profile-pic

Kumaran Ramachandran

Highly motivated and Experienced in Security Administrator to be a top performer by maintaining cutting edge skills and the latest Industry knowledge. Specialized in network monitoring security software installation and working to prevent cyber- attacks especially in business and corporate settings.
  • Role

    Lead - Cyber Security Operations

  • Years of Experience

    16 years

Skillsets

  • Penetration Testing - 7 Years
  • Splunk - 7 Years
  • Cyber security - 11 Years
  • Security - 11 Years
  • AWS Services - 11 Years
  • Networking - 13 Years

Professional Summary

16Years
  • Jan, 2023 - Present2 yr 7 months

    Lead - Security Operations & Cloud Security

    Delivery Solutions
  • Jun, 2021 - Oct, 20221 yr 4 months

    Cloud Security Administrator

    Relevance Lab
  • Jul, 2020 - May, 2021 10 months

    IT Security Analyst

    Xyram Software Solutions Pvt Ltd
  • Jul, 2014 - Oct, 20162 yr 3 months

    Server & Network Security Administrator

    AL Technology Services Pvt Ltd
  • Oct, 2016 - Jul, 20181 yr 9 months

    Sr. Network Security Administrator

    InEight India Pvt Ltd
  • Oct, 2018 - Jul, 20201 yr 9 months

    Technology Specialist / Security Administrator

    Yash Technology Services Pvt Ltd
  • Jan, 2010 - May, 20144 yr 4 months

    System Administrator

    Pioneer Peripherals Pvt Ltd
  • Sep, 2008 - Dec, 20091 yr 3 months

    Desktop and Server support

    SGJ Infotech Pvt Ltd

Applications & Tools Known

  • icon-tool

    Splunk

  • icon-tool

    AWS

  • icon-tool

    Azure

  • icon-tool

    DLP

  • icon-tool

    SAN

  • icon-tool

    ISO27001

  • icon-tool

    CI/CD

  • icon-tool

    CASB

  • icon-tool

    DAST

  • icon-tool

    SAST

  • icon-tool

    GRC

  • icon-tool

    HIPAA

  • icon-tool

    GDPR

  • icon-tool

    NIST

  • icon-tool

    OWASP

  • icon-tool

    OSINT

  • icon-tool

    Sandbox

  • icon-tool

    CVE

  • icon-tool

    IAM

  • icon-tool

    AWS Security Hub

  • icon-tool

    Amazon GuardDuty

  • icon-tool

    Jira

  • icon-tool

    Zendesk

  • icon-tool

    MongoDB

  • icon-tool

    New Relic

  • icon-tool

    AWS Route53

  • icon-tool

    AWS WAF

  • icon-tool

    VPC

  • icon-tool

    IBM Qradar

  • icon-tool

    VPN Gateway

  • icon-tool

    HP Fortify

  • icon-tool

    Nagios

  • icon-tool

    Snort

  • icon-tool

    Wireshark

  • icon-tool

    Service Now

  • icon-tool

    Ghost

  • icon-tool

    Active Directory

Work History

16Years

Lead - Security Operations & Cloud Security

Delivery Solutions
Jan, 2023 - Present2 yr 7 months
    Implemented Wiz.io, Monitored Organizations network for security breaches and investigated violations. Assisted the Infra team in planning/building MongoDB, New Relic as a monitoring tool for all critical Networks/Servers. Worked with the CTO and Architects and IT and business stakeholders to define metrics and reporting strategies that effectively communicate the success and progress of the security program. Prime responsible for maintaining AWS Route53 AWS Macie, AWS WAF, AWS Security HUB, VPC, ALB IBM Qradar, Wiz.io, Akamai DDoS protection and Proofpoint email security, VPC, OKTA, InternetGateway, NAT Gateway, ACL, VPN Gateway, Routing table. Developed an automation plan to scan and install security patches for the AWS instances. Managed DS SaaS Production setup and got it to 90% scorecard of CIS Top-10 and AWS Security Best Practices, DRATA compliance management etc.

Cloud Security Administrator

Relevance Lab
Jun, 2021 - Oct, 20221 yr 4 months
    Highly motivated and Experienced in Security Administrator to be a top performer by maintaining cutting edge skills and the latest Industry knowledge. Specialized in network monitoring security software installation and working to prevent cyber-attacks especially in business and corporate settings.

IT Security Analyst

Xyram Software Solutions Pvt Ltd
Jul, 2020 - May, 2021 10 months
    Provided technical expertise for IT Network & Security design, Implementation, optimization, and upgrade. Knowledge of OWASP, OSINT, Sandbox, Kali, Burpsuite Pro, CVE, IAM, Perimeter Security, and SIEM solutions. Streamlined onboarding processes for new security tools (Wiz.io, Falcon EDR, QRock, Qualys VM & Network Scanner) within the UPS cybersecurity team, ensuring efficient integration and utilization. Played a key role in managing UPS cybersecurity tools (Wiz.io, Falcon, QRock, Qualys VM) by developing training materials and providing ongoing support to security personnel. Direct cybersecurity strategy, Incident response, Threat hunting, network-focused forensics, and Cyber resiliency to protect $13m in government assets for BBMP and Scholastic incident response center.

Technology Specialist / Security Administrator

Yash Technology Services Pvt Ltd
Oct, 2018 - Jul, 20201 yr 9 months
    Developed and implemented a comprehensive application security program, reducing identified vulnerabilities by 40% within the first year. Led a team of security engineers in conducting threat modeling exercises for critical applications, identifying and mitigating potential security risks. Reduced onboarding time for new security tools by 20% through streamlined processes and user training Established a security awareness training program for developers, resulting in a 25% increase in secure coding practices. Automated security tasks using AWS Lambda functions and CloudWatch Events for vulnerability scanning, security configuration checks, and incident notification. Leveraged AWS Security Hub for centralized aggregation and analysis of security findings from various cloud services, improving the efficiency of security operations.

Sr. Network Security Administrator

InEight India Pvt Ltd
Oct, 2016 - Jul, 20181 yr 9 months
    Optimized cloud security posture by utilizing cost-effective security solutions and right-sizing cloud resources to balance security and cost considerations. Demonstrated strong technical skills in understanding and utilizing various cloud security tools (e.g., Wiz, Falcon, QRock, Qualys VM) Ensured compliance with PCI DSS requirements for cloud-based payment processing systems by implementing strong encryption, access controls, and regular security assessments. Collaborated with the IT audit team to conduct SOC 2 Type II audits for the cloud environment, demonstrating adherence to security controls and best practices. Maintained awareness of relevant cloud security regulations (HIPAA, GDPR) and implemented necessary controls to meet compliance requirements.

Server & Network Security Administrator

AL Technology Services Pvt Ltd
Jul, 2014 - Oct, 20162 yr 3 months
    Developed a cloud security monitoring strategy using CloudWatch logs and metrics to detect suspicious activity and potential security incidents. Led the investigation and remediation of a cloud security incident involving unauthorized access to an S3 bucket, implementing corrective actions and improving access control policies. Established a cloud security incident response plan (SIRP) for rapid detection, containment, eradication, and recovery from security incidents. Designed and implemented secure cloud architectures using AWS services to meet security best practices and industry compliance standards (SOC 2, ISMS 2013, HIPAA, GDPR, NIST). Utilized AWS Security Hub and NIST 800-53 controls to identify and remediate security vulnerabilities within the AWS environment.

System Administrator

Pioneer Peripherals Pvt Ltd
Jan, 2010 - May, 20144 yr 4 months
    Leveraged Amazon GuardDuty to continuously monitor for suspicious activity and automate incident response procedures. Performed comprehensive security assessments using tools like Crowdstrike Falcon, Qualys VM scanner, Qualys Vulnerability Management, and Wiz.io to identify and remediate vulnerabilities across cloud and on-premises environments. Managed endpoint security using ManageEngine Endpoint Management to enforce security policies, deploy antivirus solutions (Apex One Antivirus), and ensure endpoint compliance. Conducted Privacy Impact Assessments (PIA) to evaluate the risks associated with processing personal data. Implemented security awareness training programs using KnowBe4 to educate employees on cybersecurity best practices and phishing attempts.

Desktop and Server support

SGJ Infotech Pvt Ltd
Sep, 2008 - Dec, 20091 yr 3 months
    Utilized Burp Suite for manual penetration testing to identify potential security weaknesses in web applications (OWASP). Led security teams in managing projects, assigning tasks, and tracking progress using Jira and Zendesk ticketing systems. Maintained clear communication with stakeholders to ensure alignment on security objectives and initiatives. Implemented asset management procedures to maintain an accurate inventory of hardware, software, and cloud resources for improved security posture. Administration of TrendMicro Email Security & Antivirus, whitelisting and blacklisting applications. Actively monitored for all Zer0day threats and critical patches.

Achievements

  • Developed and implemented a comprehensive application security program
  • Led a team of security engineers in conducting threat modeling exercises
  • Reduced onboarding time for new security tools by 20%
  • Established a security awareness training program
  • Automated security tasks using AWS Lambda functions
  • Leveraged AWS Security Hub for centralized aggregation and analysis
  • Optimized cloud security posture
  • Ensured compliance with PCI DSS requirements
  • Collaborated with the IT audit team to conduct SOC 2 Type II audits
  • Maintained awareness of relevant cloud security regulations
  • Developed a cloud security monitoring strategy
  • Led the investigation and remediation of a cloud security incident
  • Established a cloud security incident response plan
  • Designed and implemented secure cloud architectures
  • Utilized AWS Security Hub and NIST 800-53 controls
  • Leveraged Amazon GuardDuty to continuously monitor for suspicious activity
  • Performed comprehensive security assessments
  • Managed endpoint security using ManageEngine Endpoint Management
  • Conducted Privacy Impact Assessments
  • Implemented security awareness training programs using KnowBe4
  • Utilized Burp Suite for manual penetration testing
  • Led security teams in managing projects
  • Maintained clear communication with stakeholders
  • Implemented asset management procedures
  • Administration of TrendMicro Email Security & Antivirus
  • Monitored for all Zer0day threats and critical patches
  • Implemented Wiz.io
  • Monitored Organizations network for security breaches
  • Assisted the Infra team in planning/building MongoDB
  • Worked with the CTO and Architects to define metrics and reporting strategies
  • Maintained AWS Route53
  • Developed an automation plan to scan and install security patches
  • Managed DS SaaS Production setup
  • Implemented data security and data privacy using Macie
  • Implemented AWS WAF to protect web applications
  • Deployed automated patching solution for Delivery Solutions Servers
  • Increased security team adoption of Wiz.io
  • Integrating new log sources to Qradar SIEM
  • Configured and Designed DLP system with ProofPoint security
  • Build and integration primarily of AWS GuardDuty
  • Administration of Sentinel one EDR
  • Implemented AlienVault as SEIM
  • Assisted the Internal IT team to plan/build Nagios
  • Worked with the CISO and IT stakeholders to define metrics
  • Lead policy and standard revisions
  • Ensuring compliance accuracy for documentation
  • Created enterprises communication plan
  • Developed cyber capabilities cloud catalog
  • Interacted with clients/Developers and analyzed operational requirements
  • Ensured clients network are safe and free of technical problems
  • Pentesting on and Internal network
  • Implemented SEIM
  • Provided technical leadership to the enterprise
  • Install and maintain security infrastructure
  • Assess threats, risks and vulnerabilities
  • Managed process and acted in the lead role for computer / network security incident response team
  • Assist with the development of processes and procedures to improve incident response times
  • Document all activities during an incident
  • Analyze a variety of network and host-based security appliance logs
  • Provide information regarding intrusion events
  • Responsible for 5000+ users and more than 200+ sites
  • Proxy management
  • Analysing the events and create incidents
  • Provide support and guidance to the L1 Engineer
  • Perform multiple assigned technical tasks
  • Tested responses of client websites to hacker attacks
  • Installed and deployed new software
  • Implementing traffic filters
  • Building and Maintaining Visio documentations
  • Documenting all network setups
  • Educated management on how to prevent or minimize cyber security attacks
  • Performed comprehensive investigations of cyber security breaches
  • Purchased new security software and made update recommendations
  • Planned, Evaluated and implemented Network Security Measures
  • Maintained Network security Technologies and services
  • Monitored and updated security systems
  • Provide networking engineer support to private and public organizational
  • Interacted with clients and analyzed operational requirements
  • Developed and executed networking solution for internal and external sources
  • Managed user accounts, groups, print queues and controlling access rights
  • Performed day-to-day administration functions
  • Created images for various divisions for all desktops and laptops
  • Maintained technical knowledge in networking area
  • LAN Administration
  • Monitored server performance and Network Performance
  • Responsible for creating, testing PC images
  • Provided technical support for hardware/software configurations and applications
  • Administered and supported local/LAN printers
  • troubleshooting for MS Outlook
  • Installing and configuring various Peripherals
  • Securing Network Resources with NTFS permissions
  • Applying NTFS Permissions
  • Configuring and Managing Software RAID's
  • Deployed a small VMWare Environment
  • Installed, configured, set policies and schedules for Symantec Mail Security
  • Exchange Mailbox Migration

Major Projects

2Projects

Lead - Security Operations & Cloud Security Delivery Solutions

Jan, 2023 - Present2 yr 7 months
    Developed and implemented a comprehensive application security program, reducing identified vulnerabilities by 40% within the first year. Led a team of security engineers in conducting threat modeling exercises for critical applications, identifying and mitigating potential security risks. Reduced onboarding time for new security tools by 20% through streamlined processes and user training Established a security awareness training program for developers, resulting in a 25% increase in secure coding practices. Automated security tasks using AWS Lambda functions and CloudWatch Events for vulnerability scanning, security configuration checks, and incident notification. Leveraged AWS Security Hub for centralized aggregation and analysis of security findings from various cloud services, improving the efficiency of security operations. Optimized cloud security posture by utilizing cost-effective security solutions and right-sizing cloud resources to balance security and cost considerations. Demonstrated strong technical skills in understanding and utilizing various cloud security tools (e.g., Wiz, Falcon, QRock, Qualys VM) Ensured compliance with PCI DSS requirements for cloud-based payment processing systems by implementing strong encryption, access controls, and regular security assessments. Collaborated with the IT audit team to conduct SOC 2 Type II audits for the cloud environment, demonstrating adherence to security controls and best practices. Maintained awareness of relevant cloud security regulations (HIPAA, GDPR) and implemented necessary controls to meet compliance requirements. Developed a cloud security monitoring strategy using CloudWatch logs and metrics to detect suspicious activity and potential security incidents. Led the investigation and remediation of a cloud security incident involving unauthorized access to an S3 bucket, implementing corrective actions and improving access control policies. Established a cloud security incident response plan (SIRP) for rapid detection, containment, eradication, and recovery from security incidents. Designed and implemented secure cloud architectures using AWS services to meet security best practices and industry compliance standards (SOC 2, ISMS 2013, HIPAA, GDPR, NIST). Utilized AWS Security Hub and NIST 800-53 controls to identify and remediate security vulnerabilities within the AWS environment. Leveraged Amazon GuardDuty to continuously monitor for suspicious activity and automate incident response procedures. Performed comprehensive security assessments using tools like Crowdstrike Falcon, Qualys VM scanner, Qualys Vulnerability Management, and Wiz.io to identify and remediate vulnerabilities across cloud and on-premises environments. Managed endpoint security using ManageEngine Endpoint Management to enforce security policies, deploy antivirus solutions (Apex One Antivirus), and ensure endpoint compliance. Conducted Privacy Impact Assessments (PIA) to evaluate the risks associated with processing personal data. Implemented security awareness training programs using KnowBe4 to educate employees on cybersecurity best practices and phishing attempts. Utilized Burp Suite for manual penetration testing to identify potential security weaknesses in web applications (OWASP). Led security teams in managing projects, assigning tasks, and tracking progress using Jira and Zendesk ticketing systems. Maintained clear communication with stakeholders to ensure alignment on security objectives and initiatives. Implemented asset management procedures to maintain an accurate inventory of hardware, software, and cloud resources for improved security posture. Administration of TrendMicro Email Security & Antivirus, whitelisting and blacklisting applications. Actively monitored for all Zer0day threats and critical patches. Implemented Wiz.io, Monitored Organizations network for security breaches and investigated violations. Assisted the Infra team in planning/building MongoDB, New Relic as a monitoring tool for all critical Networks/Servers. Worked with the CTO and Architects and IT and business stakeholders to define metrics and reporting strategies that effectively communicate the success and progress of the security program. Prime responsible for maintaining AWS Route53 AWS Macie, AWS WAF, AWS Security HUB, VPC, ALB IBM Qradar, Wiz.io, Akamai DDoS protection and Proofpoint email security, VPC, OKTA, InternetGateway, NAT Gateway, ACL, VPN Gateway, Routing table. Developed an automation plan to scan and install security patches for the AWS instances. Managed DS SaaS Production setup and got it to 90% scorecard of CIS Top-10 and AWS Security Best Practices, DRATA compliance management etc. Implemented (DLP) data security and data privacy using Macie, TrendMicro Email security, AWS NLB, and ALB for high availability. Implemented AWS WAF to protect web applications and APIs against exploits. Deployed automated patching solution for Delivery Solutions Servers using Inspector, Systems Manager, Lambda, S3. Increased security team adoption of Wiz.io by 30% through comprehensive training materials and ongoing support.

Cloud Security Administrator

Jun, 2021 - Oct, 20221 yr 4 months
    Highly motivated and Experienced in Security Administrator to be a top performer by maintaining cutting edge skills and the latest Industry knowledge. Specialized in network monitoring security software installation and working to prevent cyber- attacks especially in business and corporate settings.

Education

  • BCA - Bachelor's

    Manoanmaniam Sundaranar University - Tirunelveli

Certifications

  • Ccna security 210-260 iins

  • Aws security speciality 2021

  • Alienvault - security engineer

  • Az-500: microsoft azure security technologies - in progress

  • Chif - in progress

  • Cissp - exam scheduled on october 05 2024

  • Iso 27001:2013 internal auditor training program