Yash Kothiya, CISSP Mumbai
Cybersecurity Engineer *******.****@*****.*** LinkedIn
PROFESSIONAL SUMMARY
Certified and detail-oriented Cybersecurity Professional with around 4 years of experience in identifying vulnerabilities, mitigating risks, and implementing robust security measures. Proficient in various security tools and technologies, with a strong background in network security, penetration testing, and incident response. Committed to maintaining the highest standards of information security and continuously updating skills to stay abreast of the latest industry trends. Strong analytical and problem-solving skills with a proven track record of successful project management and cross-functional collaboration. I have also hold Certified Information Systems Security Professional (CISSP) certificate. Key Skills:
• Incident Response: Led incident response team, reducing mean time to respond (MTTR), while handling security incidents.
• Security Architecture and Design: Designed and implemented security architecture for projects, ensuring compliance with regulatory standards. Developed security standards and procedures, enhancing overall security posture.
• Vulnerability Management: Conducted quarterly vulnerability assessments, identifying vulnerabilities and implementing remediation plans for critical vulnerabilities.
• Security Testing: Performed penetration tests, identifying vulnerabilities, and developed security testing methodologies for continuous improvement.
• Security Awareness: Developed and delivered security awareness training sessions to employees, resulting in a reduction in security incidents.
• Network Security: Established security policies and conducting quarterly vulnerability assessments, remediating 70% of network infrastructure vulnerabilities.
• Cloud Infrastructure and Security: Utilized New Relic to monitor applications and infrastructure components, generating custom alerts. Conducted bi-annual vulnerability scans and penetration tests, leveraging New Relic Compliance plugin to enhance compliance efforts.
• Strong leadership traits with strong behavioral management skills, strong competence to collaborate with Senior Management for providing strategic inputs and IT vision and implementing new technologies. SKILLS
Security Governance: NIST 800-53, 800-53A, 800-37, COBIT, ISO 27001, MITRE, STRIDE, CIA, SOC Reports. Security Protocols: OSI Model, DNSSEC, VPN, SDN, SFTP, 802.11, TCP/IP, VLANs, OPENVPN, LAN, WAN, OWASP. Tools: Nmap, OWASP- ZAP, Docker, Burp Suite, Snort, Nessus, OpenVAS, Wazuh, TheHive, Shuffle, Metasploit, SQL, SIEM Splunk, IDA Pro, Ghidra, Google Cloud Console, Docker, Kali Linux. Languages: Python, C Programming, Shell Scripting
Soft Skills: Communication, Creativity, Flexibility, Leadership, Teamwork & Programming, Decision Making, Fast Learner. CERTIFICATIONS:
CISSP – Member ID - 1600281
EMPLOYER
Cybersecurity Engineer
Gurushcools LLC, NJ, USA Feb 2023 – Sept 2024
Description: GuruSchools LLC is one of the leading IT consulting and outsourcing partners with 100+ fortune 500 companies and mid-sized firms across industries with the best in class, uniquely customized and scalable workforce solution. They work with companies in banking, insurance, airlines/aviation, healthcare, manufacturing, oil, gas, energy, pharma, telecom, automotive etc. PROFESSIONAL EXPERIENCE
Cloud Security Engineer
Remote Client: Insurance Company, NYC, USA Mar 2024 – Sept 2024 Responsibilities:
• Evaluate, Design, and Implement Security Solutions: Evaluated and designed security solutions to mitigate risks from emerging threat vectors such as data security, remote access, and mobility technologies.
Implemented these security solutions across the group to improve the overall security posture and protect sensitive information.
• Security and Governance Framework Improvement:
Assessed and enhanced the security and governance framework to achieve maximum compliance with global standards. Standardized this framework across all domestic and overseas businesses, ensuring a consistent and robust security posture.
• Stakeholder Collaboration and Project Buy-In:
Built consensus among stakeholders to secure buy-in for security projects. Defined the scope of work, roles, and responsibilities, and obtained business approval for proposed solutions, ensuring alignment with business demands.
• Third-Party Access Management:
Established governance for third-party network access by designing and implementing a security framework. Evaluated and leveraged tools to track third-party access, developed policies and procedures, and generated reports for business stakeholders.
• Vendor Coordination and Technology Evaluation:
Identified and engaged with vendors to evaluate and implement new technologies. Coordinated product performance reviews and developed improvement plans to address problem areas within the solution design, ensuring continuous enhancement of security measures. Information Security Analyst
Remote Client: Energy Company, Atlanta, USA Sept 2023 – Feb 2024 Responsibilities:
• Enhanced Security Posture through Risk Assessments and Training: Comprehensive IT Risk Assessments: Conducted IT risk assessments, documenting key controls and collaborating with application managers across the scoping, planning, and execution phases.
• Security Monitoring & Incident Response:
Monitored Security Information and Event Management (SIEM) systems, analyzing millions of security logs daily to identify potential threats.
Participated in the investigation and responded to security incidents, contributing to swift containment and minimal damage.
• Phishing Simulation Program Champion:
Collaborated with stakeholders to gather requirements and champion leadership advocacy for the company security awareness program. Deployed relevant training based on user needs, including phishing simulations and mandatory training for privileged users who fell victim to simulated phishing attempts.
Targeted Security Training: Identified key audiences (executives, privileged users) and developed tailored training and awareness programs to address specific security risks.
Industry-Leading Phishing Programs: Recommended and implemented customized phishing simulation programs based on industry best practices and client goals.
Testing and Troubleshooting Expertise: Participated in test planning, functional testing, and error reporting, documenting identified issues, steps for reproduction, and potential solutions.
• Implemented a SOC automation project utilizing Wazuh, TheHive, and Shuffle to enhance incident response capabilities. Configure alert generation and forwarding from Wazuh to TheHive and Shuffle, enabling automated email notifications to SOC Analyst based on predefined alert levels.
System Security & Risk Management Specialist
Remote Client: Bank, NYC, USA May 2023 – Aug 2023
Responsibilities:
• System Security & Risk Management:
Classified systems using NIST SP 800-60/53 frameworks to establish appropriate security control baselines. Conducted comprehensive risk assessments to identify and prioritize threats and vulnerabilities. Developed System Security Plans (SSPs), Risk Assessments (RAs), Security Assessment Reports (SARs), and Plan of Action and Milestones (POA&Ms) to document security posture and mitigation strategies.
• Security Assessment & Authorization:
Performed independent security control assessments aligned with NIST SP 800-53, 800-53A, and the NIST SP 800-37 Risk Management Framework (RMF).
Employed various techniques (interviews, document review, testing) to gather evidence and evaluate security controls. Collaborated with the team to implement appropriate security controls and mitigate identified risks.
• Security Monitoring & Improvement:
Worked with the team to establish continuous monitoring of client information systems and security controls. Provided expert analysis and recommendations to address IT security problems.
• Risk Management Framework (RMF) Expertise:
Supported the implementation of RMF training courses and kick-off meetings for client projects. Performed system categorization according to NIST SP 800-37 requirements (low, moderate, or high impact). Developed risk assessment reports that identified threats, vulnerabilities, and mitigation actions.
• Continuous Learning & Improvement:
Remained informed about the latest cyber threats and attack vectors through ongoing research and training. Actively sought opportunities for professional development to enhance my cybersecurity skillset. Security Analyst, Vrindavan Exports, Mumbai, India Jun 2020 - July 2022 Project: At Vrindavan Exports, led the implementation of a robust security monitoring system, analyzing logs daily to identify potential threats. Conducted web application security assessments using Burp Suite, identifying and remediating critical vulnerabilities. Configured and managed Splunk for security event monitoring and developed customized dashboards for real-time visualization of security metrics. Proactively engaged in threat hunting, integrating security tools to enhance visibility, and reducing incident response time by 10-15%.
Responsibilities:
• Firewall Configuration:
Configured firewall rules for LAN, WAN, DMZ, and custom zones to ensure secure network segmentation and traffic control. Created a zone-to-zone access control matrix for cloud and on-premises Data Centre. Reviewed every firewall port opening request.
Reviewed more than 500 applications and created risk profiles for them. Wrote risk mitigation steps for applications, infrastructure, and other areas. Presented the same to the CISO and Board of Directors.
• Application and Web Filtering:
Designed and implemented application filters and web filters to block malicious content and ensure compliance with organizational policies.
• Network Services Configuration:
Configured essential network services such as DNS and NTP to ensure reliable name resolution and accurate time synchronization across the network.
• Address Translation:
Implemented Network Address Translation (NAT) and Port Address Translation (PAT) to manage and secure the allocation of IP addresses within the network.
• Antivirus Management:
Administered and managed antivirus solutions to protect network devices from malware and other security threats. EDUCATION
Saint Peters University, Jersey City, New Jersey
Degree: Master of Science in Cyber Security
K J Somaiya College of Engineering, Mumbai, India
Degree: Bachelor in Electronics and Telecom Engineering PROFESSIONAL AFFILIATIONS
Member, International Information System Security Certification Consortium, Inc. (ISC2). Member, ISC2 New Jersey chapter.
Attended various webinars and seminars on cybersecurity, cloud security and information security as part of ongoing learning.