Neeraj Vij

DevOps Manager

Gurgaon, Haryana, India21 yrs 6 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 20 years of experience in cyber security.
  • Expert in security architecture for hybrid cloud environments.
  • Proficient in managing enterprise security programs.
Stackforce AI infers this person is a seasoned Cybersecurity Architect specializing in enterprise security solutions across various industries.

Contact

Skills

Core Skills

Cloud SecuritySecurity Architecture DesignApplication SecurityPenetration Testing

Other Skills

Application Security ArchitectureCISSPCyber-securityCybersecurityGRCHybrid CloudIT Security AssessmentsIT Security OperationsIT Security Policies & ProceduresIT StrategyInformation SecurityInformation Security ManagementJava Enterprise EditionOWASPProgram Management

About

Versatile cyber security professional with over 20 years of extensive experience in managing, executing, architecting security solutions and programs across enterprise. Proficient in working across Cyber security domains (Cloud security, AI Security, Application Security, Infrastructure Security, Risk Assessments, Penetration testing, GRC, Audit & Information Security etc.) Strong experience of securing applications and infrastructure across various industry domains (cloud, data analytics, warehousing, digital access management, digital learning, enterprise intranet solutions, data lakes, project management, ITSM & ITBM etc.) and create strategic technical recommendations based on corporate/business unit requirements. Thoroughness, ability to multi-task, to work both independently and manage teams. Adept in accomplishing short and long term goals across organization business units Core Skills ● Security architecture & reviews in hybrid cloud environments (AWS, Azure, and GCP), Securing cloud workloads, and automation. ● Application security, secure- SDLC, DevSecOps, Security in Agile product development ● Enterprise security program management ● Penetration testing (Web/Mobile-iOS/Android), Cloud security configuration assessments ● Cyber Security, security audits, compliance, incident response, policies & standards ● Enterprise security risk assessments- Web, mobile, Cloud/Saas offering, COTS products ● Enterprise vulnerability management (on-prem and cloud environments) ● Vendor & 3rd party risk assessments

Experience

Gartner

2 roles

Principal Security Architect

Promoted

Oct 2022Present · 3 yrs 5 mos

Security Architect

Nov 2018Oct 2022 · 3 yrs 11 mos

  • Brief overview
  • > Security architecture/integration reviews of multiple AI based services/applications like( Azure
  • OpenAI multiple use cases, Databricks, MS Copilot, Adobe etc.) vendors from domains in (Legal, Audio
  • Visual transformations, Job listing, GenAI content detection, Intranet experience, Education/learning )
  • > Setup & management of GRC tool Onetrust for automating multiple tasks of security architecture
  • reviews, capture review artifacts, creation of central repository of risk, observations and exceptions.
  • > Execute and manage a Lean Security Risk Review (LSRR) program to perform security risk assessments of business critical applications deployed on-prem and hybrid cloud environments, SaaS offerings and COTS products. Program is executed in a risk and compliance based approach to support internal/client security requirements and audits.
  • > LSRR Program facilitated secure migration of on-prem applications to hybrid cloud environments by identifying risk posture of legacy applications and establishing sufficient mitigation controls in cloud architectures.
  • > As a part of LSRR conducted vendor risk assessments, security architecture and complex integrations review of major SaaS applications with the Gartner systems. Majority of the workflow integrations were reviewed and approved with MFA supported for all enterprise employees for enhanced security. Security architecture reviews covered major SaaS vendors and integrations involved applications hosted on AWS, Azure, GCP and on-prem data centers. Security assessments coverage spread across industry domains like Data warehouse ETL, CRM, Analytics, Office productivity tools, Finance, Intranet solutions, Cloud cost management and auditing access,project management, SSO, Digital access management and learning, MDM and mobile BYOD(iOS, Android) etc.
Application Security ArchitectureApplication SecurityCloud SecurityInformation Security ManagementPenetration TestingRisk Assessment+5

Mckinsey & company

Information Security Architect

Jun 2011Oct 2018 · 7 yrs 4 mos · Gurgaon, India

  • > Develop and drive application security standards to ensure adequate protection. Translate
  • standards to baseline security requirements for IT teams derived from industry best practices from SANS
  • and OWASP
  • > Significantly improved the IT application security posture by threat modeling high risk applications
  • > Managing team of security consultants (penetration testers) on the end-to-end penetration testing
  • and plan to remediate risk, threats, and vulnerabilities. Overseeing a team of security engineers and
  • security analyst for Vulnerability Management, evaluations of Enterprise security products, support and
  • rollouts
  • > Partner and collaborate with other IT and security architects to create, maintain and drive
  • technology strategies and roadmaps, lead larger and complex projects and simplify process workflows
  • > Support application and operations teams who are delivering secure code and infrastructure by
  • ensuring closure of high risk vulnerabilities from IBM AppScan, BurpSuite, Nessus, Nexpose and manual
  • assessments
  • > Simplified team's risk assessment review and penetration testing process by eliminating steps
  • improving turnaround time for project teams
  • > Interview and hire information security staff. Coach, mentor and manage team performance
  • > Lead POC and evaluate security initiatives like Virtual Data Rooms, and Devops. Compile
  • recommendations based on research from sources like Gartner for different security projects
  • > Managing project and timelines for security initiatives of offensive security using red team and
  • crowd sourcing model
  • > Created and perform application security awareness program
  • > Managing vendor risk assessment projects and vendor engagements (Vendor among top 4
  • consulting firm)
  • > Researched and provided security perspective on emerging technologies
Application SecurityApplication Security ArchitectureCISSPCloud SecurityCybersecurityIT Security Assessments+14

Polaris software lab

Consultant

Feb 2008May 2011 · 3 yrs 3 mos · Gurgaon, India

  • Consultant - Java/Application Security

Wipro technologies

SPE

May 2007Feb 2008 · 9 mos

Hcl technologies

Lead Engineer

Sep 2005May 2007 · 1 yr 8 mos

Birlasoft (india) limited

SE

Aug 2004Sep 2005 · 1 yr 1 mo

Stackforce found 100+ more professionals with Cloud Security & Security Architecture Design

Explore similar profiles based on matching skills and experience