Ankit Kumar

DevOps Engineer

Bengaluru, Karnataka, India9 yrs 3 mos experience
Most Likely To Switch

Key Highlights

  • 9+ years of diverse security engineering experience
  • Expertise in AWS security and DevSecOps practices
  • Proven track record in vulnerability assessments and incident response
Stackforce AI infers this person is a Cloud Security and DevSecOps expert in the cybersecurity industry.

Contact

Skills

Core Skills

Aws SecurityCloud SecurityDevsecopsIncident ResponseApplication SecurityNetwork Security

Other Skills

ARBOR PeakflowAmazon Web Services (AWS)CSPMCisco Sourcefire Intrusion Prevention SystemCybersecurityDASTFirewallsFirewalls: CheckPoint and freeBSD - Packet-FilterIPSInfosec policyLinuxPenetration TestingPythonRisk AssessmentSAST

About

Senior Security Engineer with 9+ years of experience and hands-on a range of security domains from SecureSDLC, DAST, SAST, SCA, VA/PT, BugBounty, Threat hunting & AWS security. Skilled in WebApplication Security, DevSecOps, Cloud Security, Infra Security, Linux, Amazon Web Services (AWS), and Python (programming language). Cloud Security: Assisting the team in crafting security baselines, encompassing IAM (Identity and Access Management), Logging and Monitoring, Data Protection, Infrastructure Security, and Incident Response. Conducting regular security assessments on AWS services to ensure ongoing protection. DevSecOps: Collaborating with the team to create secure products through activities such as Architecture Reviews and Threat Modelling. Architecting CI/CD pipelines for the automation of secrets scanning, Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST) solutions. Implementing automated static analysis for Infrastructure as Code. Vulnerability Assessment (VA) / Penetration Testing: Conducting Penetration Testing external & Internal on applications, including Web Apps and APIs. Vulnerability Assessment of Cloud Infra and Corp Infra Additional Responsibilities: Configuring and setting up SIEM (Security Information and Event Management) solutions. Configuring and deploying Data Loss Prevention (DLP) measures. Assisting the company in achieving ISO 27001 and SOC2 compliance. Tools & Technical Skills: CSPM: Wiz, CloudGuard (Dome9), Prisma Cloud DAST - Dynamic Assessment: Acunetix, Whitehat, HCL AppScan, Burp Suite Pro, HP WebInspect SAST - Source Code Review: CheckMarx SCA - BlackDuck, Github Dependabot RBVM (Risk-Based Vulnerability Management Software) - Kenna Security Mobile Application Security & API testing: DataTheorem Vulnerability Assessment and Policy Compliance: QualysGuard, Nessus, and Tenable IO Issue & Project Tracking Tool: Jira SIEM: Demisto, BlackStratus, ArcSight, Splunk, Arbor, Qradar, and Nagios. IPS/IDS: Alertlogic, F5, Cisco SourceFire IPS Firewalls: PAN (PaloAlto Networks), PacketFilter, Checkpoint URL Filtering: Netsweeper | Email Security: Mimecast, Proof point | EndPoint Detection/NexGen AV: CrowdStrike, CB defense/response

Experience

Workato

Senior Security Engineer

May 2024Present · 1 yr 10 mos · Bengaluru, Karnataka, India · Remote

Bayzat

Senior Security Engineer

Nov 2023Feb 2024 · 3 mos · Remote

  • Conducted comprehensive security assessments for AWS cloud, ensuring robust security measures.
  • Facilitated the integration and optimization of native security services within the AWS environment.
  • Conducted thorough reviews of Terraform configurations to identify and address security issues. Implemented TfSec in CI/CD to review terraform code.
  • Deployed and configured the Cloud Security Posture Management (CSPM) tool, Wiz, to enhance security posture.
  • Developed InfoSec policy, Cloud Security policy, Change Management policy, and Incident Management policy and procedures documents.
AWS SecurityWizInfosec policyTfsecCloud Security

Coinswitch

Cloud Security Engineer

Nov 2021Nov 2023 · 2 yrs · Bengaluru, Karnataka, India

  • Everything Cloud Security & DevSecOps
  • Implementation of security baseline standards for Cloud Infrastructure at CSK
  • Working on AWS’s Cloud Security Services such as IAM (Identity and Access Management), SCP, Guard duty, SecurityHub, Trusted Advisor, Macie, Key Management Service, CloudTrail, Config, SSM (Patch Management), Cloudwatch events, VPC Flowlogs, Access Analyzer, etc.
  • Working across various cloud security domains such as Cloud Security Posture Management, Identity and Access Management, Data Protection and its application, Patch Management
  • Ensuing securing compliance (from SEBI) for security asset classes like Indian Equities / Mutual Fund
  • Effectively integrated SCA (Software Composition Analysis) and SAST (Static Application Security Testing) via Snyk, bolstering the security of our CI/CD pipeline.
  • Launched security automation initiatives, incorporating Slackbot, Wiz-jira, Wiz-AWS, Snyk-confluence, and Snyk-AWS code build, to close security vulnerabilities and enhance overall security measures.
  • Established automated cloud security response mechanisms through Wiz to swiftly address critical and unauthorized changes.
CybersecurityAmazon Web Services (AWS)Cloud SecurityCSPMDevSecOpsIncident Response

Nykaa

Senior Security Engineer

Sep 2020Nov 2021 · 1 yr 2 mos

  • Implementation of security baseline standards for Cloud Infrastructure at Nykaa
  • Worked on various AWS’s Cloud Security Services
  • Onboarded & configuration of all AWS accounts on Dome9(CSPM). Managing governance and compliance of each of AWS services and resources using Dome9 for CIS compliance benchmark.
  • Performed POC and Implementation of Security tools - EDR(CrowdStrike), Email Security(Mimecast), Cloud Security Posture Mgmt(Dome9), SAST & SCA(Github Adv Security, Checkmarx, Blackduck)
  • Created IRM from the scratch, made multiple runbooks for security incidents
  • Compared different security products and interacting with different stakeholders and security service/solution providers.
  • Setup Proper Incident response - Cloudwatch Events, Config rule alerts, EDR protection on EC2, Monitoring of Audit account Findings (GuardDuty, Security Hub, Macie)
CybersecurityAmazon Web Services (AWS)Cloud SecurityCSPMDevSecOpsIncident Response

Cognizant (prediktive contractor)

Application Security Analyst

Sep 2020Feb 2021 · 5 mos · United States

  • Perform and coordinate penetration testing activities, ensuring that security testing is automated during development
  • Implement application security tools and integrate them with the existing DevOps toolchain
  • Support the testing tools SAST, DAST, and SCA - Checkmarx, Acunetix, BlackDuck
  • Deployment & Integration of Risk-Based Vulnerability Management Software - Kenna Security
  • Share results with product teams and security architects
  • Work to ensure findings are remediated
  • Provide vulnerability analysis, proper security tool integrations, and creation of metrics in order to support data-driven decision-making
  • Work with development teams to ensure that appropriate assessment of security risks is performed
  • Implement application security best practices according to industry-recognized standards and frameworks such as OWASP, SANS, CIS
  • Kenna Security, BlackDuck, Checkmarx, Acunetix
CybersecurityDevSecOpsSASTDASTSCARisk Assessment+1

Cvent

Application Security Engineer II

Sep 2018Sep 2020 · 2 yrs · Gurgaon, India

  • + Vulnerability Assessment and Penetration Testing - Internal and External. Expertise in
  • identifying, Reporting, and mitigating security vulnerabilities associated with web applications. Working with different stakeholders to fix the vulnerability.
  • + Bug bounty - Reports Triaging/Validating, response, Internal Jira ticket creation with
  • Proper POCs and closure of bug bounty security issues raised on Cvent Responsible Disclosure program
  • + Validation of Application security issues reported on DAST tools and opening Jira tickets
  • + Static/Dynamic Source Code Analysis - SAST using Checkmarx and following Secure SDLC
  • guidelines for Secure Development.
  • + Participated in Secure code training and Security Champion Activity
  • + Created monthly reports for Application Security Vulnerability reporting trends. Created
  • monthly reports for 1 year trend for InfoSec KPIs.
  • + Train and Mentor new InfoSec Analysts on processes, incident handling techniques, VA,
  • DAST.
  • + Worked on DEMISTO (SOAR)-Security Orchestration Automation and Response tool onboarding & Security Incident Playbook creation support.
  • + Acted as a key contact for Deep analysis and POC creation for incidents escalated by SOC
  • regarding Web application attacks.
CybersecurityApplication SecurityDevSecOpsSASTDASTSCA

Orange business services

2 roles

Network Security Engineer

Dec 2016Sep 2018 · 1 yr 9 mos

  • + Good working knowledge on different SIEM platforms, real-time security events - monitoring and management.
  • + Internal Server Security Certifications
  • + Vulnerability Assessment and Security Auditing - Nessus & QualysGuard.
  • + Analysis and mitigation of Phishing attacks, DLP alerts, Network and Web threats.
  • + Conducted “Phishme” phishing simulation exercises to achieve user profiling for security
  • best practice training.
  • + AMEA Network Optimization:
  • ANO SOC - Handling network security of Orange Affiliates present in Africa
  • Responsible for preparing weekly and monthly report for ANO Affiliate country and present
  • it to Affiliate’s security team.
  • + CyberSOC International:
  • Worked on Proactive and Reactive security incidents corresponding to some elite Orange
  • customers.
  • + Preparing technical analysis reports and dashboards of the weekly security incidents and
  • their possible threats.
  • + Excellent analytical Logs analysis, trends reporting, and troubleshooting skills.
  • + Firewall Management - rule configuration and troubleshooting for different flow access
  • issues. PAN, Cisco, Checkpoint, Juniper, Unix BSD - Packet Filters.
  • + IPS Signature analysis and modification for minimizing false positive count that helped
  • in alert overhead reduction.Alert Logic & Cisco Sourcefire IPS.
  • + Managing Legal Obligation Regulatory Requests being an ISP
CybersecurityNetwork SecurityIPSFirewallsIncident ResponseSIEM

GET-SOC

Aug 2016Nov 2016 · 3 mos

  • Good working knowledge on SIEM tool, Real-time Security events - their monitoring and management.
  • URL blocking activity using NetSweeper.
Cybersecurity

Berry9 it services (b9its)

Intern as a Security Analyst

Feb 2016Apr 2016 · 2 mos · Hyderabad Area, India

  • Perform vulnerability testing, risk analysis and security assessments
  • Conduct internal and external security audits
  • Analyze security breaches to determine their root cause
  • Establish plans and protocols to protect digital files and information systems against unauthorized access, modification and/or destruction
  • Train fellow employees in security awareness and procedures
Cybersecurity

Gurgaon police cyber crime cell

Intern

Jun 2015Jul 2015 · 1 mo · Gurgaon, India

  • I got the opportunity to watch various Police Station procedures that are being practically followed in Cybercrime cases. The Cyber Crime Cell is specifically framed to exclusively deal with disputes related to crimes that deal with the internet or computers in some way. I had a great opportunity to explore the cases that come in the Cyber Crime Cell during the period of my Internship. I worked on a project titled ”E-commerce Fraud and Investigation.”
Cybersecurity

Education

Rochester Institute of Technology

MicroMasters Program — Cybersecurity

Jan 2017Jan 2018

Shri Mata Vaishno Devi University

Bachelor of Technology (B.Tech.) — Computer Science

Jan 2012Jan 2016

Stackforce found 100+ more professionals with Aws Security & Cloud Security

Explore similar profiles based on matching skills and experience