Arun Khakh
Information Security Analyst at McKesson Europe AG- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
Topline Score
Bio
Credentials
-
Certified SAFe® 5 Practitioner
Scaled Agile, Inc.Mar, 2021- Nov, 2024
Experience
-
McKesson Europe AG
-
Germany
-
Pharmaceutical Manufacturing
-
100 - 200 Employee
-
Information Security Analyst
-
Oct 2018 - Present
• Collaborating with Windows, Unix, Linux and IT Infrastructure teams to drive remediation of reported vulnerabilities through risk/threat based assessment of security controls and tools.• Articulate risk and business impact to stakeholders• Ability to convey the urgency and need to remediate vulnerabilities commensurate with the risk it presents to McKesson • Collaborating with Windows, Unix, Linux and IT Infrastructure teams to drive remediation of reported vulnerabilities through risk/threat based assessment of security controls and tools.• Articulate risk and business impact to stakeholders• Ability to convey the urgency and need to remediate vulnerabilities commensurate with the risk it presents to McKesson
-
-
-
Celesio UK
-
United Kingdom
-
Hospitals and Health Care
-
1 - 100 Employee
-
IT Security & Compliance Analyst
-
Feb 2015 - Apr 2018
• Managed information security threats and vulnerabilities and improved information security and data protection controls• Evaluate systems, networks & applications to ensure compliance to information security standards and minimise potential risk to the computing infrastructure • Provide support in the regular monitoring of IT process compliance in accordance with the SOX Celesio IT SOX control framework• Maintain control framework, including maintenance of control ownership• Own relationships with a number of SOX process owners and take responsibility for the collation of regular SOX reporting provided by process owners• Provide support in regular reviews of internal compliance testing protocols and sample sizes for validity and work with process owners to ensure completeness of regular testing• Documentation of identified non-compliance in conjunction with process owners, including definition of remediation planning• Work with third parties on annual penetration testing and own and co-ordinate the remediation actions.• Track remediation plan delivery by allocated process owners and compile initial reporting of deliveryWorked on various different streamlines and projects:• Cyber Security: Threat & Vulnerability Management (PowerBI)• General Data Protection Regulation (GDPR)• Web Application Firewall (WAF) - F5 load balancer/Imperva - Incapsula• Differentiated Controls (Application Compliance)• Application Security Penetration Testing
-
-
IT Service Analyst
-
Feb 2015 - Aug 2016
-
-