Waseem Mohammed Abdul
**** ***** **** ** #*** Houston, TX 77054
**************@*****.***
CAREER OBJECTIVE:
Results-oriented IT Security professional with 8+ years of work experience. Aiming to leverage my Security experience and a proven knowledge of system administration, SIEM management and infrastructural engineering.
APPLICATIONS:
Red Hat, Centos, AWS, Veritas Volume Manager, Apache, Tomcat, Jboss, NetBackup, IBM Endpoint manager, Splunk Phantom, Splunk Enterprise Security, Puppet, Jenkins, Jira, Confluence, Regex, Vagrant, Nagios, GIT, Regex, VMware, Linux, Remote Desktop, JON, Remedy, OSSEC, Microsoft teams, IDS/IPS, Hip chat, Slack, Wireshark, Zscalar, Proofpoint, Crowd Strike, Carbon Black, Kubernete,Azure, McCaffe, Google Cloud, PAN, ATP,SIEM
SCRIPTING LANGUAGES:
Bash Scripting Phython
CREDENTIALS AND LICENSES:
Certified Splunk Administrator (Expired) Reappear.
Certified Splunk Enterprise Security Administrator.
Certified Splunk Power User.
Certified Splunk User.
Advanced Splunk Power User(InProgress).
ScrumITILCEHin Progress) DevOps Generalist Sec.
EDUCATION:
Master of Science in Information Technology Management
Campbellsville University
Kentucky, July 2015 to July 2016
Degree :Bachelor in computer science
Osmania University
Hyderabad, 2005-2009
PROFESSIONAL EXPERIENCE
Amerihealth Caritas
Philadelphia, PA
Splunk Engineer (Security/Admin) Sept 2019 – Present
Onboarding and analyzing new data source into Splunk.
Reviewed indexing capacity and provide a capacity (retention) planning strategy.
Reviewed customer data source and mapped them accordingly.
Documented standard operating procedures (SOP) for deploying and running Splunk. instances on Cloud services (AWS).
Responding to different notables and investigate same.
Provide assistance with the creation of splunk search queries and dashboard.
Performed technical assessment on existing Splunk environment.
Splunk environment health check.
Use Case SOP and development.
Create, optimize and continuous evaluation of Alerts and security Contents.
Multisite clustering troubleshooting.
Developing visual dashboard for Metrics
Bucket troubleshooting.
Reviewed existing data onboarding procedures to ensure adherence with Splunk best practices.
Reviewed indexing performance within Splunk environment.
Reviewed license utilization within Splunk environment.
Reviewed forwarder configuration within the Splunk environment.
Installed, configured and tuned up Splunk instances.
Conducted Splunk data onboarding & parsing process and walked customer through best practices.
Data source configuration including.
Familiar with LDAP Authentication set up with Splunk
Engineering of systems administration-related solutions for various project and operational needs
Doing data CIM mapping to available data model in ES.
Creating and manage Datamodel.
Mapping data to multiple data model for proper use case generation on Splunk enterprise security.
Modifying, disabling and enabling use cases in Splunk ES.
Managing access to investigations on Splunk ES.
Design and implement Splunk infrastructure, apps, reports, alerts, and dashboards.
Manage Splunk knowledge objects (Apps, Dashboards, Saved Searches, Scheduled Searches, Alerts).
The ability to de-code and debug complex Splunk queries.
Integrate and onboard event feeds from customer’s security devices and appliances.
Provide recommendations and implement changes to optimize Splunk products in the customer environment.
Maintain proper daily operation and performance of the Splunk deployment.
Support the SOC.
Perform Content Development to properly identify data feeding SIEM’s and correlation of events.
Engineering of systems administration-related solutions for various project and operational needs.
Install new/rebuild existing servers and configure hardware, peripherals, services, settings, directories, storage, etc. in accordance with standards and project/operational requirements.
Install and configure systems which support infrastructure and/or activities.
Analyze highly complex business requirements; generate technical specifications to design or redesign complex software components and applications.
Be flexible and thrive in an evolving environment
JPMorgan Chase
Houston,Tx
February 2016 Sept 2019
Splunk Lead Administrator Engineer
Creating various administrations dashboards.
Onboarding legacy data into Splunk
Parsing and data validation
Work with various security team to build and develop security use cases
Managing Scrum board to manage the team everyday activities
Monitoring Splunk infrastructure, deployment, products, apps, reports, alerts, and dashboards
Manage Splunk knowledge objects (Apps, Dashboards, Saved Searches, Scheduled Searches, Alerts)
The ability to de-code and debug complex Splunk queries
Provide recommendations and implement changes to optimize Splunk products in the customer environment.
Maintain proper daily operation and performance of the Splunk deployment
Perform Content Development to properly identify data feeding SIEM’s and correlation of events
Engineering of systems administration-related solutions for various project and operational needs.
Install and configure systems which support infrastructure and/or activities.
Develop and maintain installation and configuration procedures.
Contribute to and maintain system standards.
Contribute to and maintain system standards.
Contribute to and maintain security posture of the system
Research and recommend innovative, and where possible, automated approaches for system administration tasks. Identify approaches that leverage resources. Operations and Support.
Install and maintain security patches on the operational and development system,
Perform daily system monitoring, verifying the integrity and availability of all hardware, server resources, systems and key processes, reviewing system and application logs, and verifying completion of scheduled jobs such as backups.
Perform regular security monitoring to identify any possible intrusions.
Created, changed, and deleted user accounts per request as necessary.
Repair and recover from hardware or software failures. Coordinate and communicate. with impacted constituencies. Maintenance.
Created home dashboard to monitor ingestions and feeds.
Metrics creation to monitor various instances.
Develop use cases based off of Mitre Att&ck template.
Hewlett Packard
Bangalore, Karnataka
October 2012 -Feb 2016
Linux System Administrator/ Splunk Admin
Maintenance of server on a weekly basis (Brand Rolls)
Setup and manage user accounts
Attend to system operations tickets
Responsible for monitoring and management of VMware environment of virtual servers
Train new users to use standard applications, equipment’s and business applications
Manage systems routine backup, enabling cron jobs, enabling system logging and network logging of servers for maintenance
RPM and YUM package installations, patch and other server management
Installed, tested monitoring solutions with Splunk services.
Customize the input parsing process
Provided technical services to projects, user requests and data queries.
Supported data source configurations and change management processes.
Analyzed and monitored incident management and incident resolution problems.
Resolved configuration-based issues in coordination with infrastructure support teams.
Maintained and managed assigned systems, Splunk related issues and administrators.
Utilized knowledge objects for reporting statistics
Utilize the Distributed management console to investigate resource usage
Configured license pooling
Troubleshooting Splunk feed issues and data ingestion for remote locations
Deployed new Splunk architecture at disaster recovery site.
Configure hot, warm and cold buckets hold data for extended period of time.
Created home dashboards to monitor ingestion and feeds for private network performance.
Configured Firewall to allow Applications to run.
Create Logical volumes and design the environment to the job's directions.
Install Virtual machines, as well as physical machines.
Assist in any data migration activities whenever necessary with the team
Assist the team with transferring of software applications and reports between testing and production environments.
Setup Nagios server to monitor systems uptime, services and disk space
Installation and configuration of intrusion detection system such as OSSEC for log analysis, file integrity checking, real time alerting and brute force attach prevention.
Schedule Jobs with Crontab
Red Hat Linux Servers Patching using RHEL Satellite Network
Working knowledge of Puppet automation tool for system-wide configuration and management of Linux servers.
Install Centos, Red Hat on machines
Provide internal support for large scale data warehouse. (Approximately 75 to 125 Linux/Unix servers any routine and vendor-specific maintenance on all system.
Follow job's policies to create user accounts.
Manage groups of multiple user accounts
Giving remote access to different levels and types of users.
Installed and used these Splunk apps: *Nix, Deployment Monitor, Sanity Check, Afterglow, Enterprise Batch Ops, Splunk on Splunk, Sideview and DB Connect.
Created Linux Kickstart servers and processes to automate and standardize the installation process, reducing installation time by 35% and post-installation errors by 50%.
Researched and evaluated new technology solutions, such as the migration from IBM ClearCase to Subversion.
Documented and implemented a disaster recovery plan that included backup schedule policies.
Manage vSphere ESXI host and virtual machines using VMware vCenter
Managed and configured RPM package building tools for building and patching of applications from source codes for Centos and RHEL system.
WIPRO
Hyderabad
June’10 – March’12
SQL Developer
Responsibilities:
Designed, Coded, Tested, Implemented the Stored Procedures to support the System.
Fixed bugs in the existing in-house developed Software which is used to upload the reports for the end users to view the reports.
Created records, tables, collections (nested tables and arrays) for improving Query performance by reducing context switching.
Participated in code reviews in Oracle Views, Pl/SQL Procedures to understand the testing needs of the change components.
Involved in writing PL/SQL Packages, Functions, Stored Procedures, and Data Base Triggers.
Created huge database packages with related functions and procedures.
Added database triggers to some history tables of the database.
Created and configured SQL mail to send mail as events occur.