Taniya R.

Product Engineer

Dubai, United Arab Emirates10 yrs 6 mos experience
Most Likely To Switch

Key Highlights

  • 10 years of experience in cybersecurity services.
  • Transformed VMaaS into a customizable service.
  • Managed vulnerability assessments for high-profile clients.
Stackforce AI infers this person is a Cybersecurity expert specializing in vulnerability management and cloud security.

Contact

Skills

Core Skills

Vulnerability AssessmentInformation SecurityCloud SecuritySecurity Operations

Other Skills

Amazon Web Services (AWS)Azure SentinelConfiguration ManagementContainer SecurityExporter Pro and HyenaGRCGovernance as codeIT OperationsIncident ResponseInformation Security Management System (ISMS)Log AnalysisMDRMalware AnalysisMicrosoft AzureMicrosoft Defender for Cloud

About

Bringing 10 years of experience in cybersecurity services and currently work as a VMaaS Service Manager for the UAE's one of the largest MSS, where I have transformed VMaaS into a customisable service that includes risk-based vulnerability assessments, personalised client reports, and simplified patching/remediation methods. I recently added WebApp scanning, CIS and NESA compliance scans, and Kubernetes cluster vulnerability scans as additional services, that features pricing calculator, SLA, service architecture, and deliverables. Prior joining Help AG, I held various cybersecurity responsibilities at NetApp, Microsoft and Wipro where I handled a variety of challenging security incidents for high-profile clients. I've worked as a service design expert, security consultant, cloud security engineer, security administrator & security analyst, focusing on both on-premises and multi-cloud infrastructure, and have experience on multiple tools like : Microsoft Defender for Cloud, Azure Sentinel, Tenable.sc, Qualys, Symantec Endpoint,Tenable.io , RedCloak EDR, Scoutsuite, Trivy, Kubescan, QRadar, Stacklet, Tripwire Enterprise. My M.Tech is from VIT in Vellore, and my BSc honors is from Miranda House in Delhi.

Experience

Help ag, an e& enterprise company

2 roles

Vulnerability Management Lead

Jul 2025Present · 8 mos · Dubai, United Arab Emirates

Vulnerability Management Specialist

Mar 2023Jul 2025 · 2 yrs 4 mos · Dubai, United Arab Emirates

  • Manage the vulnerability management service lifecycle and build it as VMaaS for customers in the UAE region.
  • Established processes & assisted in pricing for
  • 1. Vulnerability assessment of assets, determining risk surface area and priority rating using risk based vulnerability approach (RBVA)
  • 2. Remediation coordination, generated script to create a simple to navigate and close vulnerability in a document that included the executive summary, IT summary, and third-party vendor assessments.
  • 3. Compliance scanning using CIS and NESA frameworks and designed MBSS (minimum baseline security standard) for specific to customer domain.
  • 4. Web Application scanning with custom selenium scripting, session cookie, login form etc.
  • Created a SLA/OLA document that translated the service delivered to time utilisation for effective resource allocation and cost of service projection.
  • Created a common DL for receiving requests, mapping it to set SLAs, and automated service request creation in the ticketing application.
  • Improved service delivery tiers: basic, advanced, and premium with add-on services.
  • Managing 10+ UAE government & semi-government customers by scheduling authenticated scans, creating scan policy, dashboard, report templates, outstanding remediation tracking, recasting vulnerability severity and score, assisting in remediation, detection of false positive.
  • Administrating platform by upgrading Tenable.sc &Nessus scanners, installing new scanner, application of security patches, resolve plugin feed failure, asset database accessibility, repository planning, scanner reachability & manage scanner freeze window
  • Monthly reporting for detected vulnerabilities, trend analysis for 3 months, outstanding remediation tracking, vulnerability severity summary, RBVA reporting and compliance scan reporting
  • Managing vulnerability as well as web app scanning via Qualys for payments industry, network as well as host-based scanning, maintaining host agent health.
Vulnerability AssessmentThreat & Vulnerability ManagementInformation SecurityWeb Application SecurityConfiguration ManagementTripwire Enterprise+5

Netapp

Cloud Security Engineer

Oct 2021Mar 2023 · 1 yr 5 mos · Remote

  • Deployed internal scanner managed via tenable.io, scheduled external scans, enabled cloud connectors, and managed vulnerability management portfolio for several product teams.
  • Scanned AWS FSx for ONTAP pre-deployment components and builds for FedRAMP authorization.
  • Implemented open-source software such as Prowler and Scout-Suite for CSPM, Trivy for container scans, Kube-scan for kubernetes risk assessment, and Cloud Custodian for cloud governance as code.
  • PoC / PoV for Automox, Stacklet, and Rapid7 Insight Appsec.
Vulnerability AssessmentMicrosoft AzureContainer SecurityInformation SecurityAmazon Web Services (AWS)Governance as code+3

Microsoft

2 roles

Azure Security Support Engineer - APAC

Sep 2021Oct 2021 · 1 mo

  • Promotion
Microsoft AzureInformation SecurityTeam LeadershipCloud SecurityMicrosoft Defender for CloudQualys+1

Azure Security Support Engineer

Jan 2020Aug 2021 · 1 yr 7 mos

  • Worked on Azure Security Center, Azure Sentinel, Storage ATP & SQL ATP as a support engineer
  • Assisting customer's to understand the product, features and providing guidelines/best practices to implement the product
  • Assisting in resolving recommendations, analysis of security alerts, creation of custom policy for security resource provider, continuous export of logs to Log Analytics workspace, SIEM (via event hub), Just in time access creation, file integrity monitoring etc. in Security Center
  • Assistance in data source integration to Azure Sentinel via built-in connector as well by using workarounds, creation of simple playbooks, implementation of available rule templates etc. in Azure Sentinel
  • Provide knowledge and information on preview features as and when available
  • Gather customer feedbacks and update product developer teams
  • Identify bugs in workflows
  • Assist on Storage ATP configuration, SQL ATP and Qualys extension configuration.
  • Basic understanding of NSG rules, VM extensions, event hub, Log Analytic Workspaces & solutions related to Security
Microsoft AzureInformation SecurityCloud SecurityMicrosoft Defender for CloudQualysAzure Sentinel

Wipro limited

4 roles

Senior Security Analyst

Promoted

Nov 2018Dec 2019 · 1 yr 1 mo

  • QRadar:
  • Expertise in incident handling & response, security incident triage & threat hunting
  • Administration of security operations to identify true positives & fine tune false positive
  • Integrate log sources such as on-prem AD, DNS, DHCP, Checkpoint firewall etc.
  • Integrate SecureWorks portal with ServiceNow SecOps module
  • Handled 25+ C1 priority security incidents and reduced impact rapidly
  • RedCloak AETD:
  • Package creation, deployment across servers & workstation
  • Control network access of infected assets via host isolation & disrupt suspicious process by procwall module
  • Track notable events and take necessary action
  • Azure Security Center & Azure Sentinel:
  • Created subscription, configured network security groups, installed Microsoft monitoring agent on windows workstations
  • Comply recommendations, configured mail for alerts and implemented just-in-time VM to lock inbound traffic to VMs
  • Involved in project to incorporate SIEM services using Azure Sentinel.
  • Sandbox Implementation:
  • Implemented Cuckoo Sandbox for automated malware analysis of files reported as suspicious
  • SOP & KEDB creation:
  • Created SOP on incident handling, categorization of incidents, spam analysis and rule fine tuning
  • Established database for known errors, false positive, fine tuning, corrective & preventive actions for C1 incidents
QRadarMicrosoft AzureInformation SecurityTeam LeadershipSecurity OperationsCloud Security

Security Analyst

Promoted

Mar 2017Nov 2018 · 1 yr 8 mos

  • SOC Operations & Incident Analysis (QRadar):
  • Expertise in incident handling & response, security incident triage , threat detection & response.
  • Administration of SOC operations to identify true positives, design new correlation rules, set up dashboards & generate reports.
  • Performed security monitoring and identified security incidents by analyzing network traffic and logs data via SIEM tools like IBM QRadar
  • Analyzed the security incidents based on kill chain process as part of cyber kill chain framework
  • Malware Analysis (static & dynamic) in sandbox environment i.e Cuckoo.
  • Coordinated with security engineering team to fine-tune rules in firewall/IPS/McAfee NSM
  • Log Integration:
  • Integrated various log sources network/security controls like AD, McAfee ePO, Windows Server, Cisco ASA etc.
  • Integrated third party extension threat feed search engine like IPVoid, Virus-Total, etc.
  • Spam Mail Analysis:
  • Handle, mitigate and investigate email threats and categorize accordingly.
QRadarInformation SecuritySecurity Operations

Senior Security Administrator

Promoted

Oct 2016Mar 2017 · 5 mos

  • SEPM & McAfee ePO:
  • Installation of SEPM with SQL/embedded database, configuring group update provider and LUA
  • Configured policy for various component like virus and spyware, firewall, IDS & white-listing hashes.
  • Created feature set and packages as per requirement.
  • Installation of license files
  • Upgraded from version 12.x to version 14
  • Configured proxy, heartbeat, live update settings, replication and backup for SEPM
  • Configured policy on McAfee ePO for Threat Prevention & Web control
  • Qualys, McAfee Vulnerability Manager & Tenable IO:
  • Troubleshoot potential causes of scan failure (authentication failure, scanner offline, port block)
  • Created asset tag & scan template as per compliance standard SOX, PCI DSS
  • Security Team Operations & Risk Management:
  • Provided evidence for audit requirement (SOX, PCI DSS)
  • Resolved multiple C1 incidents & provided RCA.
  • Connect on multiple calls related to change management, problem management & infrastructure improvement.
  • Identification of risks and updated in risk register with impact and urgency score, plans to mitigate etc.
  • TrendMicro Server Protect:
  • Install and configure information server, normal server & management server
  • Add filers to NS and IS , initiate scans & configure rules/policies.
Vulnerability AssessmentThreat AssessmentInformation SecurityTeam LeadershipSymantec Endpoint ProtectionQualys

Security Administrator

Jun 2015Oct 2016 · 1 yr 4 mos

  • SEPM & Vulnerability Management:
  • Health monitoring of SEPM/McAfee servers across multiple business domains expanded across 35 global regions.
  • Ensure timely updates of definition and other content (SONAR/amcore etc.) in Symantec endpoint protection manager & McAfee epo.
  • Analyse and customize health & compliance report.
  • Troubleshoot SEP at servers.
  • Weekly report & remediation of unhealthy clients.
  • Vulnerability assessment and closure.
Information SecuritySymantec Endpoint ProtectionQualys

Education

Vellore Institute of Technology

Master of Technology - MTech — Information Technology

Miranda House, Delhi

Bachelor's Degree — Physics

Stackforce found 100+ more professionals with Vulnerability Assessment & Information Security

Explore similar profiles based on matching skills and experience