Post Job Free
Sign in

Information Security Management

Location:
Halifax, NS, Canada
Posted:
June 24, 2020

Contact this candidate

Resume:

MANINDER SINGH

Montreal, QC 902-***-**** ********.*********@*****.***

LinkedIn URL - www.linkedin.com/in/Maninder-Singh1

Certification

CCNA (Routing & Switching)

CCNA Security

CISSP, CISA/CISM awaiting examination

Work History

Cyber Security Analyst Feb 2020 – Jun 2020

Air Canada Montreal, Canada

Contribute to the development documentation, monitoring and maintenance of information security standards, policies, and protocols to ensure organizational infrastructure, data and resources are protected from unauthorized and inappropriate use or access.

Third Party Risk Management Information Security practices related to supplier onboarding, continuous monitoring, and issue management using SPAR(Supplier portal for accessing Risk).

Provide expertise in the definition, selection and implementation of IT Security related controls to the IT Department and advise on meeting compliance with information security policies and procedures.

NIST SP 800-53, PCI-DSS, ISO 27001, GDPR, HIPAA, PIPEDA, SOX, COBIT5 based firm Security Policies and industry standards regulations are followed for compensating relevant security controls for regulatory compliance requirements and guidelines.

Coordinate with operational groups and business units to set up and implement identity and access management measures to prevent or detect security incidents or breaches.

Generate security reports for IT administrators and business managers to evaluate the efficacy of systems security and policies.

Collaborate with system administrators to ensure that appropriate controls are installed, operating properly, in accordance with the corporate policies. Conduct periodic audit.

Track risks and various action plans using the Air Canada GRC tool (Archer).

Support the business initiatives, RFP process, Agile, Lean, Rapid Labs and other accelerated projects and making sure any IT specific risk introduced is properly managed.

Identify IT risks, communicate and develop “best practices” solutions, and implement mitigating controls consistent with company strategy.

Plan, coordinate and oversee activities related to the design, development and integration of information systems, operations systems and reporting systems in a business or security or risk context

Work with the vendor’s teams (business and technical) to establish and review policies and IT direction.

Perform project reviews to ensure that they align to Air Canada’s business/ information security requirements and project management policies.

Senior Information Security Analyst Sep 2019 – Jan 2020

NTT Data Services (Morgan Stanley) Halifax, Canada

Conducting IT Risk Assessments including technical assessment, vendors assessment, network security for vulnerability management, Information Risk and Technology Risk Management for fortune 500 clients (Banking) and vendors for Morgan Stanley.

Provide resolution for the security vulnerabilities in platform, application, various ICT architecture / network design and information systems security risks and identify the potential threats and exposures.

Risk management of the various data exposure by ensuring proper security controls, data analytics and data exploration to prevent any type of potential data leakage.

NIST and PCI-DSS based firm Security Policies and standard regulation are followed for compensating relevant security controls for regulatory compliance requirements and guidelines.

ISO 27001, COBIT frameworks and global security or network management strategies are used for IT governance.

Provide amendments to the existing firm Security Policies and assist in the development and documentation for new firm Security Standards in order to improve the existing security controls.

Worked on the security information and event monitoring systems (SIEM), firewalls, network and host intrusion prevention and detection systems, proxies, vulnerability scanners, and anti-virus solutions.

Worked on the firewall inbound and outbound tickets through ServiceNow to make a check on Defense in Depth.

Use Open Pages (IBM) to keep a track the various action plans for risk mitigation and remediation plans and remediation strategy.

Assist in developing, implementing, and maintaining Information Security Management System (ISMS with applicable security policies, processes, and practices)and to ensure ISO 27001 compliance.

Manage access control design of one or more applicable security technologies or platforms including MFA, SSO (Single Sign On) technologies like SAML2.0 and Kerberos and mitigate technology risks including XSS, CSRF, Injection attacks and all the risks listed in the OWASP Top 10.

System configuration Analyst (Information Security) Jul 2016 - Sep 2017

Aon Hewitt Gurgaon, India

Conducting risk and vulnerability assessments, leading audit review, developing project plans, and risk mitigation strategies among cross-functional project teams for US based client and federal government including SEC/CES.

Support the maintenance of a global information security and risk management policy set, including industry standards such as COBIT, ISO 27001, ISO 27002, and NIST Cyber Security Framework (CSF).

Conduct risk and privacy impact assessments to information systems and business processes to Implement risk treatment plan.

Manage the various information security control technologies including access control, cryptography, vulnerability management, SIEM/log management, ID/IPS, and penetration test.

Working knowledge of network protocols, DNS, and networking devices – switches, routers, VPNs, proxies, firewalls. And System hardening skills on information technologies including Linux, Windows, VMWare, MySQL, MSSQL, Oracle, etc.

Provide resolution for the security vulnerabilities in platform, application, various architecture / network design and information security risks and identify the potential risks and exposures.

Create action Plans standards and roadmaps for hardware and software and decide how Security infrastructure is build and recommend standards for risk mitigation strategies using Open Pages (IBM).

Assist with scoping prospective engagements, participating in investigations from kickoff through remediation, mentoring less experienced staff, and review assessments for the peers.

Reviewing assessment for the peers to ensure all the access controls and security controls are in place and no data is compromise that may leads to data exposure.

Information Security Consultant Aug 2014 - Jul 2016

Integrated Technologies Delhi, India

Creating comprehensive security architecture assessment reports to identify the vulnerabilities and create remediation strategies by using compensating security controls, Identity and Access Management and other information security elements.

Conduct IT Risk assessment to information systems and business processes, develop IT policies and procedures, and provide improvement recommendations to current policies and procedures.

Collaborate with system administrators to ensure that appropriate controls are implemented, operating properly, in accordance with the corporate policies.

Conduct audit readiness assessments and coordinate with internal and external functions and audit resources.

Provide technical consulting services to clients on the network security controls required for the development of enhancements and the implementation of new and/or ongoing business units.

Evaluating the new and emerging products and technologies and make recommendations or requirements before deploying in Prod for risk management of information system.

Investigate events or incidents of apparent security breaches and report to appropriate authorities using corporate procedures.

Evaluating the new and emerging products and technologies and make recommendations or requirements before deploying in Prod for risk management.

Hands on in Investigating security breaches and other cyber security incidents, provide support to the incident response team and conduct security awareness end user training.

IT Support Specialist (IT Admin) Jan 2018 – Aug 2019

Dalhousie University Halifax, NS

Provide Online or on-call support to the customers Regarding Phishing/ Hacking/ or any other Technical Queries and report those incidents through tickets on an online Ticketing System such as BMC Ticketing System i.e. Footprints Ticketing System.

LAN account administration on multiple domains, including creation, modification and deletion of IDs, adhering to specified approval processes.

Articulate with different entitlements Platforms for Identity access management.

Handles the password resetting and privileges for the different users in the LDAP groups.

Troubleshooting and management control of various web services and applications such as learning management system (D2L Brightspace), and over 180 workstations. Also managed Wi-Fi troubleshooting.

Education

Masters of Engineering: Internetworking (Computer Science) Sep 2017-May 2019

Dalhousie University Halifax, NS

Skills

Networking: Routing, Switching, TCP/IP, VLAN, DNS, DHCP, VPN, OSPF, BGP, MPLS, IPv6, IPv4, RIPv2, LAN, WAN, DMVPN, IPsec, VoIP, SMTP

Security: Firewalls, ACL, IPsec, IDS/IPS, VPN, NAT, HTTP, HTTPS, SSL/TLS, SSH, SSO, OAuth 2.0, OpenID Connect, SAML, Kerberos, SPNEGO, OWASP Top 10, SFTP, SIEM, IPS/IDS, PMP, MIS, proxies, vulnerability scanners, SOX, DLP/FIM, SIEM

Programming: C++, SQL, JavaScript, HTML, MySql, Linux, and Python

Virtualization: Vmware, Virtual box

Operating systems: Windows, Linux, Unix, MacOS

Others: MS office, MS Excel, Oracle, MySql, LDAP, KPIs, SDLC, Agile, MS terminal services, ITIL, SDLC, Citrix XenApp client, Logic Monitor, Sophos/Fortinet Firewall, AWS, Qradar, ERP, Open Pages, Archer, ServiceNow

Interpersonal Skills

Demonstrate good analytical skills, leadership abilities, Innovative, committed, motivated, attention to detail and always passionate towards work.

Ability to work under pressure, tight deadlines, work independently, facilitate discussion, decision-making, friendly, approachable demeanor, and problem solving ability.

Strong verbal and written communication skills, presentation skills, and able to engage and effectively respond to diverse stakeholders with strong collaboration.

Ability to rapidly build a relationship and set up trust among the new people and enthusiastic to grow with the team collaboration.

Analytical vision with the ability to develop strategic direction, anticipates and reduces complexity for others.



Contact this candidate