Azaz أحمد, Technical Lead

Azaz أحمد

Technical Lead

STMicroelectronics

البلد
الهند - دلهي
التعليم
بكالوريوس, INFORMATION SYSTEM & CYBER SECURITY
الخبرات
14 years, 6 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :14 years, 6 أشهر

Technical Lead في STMicroelectronics
  • الهند - دلهي
  • أشغل هذه الوظيفة منذ ديسمبر 2014

The group ICT Risk Management, Compliance & Information Security - In-Charge of making sure that ICT-related risks are identified & kept within accepted limits, ICT Compliance with Sarbanes Oxley and ISO/TS, PCIDSS & information security management in ST.
•Manage the solutions in place for IT Infrastructures, AWS Cloud - Security Vulnerabilities and Compliance.
•Run the security testing service for IT infrastructures, DevOps.
•Run the compliancy service for IT infrastructures, DevOps.
•Internal IS Auditor.
•Performing- Internal Security Assessments Projects i.e for GSMA -STMicroelectronics Becomes First Chip Maker Accredited by the GSMA to Personalize eSIMs for Mobiles and Connected IoT Devices.
•Define and maintain technical compliancy policies to controls for Sarbanes Oxley.
•Define and maintain technical compliancy policies to security standards. Propose review/evolution of those standards.
•Support Teams to solve the security vulnerabilities or compliance gaps detected.
•Advice Designs in Security Solutions like Encryption and Advising Future needs information to Higher Management.
•Push and follow-up until resolutions of the security vulnerabilities or compliance gaps.
•Define and maintain the dashboard/Score Card for IT infrastructures security vulnerabilities and Security compliance, and use it to report and advise management.
•Define and provide any on-demand specific reports.
•Reduction of False Positives Case and Producing POC Evidence.
•Conducting Root Cause Analysis.
•To Study the current infrastructure status and proposing strategy for the Risk Management to get ready for Next Year Plan to C-level Management.
•Conducting Training Sessions for Technical Teams.
•Bug Reporting

Security Analyst في British Telecommunication
  • الهند
  • يونيو 2012 إلى ديسمبر 2014

Manual and automated assessment of Infra / web applications.
•Conducting web application security, network security and OS audit assessments.
•External and internal penetration testing assessments.
•Device/Host Security Configuration Review.
•Test plans creation.
•Firewall rule set review.
•Presenting to Top-Level management

Security Consultant في Paladion Networks
  • الهند
  • يوليو 2011 إلى يونيو 2012

Manual and automated assessment of web applications.
•External and Internal penetration testing assessments.
•Android application security assessment.
•Conducting physical security and Social Engineering assessments.
•Wireless security assessment.
•Threat Profiling.
•Risk assessment.
•Compiling CVE, CVSS scoring and CWE sheet based on the vulnerabilities.
•Mentoring teams’ members and report reviewing.
•Carrying out technical interview for recruitment process

Security Engineer في HCL Comnet Ltd
  • الهند
  • مايو 2010 إلى يونيو 2011

Provide technical support services based on proven methodologies on complete range of Firewalls of Cisco, Checkpoint.
•Configure Policies and NAT on Checkpoint firewall, Cisco PIX/ASA to provide access of external network through firewall

Trainee في ACTS-CDAC
  • الهند
  • سبتمبر 2009 إلى فبراير 2010

Post Graduate Diploma in Information Systems & Cyber Security.
•Threat Profiling.
•Test plan creation.
•Conducting web application security and network security assessments.
•Carrying out forensics using FTK toolkit.

الخلفية التعليمية

بكالوريوس, INFORMATION SYSTEM & CYBER SECURITY
  • في ACTS, C - DAC
  • يناير 2010

in

بكالوريوس, Computer Science
  • في Institute of Engineering & Technology, Bundelkhand University
  • يناير 2009

in with Specialization

Specialties & Skills

Information Security Management
ISO Auditor
PCI DSS
Vulnerability Management
Risk Management
NETWORK SECURITY
POLICY ANALYSIS
CRYPTOGRAPHY
FIREWALLS
INFORMATION SECURITY
MICROSOFT ACCESS
NETWORKING
IT Audit
Risk Management
Vulnerability Managemnt

حسابات مواقع التواصل الاجتماعي

الموقع الشخصي
الموقع الشخصي

لقد تم حذف الرابط بسبب انتهاكه لسياسة الموقع. يرجى التواصل مع قسم الدعم لمزيد من المعلومات.

اللغات

الانجليزية
متمرّس
الهندية
متمرّس
الأوردو
متمرّس

التدريب و الشهادات

P.G Diploma in INFORMATION SYSTEM & CYBER SECURITY (تدريب)
معهد التدريب:
ACTS, C - DAC, Pune
تاريخ الدورة:
September 2009
Juniper Networks Certified Internet Specialist, (JNCIS) (الشهادة)
Juniper Networks Certified Internet Associate, (JNCIA) (الشهادة)
Cisco Certified Network Associate-Security, (CCNA-Security) (الشهادة)
Cisco Certified Network Associate (CCNA) (الشهادة)
Checkpoint certified security administrator (CCSA) (الشهادة)
Qualys Certified Specialist Cloud Agent (الشهادة)
Qualys Certified Specialist Scanning Strategies and Best Practices (الشهادة)
Qualys Certified Specialist PCI Compliance (الشهادة)
QualysGuard Certified Vulnerability Management Specialist (الشهادة)
Certified Ethical Hacker (CEH v8). (الشهادة)
ISACA-CSX-Cybersecurity Fundamentals Certificate (الشهادة)
ISACA-CISA – Certified Information Systems Auditor (الشهادة)

الهوايات

  • Playing football, Chess, Computer games, cooking, listening to Music, Social service, I have a Knack
    Trainer- NGO- http://www.stfoundation.org/digital-unify/ - Providing Free Computer Training. Won one Gold medal in NCC with B Certificate. Won price in Science exhibitions. Won prizes in GK competition at State level. Training in Nagrik-Suraksha-Core Moradabad. Participated in Scorpio speedster. Played at district level in football.