AMAR RAJADHYAX
Scotch Plains, New Jersey, USA 201-***-**** ***.***********@*****.*** linkedin.com/in/amar-rajadhyax-a01a9210a
VULNERABILITY MANAGEMENT SECURE CONFIGURATION MANAGEMENT CYBERSECURITY LEADERSHIP
●IT security and vulnerability management professional with 10+ years transforming cybersecurity postures — specialized in risk elimination through data fidelity, process optimization, and automation across QualysGuard, Rapid7, Tenable, and Wiz, with growing cloud expertise.
●Delivered an 85% increase in compliance adherence and a 95% reduction in vulnerability risk scores; skilled at crafting unified remediation strategies across vulnerabilities, non-compliant configurations, and penetration-test findings, integrated with threat intelligence and risk prioritization.
●Strong background in IT audit/compliance, security operations, and IT risk management, with expertise in SLA/ELA integration, process improvement, project management, and remediation automation.
KEY HIGHLIGHTS
●Led six major global vulnerability remediation projects — securing 500 domain controllers, 100,000+ compute instances, and 25,000+ databases/application instances — for 75% faster completion and a 95% vulnerability reduction.
●Resolved 12 key regulatory audit issues while expanding network scan coverage across a complex hybrid environment of 100,000+ endpoints, achieving a 95% post-remediation compliance rate.
●Enhanced security engagements through automation and process improvements, achieving 65% faster response times and an 85% increase in metric accuracy.
●Key contributor to monthly threat detection campaigns focused on the OWASP Top 10, leveraging the MITRE ATT&CK framework to validate remediation results and improve standard operating procedures.
AREAS OF EXPERTISE
●Vulnerability & Scanning Tools: Qualys VMDR, Tenable/Nessus, Rapid7, Nucleus, Invicti, Wiz, Axonius, CrowdStrike, NMAP, BurpSuite, Nuclei, ZAP
●Frameworks & Standards: CIS Benchmarks, STIGs, NIST, CVE/CWE, OWASP Top 10, MITRE ATT&CK, CISA KEV
●Cloud & Infrastructure: AWS, Azure, GCP, SCCM, Intune, Ansible, Puppet, Chef, WSUS
●Identity & Access: Entra ID/Azure AD, Okta, CyberArk, SAML/OAuth/OIDC
●Analytics & Reporting: Power BI, Tableau, Excel (Power Query, Pivot Tables, Macros), Splunk, ServiceNow
●Scripting & Methodologies: PowerShell, VBA; Agile, Scrum, ITIL, SDLC
PROFESSIONAL EXPERIENCE
Sompo International Holdings, Morristown, NJ April 2026 – Present
Vulnerability & Secure Configuration Management Analyst
●Own weekly ranking and reporting of Sompo's top at-risk technologies for risk managers, executives, and auditors, anchored in the Nucleus Vulnerability Intelligence model — lifting enterprise risk posture from 500+ to under 400 (1,000-point scale).
●Track the external threat landscape and application portfolio to surface emerging exposure and detection/tooling gaps; channel findings into remediation planning and the security hardening backlog.
●Collaborate directly with system and application owners to contextualize risk and escalate vulnerabilities breaching time-to-resolve SLAs, lifting 30-day remediation adherence 60%.
●Administer the Risk Acceptance process end-to-end, ensuring proper approvals and accurate exception reporting across business units.
●Pinpoint bulk/automated mitigation opportunities, converting recurring findings into Service Requests and Security Hardening backlog items.
●Broadened vulnerability scan coverage across on-prem, cloud, and hybrid asset classes via Nessus, Qualys, and CrowdStrike, enabling near real-time risk reporting; spearheaded migration from Tenable to Qualys during SI's subsidiary integration.
●Sustain KPI/KRI metrics on vulnerability and attack-surface trends, continuously feeding data to aggregation and workflow tooling to support governance reporting.
Technologies: Nessus, Tenable Security Center, Qualys VMDR, Nucleus Vulnerability Intelligence, Ionix, Splunk, Invicti, MS Defender, ControlUp, Ninja 1, SCCM
Bloomberg LP, Princeton, NJ April 2025 – April 2026
Threat & Vulnerability Management Consultant
●Trimmed vulnerability risk to 95% of confirmed detections within 30 days via a new VM Clearing House model.
●Attained 95% CIS benchmark compliance across 65,000+ Windows Server and RHEL systems supporting global critical infrastructure.
●Championed enterprise-wide TLS 1.2 adoption on internet-facing systems, slashing risk 75%, and lifted remediation/hardening SLOs by 65%.
●Streamlined ticketing for vulnerability and pen-test findings, prioritized by CISA KEV and Five Eyes threat intelligence.
Technologies: Rapid7 Nexpose, Wiz I/O, Chef/JFrog Artifactory, Axonius (AQL), PowerShell, Excel, QlikSense, Jira, SCCM CM Pivot
Commonwealth Financial Network, Waltham, MA January 2024 – April 2025
Threat & Vulnerability Management Leader
●Lowered confirmed vulnerability risk over 60% enterprise-wide using SCAP scans and targeted remediation.
●Boosted policy compliance scores 80% by enforcing secure configuration baselines for new and migrating assets.
●Refined Rapid7/ServiceNow integration, accelerating remediation response times 65%; steered NYDFS, SEC, and FINRA VM compliance certification.
●Architected a tiered VM service offering, positioning InfoSec as a revenue-generating business unit.
Technologies: Rapid7 InsightVM & InsightAppSec, ServiceNow VM Response, Power BI, Excel, SQL Server, PowerShell, Axonius (AQL)
Bank of the West, Omaha, NE September 2022 – September 2023
Vulnerability & Secure Configuration Management (SCM) Program Leader
●Directed VM/SCM integration for the Bank of the West–Bank of Montreal merger, lifting compliance adherence 60% in six months.
●Established a purple team pairing Qualys Threat Protection with ITAM and red-team tooling, accelerating zero-day response.
●Trimmed security vulnerabilities 75% via secure baselines and Agile remediation tracking; steered NYDFS, SOC 1, and SOC 2 audit closures.
Technologies: QualysGuard, ServiceNow VM Response & Cherwell, Power BI, Excel, SQL Server, Splunk
Capgemini Americas September 2013 – September 2022
Vulnerability Management Remediation Leader Senior Security Manager, Threat Detection and Controls
●Baptist Health of South Florida (Remote), Jan–Sep 2022: Trimmed backlog vulnerabilities 75%; rolled out MS Defender for IoT, reducing SCADA/ICS vulnerabilities 85% within 48 hours.
●Google Professional Services, Aug 2021–Jan 2022 (Cloud HSM Project Manager): Delivered PCI/DSS-compliant Cloud HSM implementations; lifted transfer efficiency 30% via CMEK integration.
●Bank of Tokyo Mitsubishi UFJ, Apr 2018–Aug 2021 (Vulnerability Remediation Program Manager): Resolved 1.5M vulnerabilities across 60,000+ endpoints, clearing 85% of an aged backlog at a 95% 30-day remediation rate.
●AIG, Sep 2016–Apr 2018 (Remediation & Hardening Operations Leader): Boosted global security compliance 65%; steered a global AD hardening program across 10,000+ domain controllers.
●Horizon Blue Cross Blue Shield of NJ, Sep 2013–Sep 2016 (Security Analysis Leader): Stood up a SOC for NJ's largest health payer; trimmed unauthorized database access 60% via DAM/PAM deployment.
Technologies: QualysGuard, Tenable I/O & SC, ServiceNow, SCCM, Ansible, Wiz I/O, Alteryx, BladeLogic, Tableau
Groupware Solutions Inc., Somerset, NJ March 2004 – September 2013
Principal Business Analyst / Data Analyst
●Improved payer system efficiency 60% and data accuracy 70% through vendor integrations for NJ's largest health payer; led dual-eligible plan rollouts cutting hospitalizations 65%.
CERTIFICATIONS
●Certified Business Analysis Professional (CBAP)
EDUCATION
●Post Graduate Diploma in Software Technology, GOI Department of Electronics, India
●Bachelor of Science in Electronics and Information Systems, Bombay Institute of Technology, India