintain technical compliancy policies to security standards. Propose review/evolution of those standards.
•Support Teams to solve the security vulnerabilities or compliance gaps detected.
•Advice Designs in Security Solutions like Encryption and Advising Future needs information to Higher Management.
•Push and follow-up until resolutions of the security vulnerabilities or compliance gaps.
•Define and maintain the dashboard/Score Card for IT infrastructures security vulnerabilities and Security compliance, and use it to report and advise management.
•Define and provide any on-demand specific reports.
•Reduction of False Positives Case and Producing POC Evidence.
•Conducting Root Cause Analysis.
•To Study the current infrastructure status and proposing strategy for the Risk Management to get ready for Next Year Plan to C-level Management.
•Conducting Training Sessions for Technical Teams.
•Bug Reporting

Security Analyst at British Telecommunication
  • India
  • June 2012 to December 2014

Manual and automated assessment of Infra / web applications.
•Conducting web application security, network security and OS audit assessments.
•External and internal penetration testing assessments.
•Device/Host Security Configuration Review.
•Test plans creation.
•Firewall rule set review.
•Presenting to Top-Level management

Security Consultant at Paladion Networks
  • India
  • July 2011 to June 2012

Manual and automated assessment of web applications.
•External and Internal penetration testing assessments.
•Android application security assessment.
•Conducting physical security and Social Engineering assessments.
•Wireless security assessment.
•Threat Profiling.
•Risk assessment.
•Compiling CVE, CVSS scoring and CWE sheet based on the vulnerabilities.
•Mentoring teams’ members and report reviewing.
•Carrying out technical interview for recruitment process

Security Engineer at HCL Comnet Ltd
  • India
  • May 2010 to June 2011

Provide technical support services based on proven methodologies on complete range of Firewalls of Cisco, Checkpoint.
•Configure Policies and NAT on Checkpoint firewall, Cisco PIX/ASA to provide access of external network through firewall

Trainee at ACTS-CDAC
  • India
  • September 2009 to February 2010

Post Graduate Diploma in Information Systems & Cyber Security.
•Threat Profiling.
•Test plan creation.
•Conducting web application security and network security assessments.
•Carrying out forensics using FTK toolkit.

Education

Bachelor's degree, INFORMATION SYSTEM & CYBER SECURITY
  • at ACTS, C - DAC
  • January 2010

in

Bachelor's degree, Computer Science
  • at Institute of Engineering & Technology, Bundelkhand University
  • January 2009

in with Specialization

Specialties & Skills

Information Security Management
ISO Auditor
PCI DSS
Vulnerability Management
Risk Management
NETWORK SECURITY
POLICY ANALYSIS
CRYPTOGRAPHY
FIREWALLS
INFORMATION SECURITY
MICROSOFT ACCESS
NETWORKING
IT Audit
Risk Management
Vulnerability Managemnt

Social Profiles

Personal Website
Personal Website

URL removed due to policy violation. Please contact support for further information.

Languages

English
Expert
Hindi
Expert
Urdu
Expert

Training and Certifications

P.G Diploma in INFORMATION SYSTEM & CYBER SECURITY (Training)
Training Institute:
ACTS, C - DAC, Pune
Date Attended:
September 2009
Juniper Networks Certified Internet Specialist, (JNCIS) (Certificate)
Juniper Networks Certified Internet Associate, (JNCIA) (Certificate)
Cisco Certified Network Associate-Security, (CCNA-Security) (Certificate)
Cisco Certified Network Associate (CCNA) (Certificate)
Checkpoint certified security administrator (CCSA) (Certificate)
Qualys Certified Specialist Cloud Agent (Certificate)
Qualys Certified Specialist Scanning Strategies and Best Practices (Certificate)
Qualys Certified Specialist PCI Compliance (Certificate)
QualysGuard Certified Vulnerability Management Specialist (Certificate)
Certified Ethical Hacker (CEH v8). (Certificate)
ISACA-CSX-Cybersecurity Fundamentals Certificate (Certificate)
ISACA-CISA – Certified Information Systems Auditor (Certificate)

Hobbies

  • Playing football, Chess, Computer games, cooking, listening to Music, Social service, I have a Knack
    Trainer- NGO- http://www.stfoundation.org/digital-unify/ - Providing Free Computer Training. Won one Gold medal in NCC with B Certificate. Won price in Science exhibitions. Won prizes in GK competition at State level. Training in Nagrik-Suraksha-Core Moradabad. Participated in Scorpio speedster. Played at district level in football.