Bhumish Gajjar

DevOps Engineer

Vadodara, Gujarat, India11 yrs 6 mos experience
Most Likely To Switch

Key Highlights

  • Over 11 years of experience in Cyber Security.
  • Expert in Application Security across multiple platforms.
  • Proven track record in vulnerability management and risk assessment.
Stackforce AI infers this person is a Cybersecurity expert with extensive experience in application and cloud security.

Contact

Skills

Core Skills

Security EngineeringApplication SecurityApplication Security ArchitectureRisk ManagementPenetration TestingCloud SecuritySecurity OperationsVulnerability ManagementWeb Application SecurityMobile SecurityVulnerability AssessmentSiemNetwork Security

Other Skills

APIsBurp SuiteCybersecurityDNSDefensible SecurityDigital ForensicsDistributed Control System (DCS)FirewallsHoneypotsIDSISO 27001ISO 27001 Lead AuditorIT AuditIT Security AssessmentsITIL

About

Cyber-Security Engineer with more than 11 years of professional experience plus a full-time Master's degree in Computer and Network Security. Application Security: • Tested and identified vulnerabilities in several applications on different platforms - Web, Android, iOS, KaiOS, Tizen, API • Worked on applications of various domains like Finance, Healthcare, Telecom, Live streaming, Media, Cloud, IoT devices, Industrial Control Systems (ICS), CRMs, eCommerce, Banking Security Operations: • Setup of SIEM from scratch to integrate and monitor world's largest mobile data network's assets • SIEM installation, log device integration, log analysis and forwarding, parsing, correlation rules, monitoring and triaging of incidents Vulnerability Management: • Driving vulnerability management for large and mid scale organizations (5k-20k assets) • Identification, reporting and tracking of vulnerabilities in Servers, Endpoints, Cloud and Containers • Managing HIPS, IDS-IPS, EDR, DLP, DDoS Protection, IDAM solutions Specialties: Application Security, Burp Suite, NMap, Metasploit, Source Code Review, Qualys, Fortify, WebInspect, VA-PT, Linux, SIEM, Container Security, Mobile Security Certifications: • Crest Practitioner Security Analyst (Dec 2022) • ISO 27001:2013 certified Lead Auditor (Bureau Veritas - Feb 2016) • Certified Ethical Hacker (CEH - EC-Council - May 2015) • Network+ (CompTIA - April 2012) • Cloud Computing (RackSpace - June 2013) Courses: • Cisco Cyber Range • McAfee Nitro SIEM Administration • Qualys Container Security • Qualys Vulnerability Management • Hacking and Securing Cloud Infrastructure - NSS • AWS IoT Security • AWS Advanced Security • Azure Security Technologies • API Security Architect • ISC2 - Ransomware • Splunk Fundamentals • Scrum Fundamentals **My posts and comments are my own views/opinions, not related to my employer**

Experience

Mastercard

2 roles

Lead Information Security Engineer

Promoted

Apr 2025Present · 11 mos · Vadodara, Gujarat, India · Hybrid

Security EngineeringRisk ManagementApplication SecurityVulnerability ManagementSecurity Architecture Design

Senior Information Security Engineer

Jan 2024Mar 2025 · 1 yr 2 mos · Vadodara, Gujarat, India · Hybrid

Security EngineeringRisk ManagementApplication Security ArchitectureSecure SDLCThreat Modeling

Civica

Lead Penetration Test Engineer

Dec 2021Jan 2024 · 2 yrs 1 mo · India · Remote

  • Strategic planning of end-to-end Penetration testing projects from scoping till delivery
  • Implementing risk based methodology to assess findings and coordinating their remediation with business-units spread across UK and APAC regions
  • Evaluation of tools related to Cloud Infrastructure Security and Penetration Testing
  • Mentoring and managing a team of pen-testers
  • Penetration testing of various platforms to find security vulnerabilities and recommend effective mitigation controls in - Azure and AWS cloud infrastructure, Kubernetes, Web applications, Android and iOS applications, Thick client applications, Network infrastructure
Cloud SecurityApplication SecurityRisk ManagementMicrosoft AzurePenetration Testing

Arrow electronics

Senior Engineer II - IoT Security

Sep 2020Dec 2021 · 1 yr 3 mos · India · Remote

  • Risk Management - identifying the risk associated with each vulnerability using various risk-based formulas and suggesting suitable actions
  • Security Operations - monitoring the overall corporate environment using tools like XDR, SIEM, EDR and fine-tuning various log sources for optimal security
  • Automotive Security
  • Vulnerability Management for on-prem servers, workstations, cloud and containerized applications
  • Security Automation
  • AWS Cloud and Container Security
  • ISO 27001 Audits
Application SecurityISO 27001 Lead AuditorIoT SecuritySecurity OperationsVulnerability Management

Emxcel

Senior Cyber Security Analyst

Apr 2020Aug 2020 · 4 mos · India · Remote

  • Managing end-to-end security of internal and public-facing applications, including Web apps, APIs, Portals, Android and iOS apps
  • PoC of various security tools and devices
  • Setting up overall security management process for the organization
  • Guiding on Infosec hygiene practices to help secure the company's assets, data and employees
Mobile SecurityFirewallsNetwork SecurityWeb Application Security

Hexagon ab

Cyber Security Analyst

Dec 2018Mar 2020 · 1 yr 3 mos · Gandhinagar, Gujarat, India

  • Testing of PAS tools and products for security vulnerabilities
  • Dynamic/Static Testing and Reverse Engineering of Source-code
  • Vulnerability Testing, Tracking and Management - related to ICS products and IT assets
  • Patch Management related to third party software and libraries affecting PAS products
Distributed Control System (DCS)Risk ManagementVulnerability AssessmentPatch ManagementWeb Application Security

Jio

2 roles

Deputy Manager - Security Assurance

Promoted

Apr 2016Nov 2018 · 2 yrs 7 mos · Mumbai, Maharashtra, India

  • Security analysis of Desktop, Web and Mobile based applications
  • Penetration testing at Network and Application level
  • Hands-on experience with manual and automated security testing
  • Reverse engineering of code for understanding the logic and to bypass security checks
  • Security assessment of internal as well as third party applications based on different platforms, including Android& iOSMobiles, IOT devices, Thick-client and Thin-client applications for Windows and macOS, Feature phones, STB devices
Application SecurityMobile SecurityIoT SecurityRisk ManagementVulnerability Management

Assistant Manager - Security Operations and Digital Forensics

Apr 2014Mar 2016 · 1 yr 11 mos · Mumbai, Maharashtra, India

  • Working as a part of Information Security Operations Center (ISOC), handling the integration and monitoring of SIEM and managing other security solutions.
  • Setup of SIEM solution from scratch to analyze logs with over 30k EPS -- monitor and manage world's largest mobile data platform's security alerts
  • Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from Multiple log sources
  • Monitoring the IDS alerts, mitigating the alerts for resolving the problems
  • Doing analysis of malwares captured in the network
  • Configuring syslog, rsyslog, SIEM collector-agents for log forwarding and device integration
  • Working with logs from devices/servers like DB, Web, ASA, CDN, NIPS, HIPS, PIM, IDAM, UAG, ACS, DLP, CPI
  • Writing and deploying parsers for logs from various devices
  • Validating and triggering use-cases for Telecom, Cloud and Infra environments
  • Monitoring the vulnerabilities and patches on regular basis
  • Performing Forensic analysis of security incidents inside the environment
  • Scanning the environment for any vulnerabilities as part of Vulnerability Management team
  • Preparing security bulletins and advisories for internal circulation
  • Developing and managing a portal - knowledge base for the InfoSec team
Security Information and Event Management (SIEM)Digital ForensicsSecurity OperationsIntrusion DetectionLog AnalysisSIEM

Centre for development of advanced computing (c-dac)

IT & Network Security Research Intern

Aug 2013May 2014 · 9 mos · Pune, Maharashtra, India

  • Internship as a part of Masters degree dissertation and thesis, performing research on project title - An Improvised Honeypot system using Honeytokens for trapping Cyber Attackers.
  • The project included Malware capture, Intrusion detection, OWASP concepts, Honeypots, FTP/Web/DB servers and Python scripting.
Network SecurityMalware AnalysisHoneypots

Education

Gujarat Technological University

Master of Engineering (M.Eng.) — Computer Engineering

Jan 2012Jan 2014

Gujarat Technological University

Bachelor of Engineering (BE) — Information Technology

Jan 2008Jan 2012

Fatima Convent Senior Secondary School

XII Science — Physical Sciences

Jan 2006Jan 2008

Stackforce found 100+ more professionals with Security Engineering & Application Security

Explore similar profiles based on matching skills and experience