VINOD JOSEPH, Cyber Security Consultant

VINOD JOSEPH

Cyber Security Consultant

Toronto Hydro Corporation

Location
Canada
Education
Master's degree, CCIE -SECURITY
Experience
19 years, 1 Months

Share My Profile

Block User


Work Experience

Total years of experience :19 years, 1 Months

Cyber Security Consultant at Toronto Hydro Corporation
  • Canada - Ontario
  • My current job since May 2016

Handled numerous Cybersecurity Operations and consulting projects/activities across leading technologies and frameworks for securing Critical Infrastructure. This includes:

 Cisco Next Generation Firewall/IPS implementations, Advanced Malware protections using Cisco AMP, FireEye Web MPS (NX), Email Gateway evaluations ( Cisco, Forti Mail and Proofpoint ), Data Loss Prevention Implementations, Threat Intelligence Platform evaluations and implementations, ICS/OT anomaly detection using claroty CTD, McAfee ecosystems implementations for perimeter security stack including Intrushield NGIPS/IDS & NTBA, Fortinet Security Fabric and Internal Segmentation Firewalls, DNS Security Services using Infoblox, Infrastructure Security Implementation using Cisco IOS Security Features (Cisco IPSEC VPNs, Snort ), NGIPS implementations using ScreenOS/JUNOS SRX Firewalls, McAfee ePO for endpoint security Implementation and optimization of Citrix NetScaler ADC and NetScaler Gateway and WAF, Cisco AnyConnect and NetMotion Mobility clients for remote access VPNs, Implementation of Cisco Clean Access (NAC) & 802.1x, Vulnerability Management using Tenable Nessus, Rapid7 Nexpose, Gigamon/GigaSmart SSL proxy, Bluecoat ProxySG Web Security, and Riverbed WAN Accelerators etc.

 Information Security Governance Implementations experiences based on ISO/IEC 27001:2005 framework for a Bank in Middle East across the IT Department during Year 2007.

 Handled critical network Security consultation & implementation projects for financial institutions - including designing & implementing security architecture for Campus & Corp networks based on a layered defense model, designing secure perimeter with advanced threat controls, Web application & Mobile application Infrastructure design, Datacenter Security with Secured multi-tenancy, Endpoint Security Management, Vulnerability Management and configurations compliances framework etc.

 Designed and Implemented security controls including PaloAlto Firewalls PA3020, FortiGate 1000D, Cisco ASA 5525X- with IPS, Firepower FTD4120, Juniper SRX 650 with Chassis Clusters, F5 LTM, Cisco FWSM, Citrix Netscaler MPX-5500/VPX & Sourcefire 3D Sensors with Fire Sight Defense Center .

 Managed numerous network infrastructure projects including Routing & Switching redesign, Datacenter architectures, secured Virtualized Multi-tenancy using Catalyst 6500/ASA-SM gears, large campus and lnternet facing Infrastructure based on various Cisco Routing and Switching components etc.

Chief Manager - Networks& Information Security at Bank Sohar SAOG, Muscat Oman
  • Oman - Muscat
  • March 2007 to March 2016

Designated as Chief Manager, I was managing a team of 5 members providing L2 & L3 Support for Network/Security operations. I also had indirect reporting of Security operation Center during this period. Have executed numerous projects and initiatives around DataCenter and Security Perimeter design/implementations using layered architecture, ISO/IEC 27001:2005 implementations and Certifications, Routing & Campus LAN design & implementations, Fortinet Firewalls, VDOMs and Fortinet Fabric, Cisco AnyConnect, Bluecoat SSL proxy, Juniper SRX NG Firewall/IDS, Cisco Sourcefire 3D Sensor (7120) with Firepower management console, IBM QRADAR SIEM, Citrix NetScaler MPX/VPX with AppFirewall, FireEye Web MPS and EX for combating advanced persistent threats, Web Sense proxy service etc.

Network Security Analyst at Bank Dhofar SAOG
  • Oman - Muscat
  • March 2005 to March 2007

• Implementations of Cisco ASA 5516-X Firewalls with Sourcefire Services using NGFW, IPS, AVC and AMP services
• BGP, VRF-Lite, IPSEC and UTM implementations for remote branches - Over 70 Locations( Juniper ISG/SRX )
• Firewall Migration for Netscreen SSG to Juniper SRX-650 for the Secured Perimeter
• Implementation of Group Encrypted Transport VPN (GDOI ) setup for MPLS Cloud with High-Availability measures
• Web Application Security Implementation for Mobile & E-Enabled Services using Citrix WAF, Netscaler ADC, SSL Offloading and Accelerations, Fortigate IPS & NG Firewalls, Juniper IPS/IDP, Netflow Aggregations and SIEM using IBM QRADAR
• Layer-2 Security Implementations across the Campus Network using 802.1x, Private VLANs, CoPP, iACLs, DHCP Snooping, Port Security, DAI, IP Source Guard, MKA Security and Cisco TrustSec etc.
• Rollout of Wan Optimization Project using Steelhead Riverbed across 100 locations
• MPLS VPN Implementations for branches using BGP, OSPF, DMVPN/GET VPN ( 70+ sites )
• Implementation of Identity Based Network Services - Cisco ACS and 802.1x based port based authentications
• IPv6 Implementations ( Piolet Project ) for web portals
• Vulnerability Management and Configuration Compliance Project - Using Tenable Security Center & Rapid7 Nexpose

Education

Master's degree, CCIE -SECURITY
  • at Cisco Certified Internet Expert / CCIE Security ( #23130)
  • January 2009

Cisco Certified Internet Expert (CCIE) - LAB exam cleared during Year 2009 ( Security Track)

Bachelor's degree, Bsc IT
  • at Karnata State Open University
  • March 2002

BSC-IT program with 6 Semesters

Higher diploma, Computer Engineering
  • at Board of Tech. Education, Govt. Of Kerala
  • March 1994

3 Year Polytechnic Diploma in Computer Engineering

High school or equivalent, Physics, chemistry, Maths & Computer Engineering
  • at MG University, Kottayam
  • June 1992

PRE-DEGREE COURSE (10+2 Equivalent)

Specialties & Skills

CCIE security
Information Security Management
CCIE Routing & Switching
Security Management
CISM - ISACA
CCIE-Security
Cisco, Juniper - Routing & Swicthing
SCADA Security - ICS, OT
NG Firewalls, Malware Protection systems, SSL Decryption
Routing - OSPF, BGP and ISIS
Endpoint Security - McAfee ePO, Symantec DCS
Certificate Authority - Mircosoft CA and IOS CA
SSL Offloading, Load Balancing & ADC, Content Switching
DNS Firewalls , DHCP and IPAM - Infoblox Grid
InfoSec Governance - ISO 27001, COBIT, PCI & NIST
Multi Factor Authentications - Entrust
SSL VPN - Cisco Anyconnect, Netscaler Access Gateway & Juniper SRX Pulse
Vulnerability Management - Nexpose, Metasploit, Nessuss, Kali
Web Application Firewalls - Citrix WAAS, F5 LTM
Web Application Security - HP Webinspect, Burp
Switching - STP, VTP, Catalyst & Nexus
Firewalls - Cisco ASA, FortiNet, Palo Alto & Juniper SRX
NG IPS - Cisco SourceFire, Juniper IDP, McAfee NSP and Snort
Visibility Fabric - Gigamon GigaVue
Global Server Load Balancing ( GSLB) - Citrix NetScaler
VPNs - IPSEC, IKEV2, SSLVPN, DMVPN,GET VPN, DVTI, GREoIPSEC
Data Leak Prevention - McAfee , Digital Guardian
Security Incident Mgmt & Threat Hunting - QRADAR , Tanium
DataCenter Switching - Nexus 7000, Nexus 5000 and Catalyst 6500
Security Onion - Zeek, BRO and SNort IDS
Malware Analysis & Threat Intel
Incident Response & NIST CSF
CIS Top 20 Critical Controls
OT Security - SCADA & ICS
Cyber Security Architecture
Next Generation IPS & Threat Hunting
Cyber Incident Response
DNP3, MODBUS
Threat Hunting and EDR
SIEM & SOAR Automation
OWASP & WebApp Security
CCIE, CEH, CISA, CISM ,CRISC, Cisco, Juniper, Palo Alto, Fortinet, FireEye, McAfee, Nexus

Languages

English
Expert

Memberships

ISACA - Toronto Chapter
  • Canada
  • December 2010

Training and Certifications

CCIE - Cisco Certified Internet Expert ( CCIE #23130) (Certificate)
Date Attended:
January 2009
Valid Until:
January 2009
CCNP - Cisco Certified Network Professional (Certificate)
CEH - Certified Ethical Hacking (Certificate)
CISM -Certified Information Security Manager (Certificate)
CCSP - Cisco Certified Security Professional (Certificate)