Stuart Naveran
********@**********.*** • linkedin.com/in/stuartnaveran
CyberArk Automation Engineer
I am a technically sophisticated, certified Identity and Access Management Security Architect and Engineer with over 3 decades of experience in IT in hands-on technical roles requiring me to take enterprise projects from design, implementation, documentation, education and into operational support. I've resolved 95% of open access risk and reduced security risk by 93% in less than one year. Exceptional analytical problem-solving, people management, leadership and coaching skills. Self-motivated, team-oriented, and constantly strive for self-improvement. I currently hold or have held these certifications: CISSP,MCSE,CNE,CyberArk Defender(PAM-DEF),Splunk,IBM(ISAM),AWS-CCP,Varonis- DATAdvantage,BigID. I am always pursuing additional educational opportunities to further my technical knowledge and expertise.
WORK EXPERIENCE
BNY-Mellon • Woodland Park, NJ • 10/2022 - 11/2023 Senior Security Analyst
The Cooperators Group LImited • REMOTE • 01/2022 - 10/2022 Senior Security Analyst • Full-time
KPMG US • Montvale, NJ • 04/2012 - 07/2020
Manager – Architecture, Engineering, Operations • Full-time Updated Access Hub workflows and forms for Symantec PAM resources. Provided mentorship and guidance to peers. Facilitated collaborative and knowledgeable team working environments.
•
Designed seamless root account vault access and password management across 16 Linux VMWare hosts using CA/Symantec PAM in 3 months, ensuring compliance with security policies. Achieved A2A privileged secure safe access.
•
• Skills: Symantec PAM, Python, Hitachi PAM. Python. Eliminated security risk by 93% in 1 year by identifying and resolving open access permissions on 500k folders, resulting in improved data protection and confidentiality.
•
Ran SPHEREBoard Data Governance access review campaigns for 6 months, resolving 95% of excessive access and non-standard permissions, leading to streamlined annual recertification.
•
• Skills: Powershell, Varonis, BigID, SQL, Data Analysis, Data Governance, Camtasia Automated and monitored the ISAM architecture infrastructure for KPMG US, KPMG Global and DR, supporting 250k+ users. Achieved ISAM/Azure Integration in the POC environment.
•
Spearheaded the successful implementation of remote syslog forwarding (RSF) of all ISAM appliance logs to Splunk leading to a 25% improvement in threat detection and response.
•
Access Manager Consultant
NYPD • 10/2010 - 03/2012
Identity and Access Management Consultant
SAIC • 09/2008 - 09/2010
Identity and Access Management Consultant
Circuit City Stores Inc • 05/2008 - 08/2008
Security Consultant
City of New York • 11/2006 - 04/2008
Security Consultant
Legg Mason • 12/2005 - 11/2006
Access Manager Architect
Enhanced access management strategy by integrating CyberArk with ISAM appliances, enabling seamless SSO for administrators and improving overall secure access in 3 months.
•
Skills: Identity and Access Management (IAM), Azure AD, CyberArk, Splunk, Automation, Cybersecurity, Information Security. Risk Mitigation. Vulnerability analysis.
•
Crafted a tailored monitoring solution utilizing Powershell and REST API, resulting in a 100% improvement in alerting of access management processes.
•
Provided team leadership, direction and peer mentoring. Pulled into high priority issues to provide guidance and advisories as well as problem resolution. Interfaced with other technology groups.
•
In 18 months, with a high performance team, streamlined KPMG's access management system, upgrading TAMeBv6 to ISAM 9, improving the firm's security posture by 25%.
•
Skills: IBM Security Access Manager (ISAM), cross-team collaboration, team leadership, Powershell, REST API calls, SAML, Incident Management.
•
Upgraded IBM Tivoli Identity Manager (ITIM) from 4.6 to 5.1, improving access management policy and procedure capability and ensuring seamless functionality and security across multiple platforms.
•
Advisory work: planned the transition from Tivoli Access Manager to Tivoli Identity Manager, analyzing business requirements, enabling seamless user provisioning for a user population growth from 60k to 160k.
•
Implemented IBM’s Tivoli Access Manager for Operating Systems on HP-UX and Solaris, ensuring PCI compliance and auditing on 26 servers, safeguarding 10+ billion in annual sales.
•
Collaborated with a high-performing team on the successful implementation of IBM Tivoli Access Manager for e-Business in a SUN Solaris UNIX environment.
•
Customization of Perl scripts automating TAM authorization through RBAC, streamlining access management processes and reducing manual errors by 50%.
•
Led the implementation of IBM Tivoli Access Manager for e-business (TAMeBv6.0) in a Windows Server 2003 environment with an External Authentication Interface (EAI).
•
Marsh & McLennan Companies Inc. • 12/2003 - 11/2005 Systems Engineer, Security Specialist
EDUCATION
Bachelor of Arts (BA) in Industrial Relations (Minor: Computer Science) McGill University • 01/1984 - 12/1987
CERTIFICATIONS
CyberArk Defender (PAM-DEF) • 06/2024 - Present
CyberArk
Certified BigID Associate Admin • 07/2023
BigID University
Varonis Certified Administrator, DatAdvantage • 11/2022 Varonis
Amazon AWS CCP (Certified Cloud Practitioner) • 08/2022 Amazon
CyberArk Trustee Certification • 10/2018
CyberArk
CISSP • 08/2003 - 04/2018
ISC2
SKILLS
Enhanced security and efficiency by automating backup and restore of all TAM components, and creating detailed technical documentation.
•
Served as the SME for the setting up and implementation of IBM TAMeB v5.1 in a mixed Windows Server 2003 and Solaris 8 environment, with F5 Big IP load balancers, Multi- Master LDAP Replication.
•
• AWS
• Azure
• Bash
• CISSP
• Conjur
• CPM
• CyberArk
• DLP
• Encryption
• IAM
• ISAM
• Kanban
• LDAP
• Linux
• MFA
• Migration
• Nessus
• OAUTH
• OKTA
• PAM
• Ping Identity
• PKI
• Powershell
• PSM
• Python
• RBAC
• REST APIs
• SAML
• Secrets
• SIEM
• SQL
• SSO
• Unix
• Zero trust