Post Job Free
Sign in

SME-Identity & Access Management (IAM)

Location:
Wayne, NJ
Posted:
June 18, 2024

Contact this candidate

Resume:

Stuart Naveran

********@**********.*** • linkedin.com/in/stuartnaveran

CyberArk Automation Engineer

I am a technically sophisticated, certified Identity and Access Management Security Architect and Engineer with over 3 decades of experience in IT in hands-on technical roles requiring me to take enterprise projects from design, implementation, documentation, education and into operational support. I've resolved 95% of open access risk and reduced security risk by 93% in less than one year. Exceptional analytical problem-solving, people management, leadership and coaching skills. Self-motivated, team-oriented, and constantly strive for self-improvement. I currently hold or have held these certifications: CISSP,MCSE,CNE,CyberArk Defender(PAM-DEF),Splunk,IBM(ISAM),AWS-CCP,Varonis- DATAdvantage,BigID. I am always pursuing additional educational opportunities to further my technical knowledge and expertise.

WORK EXPERIENCE

BNY-Mellon • Woodland Park, NJ • 10/2022 - 11/2023 Senior Security Analyst

The Cooperators Group LImited • REMOTE • 01/2022 - 10/2022 Senior Security Analyst • Full-time

KPMG US • Montvale, NJ • 04/2012 - 07/2020

Manager – Architecture, Engineering, Operations • Full-time Updated Access Hub workflows and forms for Symantec PAM resources. Provided mentorship and guidance to peers. Facilitated collaborative and knowledgeable team working environments.

Designed seamless root account vault access and password management across 16 Linux VMWare hosts using CA/Symantec PAM in 3 months, ensuring compliance with security policies. Achieved A2A privileged secure safe access.

• Skills: Symantec PAM, Python, Hitachi PAM. Python. Eliminated security risk by 93% in 1 year by identifying and resolving open access permissions on 500k folders, resulting in improved data protection and confidentiality.

Ran SPHEREBoard Data Governance access review campaigns for 6 months, resolving 95% of excessive access and non-standard permissions, leading to streamlined annual recertification.

• Skills: Powershell, Varonis, BigID, SQL, Data Analysis, Data Governance, Camtasia Automated and monitored the ISAM architecture infrastructure for KPMG US, KPMG Global and DR, supporting 250k+ users. Achieved ISAM/Azure Integration in the POC environment.

Spearheaded the successful implementation of remote syslog forwarding (RSF) of all ISAM appliance logs to Splunk leading to a 25% improvement in threat detection and response.

Access Manager Consultant

NYPD • 10/2010 - 03/2012

Identity and Access Management Consultant

SAIC • 09/2008 - 09/2010

Identity and Access Management Consultant

Circuit City Stores Inc • 05/2008 - 08/2008

Security Consultant

City of New York • 11/2006 - 04/2008

Security Consultant

Legg Mason • 12/2005 - 11/2006

Access Manager Architect

Enhanced access management strategy by integrating CyberArk with ISAM appliances, enabling seamless SSO for administrators and improving overall secure access in 3 months.

Skills: Identity and Access Management (IAM), Azure AD, CyberArk, Splunk, Automation, Cybersecurity, Information Security. Risk Mitigation. Vulnerability analysis.

Crafted a tailored monitoring solution utilizing Powershell and REST API, resulting in a 100% improvement in alerting of access management processes.

Provided team leadership, direction and peer mentoring. Pulled into high priority issues to provide guidance and advisories as well as problem resolution. Interfaced with other technology groups.

In 18 months, with a high performance team, streamlined KPMG's access management system, upgrading TAMeBv6 to ISAM 9, improving the firm's security posture by 25%.

Skills: IBM Security Access Manager (ISAM), cross-team collaboration, team leadership, Powershell, REST API calls, SAML, Incident Management.

Upgraded IBM Tivoli Identity Manager (ITIM) from 4.6 to 5.1, improving access management policy and procedure capability and ensuring seamless functionality and security across multiple platforms.

Advisory work: planned the transition from Tivoli Access Manager to Tivoli Identity Manager, analyzing business requirements, enabling seamless user provisioning for a user population growth from 60k to 160k.

Implemented IBM’s Tivoli Access Manager for Operating Systems on HP-UX and Solaris, ensuring PCI compliance and auditing on 26 servers, safeguarding 10+ billion in annual sales.

Collaborated with a high-performing team on the successful implementation of IBM Tivoli Access Manager for e-Business in a SUN Solaris UNIX environment.

Customization of Perl scripts automating TAM authorization through RBAC, streamlining access management processes and reducing manual errors by 50%.

Led the implementation of IBM Tivoli Access Manager for e-business (TAMeBv6.0) in a Windows Server 2003 environment with an External Authentication Interface (EAI).

Marsh & McLennan Companies Inc. • 12/2003 - 11/2005 Systems Engineer, Security Specialist

EDUCATION

Bachelor of Arts (BA) in Industrial Relations (Minor: Computer Science) McGill University • 01/1984 - 12/1987

CERTIFICATIONS

CyberArk Defender (PAM-DEF) • 06/2024 - Present

CyberArk

Certified BigID Associate Admin • 07/2023

BigID University

Varonis Certified Administrator, DatAdvantage • 11/2022 Varonis

Amazon AWS CCP (Certified Cloud Practitioner) • 08/2022 Amazon

CyberArk Trustee Certification • 10/2018

CyberArk

CISSP • 08/2003 - 04/2018

ISC2

SKILLS

Enhanced security and efficiency by automating backup and restore of all TAM components, and creating detailed technical documentation.

Served as the SME for the setting up and implementation of IBM TAMeB v5.1 in a mixed Windows Server 2003 and Solaris 8 environment, with F5 Big IP load balancers, Multi- Master LDAP Replication.

• AWS

• Azure

• Bash

• CISSP

• Conjur

• CPM

• CyberArk

• DLP

• Encryption

• IAM

• ISAM

• Kanban

• LDAP

• Linux

• MFA

• Migration

• Nessus

• OAUTH

• OKTA

• PAM

• Ping Identity

• PKI

• Powershell

• PSM

• Python

• RBAC

• REST APIs

• SAML

• Secrets

• SIEM

• SQL

• SSO

• Unix

• Zero trust



Contact this candidate