Tanveer Bangi
Security Analyst at ParamInfo- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
Topline Score
Bio
Credentials
-
Information Security Management Systems(ISMS) Auditor (ISO 27001 LA)
The International Register of Certificated Auditors (IRCA) -
Certified Ethical Hacker (CEH)
EC-Council -
Cisco Certified Network Associate Industrial (CCNA )
Cisco -
Cisco Certified Network Professional (CCNP)
Cisco -
Microsoft Certified Systems Engineer: Windows Server 2003 (MCSE)
Microsoft -
Qualys guard vulnerability management
Qualys
Experience
-
ParamInfo
-
United Arab Emirates
-
IT Services and IT Consulting
-
100 - 200 Employee
-
Security Analyst
-
May 2023 - Present
Perform real-time investigation, analyzing of events using SIEM tools Splunk of Network Security components devices such as IDS/IPS, Firewalls, Web Application firewalls, Operating Systems like Windows and UNIX, Databases and other device. Creating filters, Queries, rules etc., in Splunk SIEM tool for monitoring purpose Working as part of SOC handling Cyber security incidents and correlating remediation actions ensuring proper closure. providing recommendations regarding security incidents mitigation which in turn makes the customer business safe and secure. Responsible for Integration of different log sources, Rule Tuning in Splunk. Configuring customized reports in Splunk as per the client requirement Developed SOC Play-books and procedures for tackling cyber security incidents. assisting Tier 1 and Teams with assistance and expertise. Manage Carbon black and CrowdStrike EDR Solution and perform triage analysis on infected hosts and leveraging same for threat hunting. Support malware analysis, extracting IOC’s and threat hunting leveraging the extracted IOC’s. Also configuring the IOC’s across different security devices for detection and containment. Administration of Qualys console which includes of VMDR, Asset View, Tagging, Connectors setup, agents’ installation, and user management In Qualys VMDR module, performing Ad hoc Scans, scheduling scans, scheduling reports creation of dashboards as per the management requirements and compliance requirements, Assets management, troubleshooting scans, setup of authentication, creation of option profile based on custom search lists, performing Map Scans, etc Scheduling Ad-hoc Vulnerability scan requests and report generation in Qualys Generating reports based on vulnerability assessments and presenting them to clients Investigating malicious phishing emails, domains and IPs using open-source tools and recommend proper blocking based on analysis Show less
-
-
-
Tech Mahindra
-
IT Services and IT Consulting
-
700 & Above Employee
-
Senior Security Analyst
-
May 2017 - Nov 2022
Worked as Senior Security Analyst in Tech Mahindra SOC for monitoring, analyzing logs from various Security/Industrial appliances using LogRhythm Responsible for LogRhythm tool administration and vendor management Responsible for Integration of different log sources, Rule Tuning and Event Mapping in LogRhythm Incident reporting and Management for various incident/security alerts triggered by LogRhythm Log monitoring and incident analysis or various devices such as firewalls, IDS/IPS, windows servers and webservers etc., Potential to bring any possible security threats or violation of Security Policy to the notice of the information Security Manager Creating filters, Queries, rules etc., in LogRhythm SIEM tool for monitoring purpose Configuring customized reports in LogRhythm as per the client requirement Prepared Daily, Weekly and Monthly reports along with complete analysis and recommendations to the clients Creation of Dashboards as per the client requirement and security threat monitoring In Asset-view, tagging the assets based on a common category, setting up AWS connectors for asset discovery, installed agents’ management. Managing the vulnerabilities and their associated risk with respective Teams follow up. Tracking of Vulnerabilities through Qualys and Ticketing system Show less
-
-
-
Tech Mahindra
-
IT Services and IT Consulting
-
700 & Above Employee
-
Senior Information Security Specialist
-
Jun 2013 - Mar 2017
As an Information security team member my responsibilities are: Ensuring that location is compliant to ISO 27001 standards. Designing and implementing ISMS policies. understanding the Client security requirements from master service agreement andprepare SCI document. Ensuring client specific controls are implements in work zones. Performing internal security audit. Follow up with teams for closure of gaps identified in the internal security audit. Facilitating client/third party audits. Information security risk assessment. Periodic review of risk register for effectiveness. Business continuity management and disaster recovery plan. Review of Business Continuity Drill reports. Analyzing information security impact whole evaluating any change due to technology orbusiness requirements. Security incident handling. Providing awareness to associates on organizations information security policies.Resume of Tanveer Bangi Page 4 Having knowledge on General Data protection Regulation (GDPR). Reviewing vulnerability assessment and penetration test reports of applicable networkdevices and ensuring that vulnerabilities identified are closed on a timely manner. Review of firewall rules on regular basis. Periodic review of physical security controls. Infrastructure risk assessment. Review of various security metrics on regular basis. Security incident investigation and root cause analysis. Show less
-
-
Network Administrator.
-
May 2010 - Jun 2013
Configuration and troubleshooting of routers & switches. Performed Router configurations and troubleshoot LAN inter-networking problems. Undertook troubleshooting of network connectivity problems and day-to-day operations Monitoring and troubleshooting ISDN, leased lines and MPLS lines Checking Bandwidth usage as well utilization of link. Checking status of CPU process time and Memory utilization. Developed and implemented documentation for NOC. Created and provided weekly Network Performance Reports to external service provider. Define procedures and documentation for local and wide area network. Troubleshooting the Leased Lines & ISDN Show less
-
-
Education
-
Bachelor of Computer Application
Bachelor's Degree