As Deputy Manager focused on Application Security, I oversee end-to-end security compliance, application security initiatives, and process improvements, ensuring robust defense mechanisms for critical applications. My role involves managing the lifecycle of SSL certificates, monitoring Web Application Firewalls (WAF), conducting vulnerability assessments, and ensuring adherence to both internal and external security compliance standards.
Key Responsibilities:
Compliance Assurance & Security Audits
Ensure adherence to statutory compliance timelines for application security. Actively participate in internal and external audits, addressing audit observations promptly to maintain 100% compliance. Contributed to the documentation of security reviews and compliance reports.
Application Security Management
Monitor Vendor SLA adherence for security tools and services, ensuring compliance with contractual obligations. Manage IT service/security reports, delivering them on time in the agreed format. Maintain up-to-date Application and Certificate Inventory, conducting quarterly reconciliation of Web Application Firewalls (WAF) and applications. Reduced attacks on web applications by 97% through the creation and implementation of efficient custom WAF rules and security policies. Managed and monitored Web Application Firewalls (Indusface WAF, Cloudflare, AWS WAF, AWS Shield), including traffic analysis, custom rule creation (DoS, DDoS, rate limiting, geofencing), and blocking malicious traffic.
Security Initiatives & Process Improvement
Led monthly information security initiatives, ensuring timely completion within defined timelines. Achieved a 75% reduction in workload by automating security processes, streamlining vulnerability management and SSL certificate lifecycle management. Played a key role in increasing the organizations security posture score by 50 points by controlling attacks, creating security policies, and remediating vulnerabilities.
Vulnerability Assessment & Penetration Testing (VAPT) and Management
Led a team to conduct comprehensive Vulnerability Assessment & Penetration Testing (VAPT), ensuring continuous identification and swift mitigation of application vulnerabilities. Managed the vulnerability resolution process, overseeing remediation efforts and guiding development teams on best practices. Enhanced security posture by optimizing automated vulnerability management processes, resulting in improved detection and faster remediation cycles.
Recognition & Achievements
Consistently achieved 100% compliance in patch management for servers and applications, earning multiple company awards for timely patch management. Provided 24/7 IT Security Support, including Emergency Response Team (ERT) coordination.
Traffic Analysis & Process Automation
Innovated through the automation of security processes, increasing efficiency and accuracy in vulnerability management and traffic monitoring. Led the Emergency Response Team (ERT) in mitigating live attacks and managing post-attack remediation, ensuring minimal downtime and safeguarding critical business functions.
- Company industry:
- Retail & Wholesale
- Job role:
-
Information Technology