Shreekanth Veleru
908-***-**** ********@*****.*** www.linkedin.com/in/shreekanth-veleru-60833a45
PROFESSIONAL SUMMARY
Highly accomplished Data Security & Governance Architect with over 23 years of enterprise IT experience specializing in Data Loss Prevention (DLP), Database Activity Monitoring (DAM), and structural Database Administration. Proven expert in engineering and scaling multi-layered data protection frameworks for PII, PCI, and HIPAA data across complex hybrid-cloud environments. Combines a powerful historical foundation as a Senior Oracle DBA with modern mastery of Microsoft Purview, Imperva, Netskope, and Data Security Posture Management (DSPM) for AI ecosystems. Adept at managing cross-functional global teams, automating security controls via APIs, and designing resilience strategies that eliminate insider threat vectors while preserving high-performance operations.
CORE COMPETENCIES & TECH STACK
Data Governance & Discovery: Microsoft Purview (Information Protection, Endpoint Protection), BigID, Snowflake PII Monitoring.
Database Security (DAM): Imperva SecureSphere, Imperva Sonar, Imperva DRA, IBM Guardium, Database Auditing Framework (DAF).
Data Loss Prevention (DLP-CASB): Netskope DLP, Microsoft Purview DLP, Zscaler Web Security, Microsoft Defender.
AI Security & Governance: Data Security Posture Management (DSPM) for AI, Cloud Security Posture Management, Microsoft Copilot Sensitivity Labeling, Generative AI Threat Mitigation.
Database Infrastructure: Advanced Oracle DB Administration, Oracle RAC, Performance Tuning, Vulnerability Remediation.
SIEM & Vulnerability Management: Splunk, QRadar, Qualys Risk Assessment.
Education
Bachelor of Technology, Computer Science AITS Engineering College, JNTU Degree obtained April 2002
Experience summary
Working as a Senior Data Protection Engineer for Newyork Life Insurance- July 2017 to present
Worked as a Senior Consultant FTE for HCL Technologies-May 2009 to July 2017
Worked as a Senior Consultant for Mphasis an EDS –July 2006 to May 2009
Worked as Systems Engineer for Polaris Software Labs Ltd-May 2004 to July 2006
Worked as an Oracle Programmer for ICSA INDIA LTD-May 2002 to May 2004
Certifications
CISM
Microsoft Certified Information Security Administrator Associate [Purview]
AWS Solutions Architect
Oracle 11G Certified
Project Profile
NewYork Life – Lebanon, NJ/Atlanta, GA
Senior Data Protection Engineer [DLP+DAM]
Duration: July 2017 to till date
Responsibilities:
DLP Infrastructure:
Worked on deploying the DLP agents on endpoints and server to monitor unauthorized data activity.
Monitor the DLP console the suspicious activity.
Implement, Configure and Administration of Cyber Security Tools like Netskope, Defender for Endpoint, DSPM for AI usage across the authority networks like Aws and Azure.
Monitored the incidents generated for unauthorized AI usage by end users and worked with them to educate and raising business exceptions and escalating the unauthorized usage.
Configure prevention policies and applying recommended policies to device groups based on the best practices.
Monitor the email gateway and analyze the emails which expose threats like phishing and malware and make recommendations for email rules to minimize malicious attacks and undesirable emails.
Monitor team mailbox and ticketing system to ensure proper steps are taken for all identified incidents.
Setup Security policies for users.
Created Threat Detection, Information Protection and Conditional Access policies in Microsoft CASB.
Created New Policy Templates as per the business need in CASB.
Monitoring the activity logs in CASB and provide recommendations to end users as per business.
Ingested the Firewall Logs into CASB to get the visibility into Cloud use, Shadow IT and the risk shadow IT
Adept at analyzing IT infrastructure, researching emerging threats and generating detailed risk assessments and Risk management solutions, uncovering firewall and network vulnerabilities, and providing technical solutions to Mitigate cybersecurity threats.
Strategized a data classification plan for internal client documents and emails to label and protect firm's sensitive information and data.
Developed test cases for model environments and managed offshore team for DLP and DAM tracks.
Provided assistance in conducting internal demos and gave trainings to demonstrate the DLP tools.
Assessed and triaged L2 level incidents on Netskope for email, Defender for endpoints and escalated policy violations by reaching out to the offenders and following up with the teams.
Compiled Zscaler web data and generated reports for management.
Prepared monthly list of unauthorized usb users for obtaining business justification and raising exceptions for usb usage.
Provisioned policies to scope in more data elements and broaden the scope of monitoring sensitive data for eg: Credit card numbers, ssn, passport numbers, DL, ITIN etc.
Planned and implemented Netskope and purview end point clients on windows and mac devices and provisioned policies to monitor printing of sensitive data by end users.
Assisted the team in daily health checks, following up on the daily trackers, service now tickets.
Contributed to clients' business needs by applying a collection of information and cybersecurity capabilities, including security and privacy, strategy, governance, IT risk, security testing, technology implementation/operations
Managed implementation team and created deliverables such as project plans, Architecture design, use cases, High-Level and Low-Level Design docs, Runbook
Provided DLP and DAM training to SMEs to develop their skills in these technologies
Helped in writing scoping and proposals for Data protection
Implemented DLP Incident Management, real time monitoring, event and log analysis, reporting of attempted compromises/Data leak to client network/endpoint through identification of suspected user/Applications.
Involved in implementing DSPM for AI and implemented Purview endpoint protection, information protection for NYL.
Involved in creating profile, policies and monitoring the incidents for L2 and L3 level triage.
Architected an end point DLP strategy for 20k windows devices using purview resulting in 45% reduction in unauthorized usb transfers.
Deployed sensitive labels for Microsoft copilot, ensured AI generated data summaries are restricted based on source data classification levels.
Monitored encrypted web traffic and created policies for Zscaler.
Developed custom sensitive information types using regex and trainable classifiers to identify HIPAA related documents.
Reduced high risk data exfiltration incidents and triaged many incidents.
DAM Infrastructure:
Implemented Securesphere infrastructure for NYL Corporate, Nylim and Direct production environments.
Implemented DRA infrastructure for NYL and established incident management workflow for triaging the alerts.
Implemented clustered environments for DAM, cloud database monitoring infrastructure deployments using Sonar.
Performed Imperva risk assessments and worked with database teams to remediate the vulnerabilities.
Performed database upgrades, patching, life cycle management, capacity planning and data governance on the sensitive information.
Performed sensitive data discovery scans and labelled the sensitive data identifiers and worked with application teams for getting an agreement on the identified data for data protection.
Performed URM scans, User and Event Behavior analytics using Sonar and DRA.
Implemented PII data governance on snowflake environment using ALTR tool. Used blocking features for data protection.
Implemented Signatures in DAM, used blocking features in both inline and sniffing mode for databases for few critical applications.
Deployed audit policies, security policies to adhere to audit compliance and provide security of company data.
Implemented Signatures in DAM, used blocking features in both inline and sniffing mode for databases for few critical applications.
Assessed available DAM tools in the market and helped organization to choose a correct tool for managing customer database environments.
Worked on setting up DAF policies and managed the sox compliance environments efficiently.
Automated agent installs for windows and unix database environments.
Performed UEBA analysis and worked with application teams in triaging the alerts.
Worked on onboarding agent less monitoring of cloud database assets and ensure the monitoring is in place for all the production assets.
Generating reports and helping application and dba teams for forensic analysis.
Architected end to end security framework for database environment for Cloud database monitoring and on-premise environments.
Worked efficiently and closely with Risk Assessment teams and compliance teams to understand the external compliance requirements
Performed Risk assessment using Imperva Risk assessment policies and informed the stake holders and database administrators about the vulnerabilities captured for the database servers.
Worked on the P1 tickets occurred for the critical databases of NewYork Life and identified the root cause of the issues and reported them to business stake holders.
Worked with Incident response teams to create a better work flow and also worked with the change management team to integrate Imperva appliances with cmdb.
Created different SOP’s for Imperva infrastructure.
Performed health checks and capacity planning for the Imperva MX, Gateways and securesphere agents.
Created production, development environments for NYL data cleansing projects.
Performed application risk assessments against Health Insurance Portability and Accountability Act (HIPAA) and Payment Card Industry (PCI)
Created reports, PII SCANS and monitored the database environments effectively using Imperva.
Deployed best practices in traffic distribution and load balancing.
Worked on Sev1 and Sev2 issues effectively and got good appreciations from the client.
Implemented oracle and Imperva best practices and increased the performance of the databases and its applications.
Performed capacity planning, created maintenance jobs, purge jobs for handling the incoming events.
Worked with Vendor support on the renewal quotes for license renewals and handled vendor meetings efficiently to reduce the costs of licensing.
AARP – Rockville, MD
Senior Data Security Engineer
Duration: November 2015 to July 2017
Responsibilities:
DAM Infrastructure:
•Involved in Imperva Monitoring for mission critical databases which is a very good security feature of the database monitoring.
•Upgraded Imperva Gateways from v10.5 to v12.0
•Created Gateways, MX and created v12.0 clustered environments.
•Onboarded database agents of MS SQL and Oracle to Imperva
•Created best practices in supporting securesphere agents efficiently.
•Resolved SSL cipher issues on the agents.
•Created Imperva data types, global objects, audit policies and security policies.
•Generated custom reports and scheduled reports using Imperva.
•Performed Discovery Scans and captured the sensitive data and reported to the business stake holders.
•Created Scan profiles, Configured Sites tree for AARP databases.
•Implemented blocking features in Imperva for the sensitive tables and restricted unauthorized access to the PII data.
•Worked as a team lead for database track and engaged in data protection and ensuring the audit data is in compliance.
•Created SQL Injection security policies and generated reports on ad hoc basis.
•Implemented Ex events platform for reports.
•Implemented counter breach environment for data analytics.
Vulnerability Management/Data Classifications/Log Monitoring:
Performed Risk assessment Scans, created option profiles for database scanning and performed asset discovery scans.
Performed asset tagging, created projects for OS teams and followed up with them based on the risk scores.
Performed forensic analysis for insider attacks and sql injection attacks and helped database teams with reports and blocked unauthorized transactions to happen.
Performed bigId scans and acknowledged the PII/PCI/HIPAA sensitive data and worked with business teams to determine the true positives.
Configure, Monitor and Administration of scan engines/appliance on perm and cloud connected networks.
Created asset groups and sites in vulnerability management console.
Scheduled monthly vulnerability scans to identify the vulnerabilities across authority’s network connected devices.
Performed compliance scans on newly connected devices to the network.
Conducted scheduled and ad hoc vulnerability scans using vulnerability tools.
Generate the monthly vulnerability reports for CISO review.
Alert monitoring and Incident response using SIEM tool.
Novelis, Data Center Migration - Atlanta, GA
Senior Oracle DBA
Duration: March 2012 to November 2015
Ernst & Young - Secaucus, New Jersey
Senior Oracle DBA
Duration: May 2009 to March 2012
EDS-Sprint & Nextel (Mphasis) – India
Oracle DBA
Duration: July 2006 to May 2009
Citibank US (Polaris) - India
Oracle DBA
Duration: May 2004 to July 2006
Hospital Management System (ICSA) – India
E-health insurance (ICSA)
Oracle Developer
Duration: May 2002 to April 2004