Management professional with proven leadership skills and a strong focus on performance improvement. Expertise in enhancing workflows and operational processes to drive team success. Demonstrated success in implementing support initiatives that boost team performance and customer satisfaction. Achievements include increased efficiency in support operations and significant growth in customer retention rates.
Overview
15
15
years of professional experience
1
1
Certification
Work History
Senior Engineer
Hanover Insurance
Worcester
09.2019 - Current
Design and implementation of System Center co-management (MEM) to manage over 6,000 endpoints, including Windows and MacOS workstations.
Implement DLP policies Microsoft Azure and 365.
Conduct endpoint assessments using Nessus Tenable to advance the security enhancements for endpoints to management.
Planning, researching and developing security policies, standards and procedures using NIST and ISO frameworks.
Documentation and enforcement of policies and procedures.
Managing security assessments for new applications.
Working with Forensics team to investigate critical cases, analyzing filesystems, memories, and network flows as well traffics to find the root cause of incidents.
Developing and implementing business continuity and disaster recovery plans for endpoints with authored Business impact Analysis (BIA).
Built security awareness, incident response and escalation program.
Led engineering projects to enhance insurance product efficiency and performance.
Developed technical specifications for new software applications and systems integration.
Analyzed data to identify trends and improve engineering processes within the organization.
Coordinated project timelines and resources to facilitate timely delivery of engineering solutions.
Implemented best practices in engineering standards and procedures.
Monitored performance metrics to identify areas of improvement.
Led team meetings to discuss project progress and address issues.
Resolved escalated customer issues in a timely manner.
Led quality assurance efforts, establishing metrics and procedures to maintain high standards across projects.
Supervised IT support staff in daily operations
Developed IT policies and procedures for best practices
Analyzed system performance to enhance efficiency
Kept project teams on-task with proactive control of budgets, schedules and scopes.
Evaluated emerging trends in information technology to recommend upgrades or improvements.
Collaborated with other departments to develop innovative solutions for complex problems.
Reviewed and approved project plans prior to implementation.
IT Security Engineer
UMASS Medical School
Worcester
04.2017 - 09.2019
Led security team built and maintain SOC 2 compliance.
Oversee risk remediation activities currently involving more than 100 servers at multiple campuses locations.
Authored security architecture design documentation and standard operating procedures.
Led team responsible to designed and implemented SCCM endpoint monthly patching procedure for 7,000 workstations, 225 Linux servers patching and vulnerability scanning using Tenable Nessus.
Implement and Managed McAfee ePO for Servers and workstations.
Coordinate staff training sessions and enforce IT processes to ensure consistency with cyber security standards.
Developed IT standards and policies designed to monthly workstations and server patching.
Development of SIEM products and big data related technologies such as Nessus and Splunk.
Built a Splunk Enterprise Security POC environment to test store endpoints for security risks.
Implemented and supported database security data protection and encryption, server security, security information and event manager.
Implemented and managed cloud technologies such as MS Azure Security, MS O365 and AWS.
Managed vulnerability assessment program, scans and reporting using Tenable Nessus.
Prepared trainings and knowledge transfer documentations for security junior engineers and help desk support staffs.
Drafted incident response plans and updated technical manuals in an effort to enhance system security documentation.
Designed and implement security processes and procedure performing cost benefit analysis on all security relate strategies.
Manage Blue Coat web content filter.
Developed and Maintained new IT security policies documentation, protocols and maintenance of the security applications and systems.
Collaborated with stakeholders at all levels of the organization to advise about risks and keep the organization inform about the latest treats.
Implemented security protocols to protect sensitive medical data.
Conducted risk assessments to identify and mitigate security issues.
Developed incident response plans to address cyber threats effectively.
Collaborated with IT teams to enhance system security measures.
Provided training sessions on cybersecurity best practices for staff.
Reviewed and updated security policies to comply with regulatory standards.
Designed and maintained secure network architectures for multiple platforms.
Implemented solutions such as encryption, authentication, access control.
Reviewed third-party applications for compatibility with corporate standards.
Maintained documentation of security and disaster recovery policies and procedures.
Senior Security Engineer
Decision Resources Group
Burlington
05.2016 - 04.2017
Company Overview: Healthcare research and consulting company
Designed and implement System Center 2012 (SCCM) to improve the Workstations and servers patching.
Designed and Implemented several endpoint products managed through McAfee ePO for servers and workstations.
Built security policies using HIPAA, NIST and ISO 27001 for the company.
Developed IT standards and policies designed to streamline desktop and software support.
Trained System Administrators and IT Help Desk personal on new security related implementations.
Created and automated reports in SCCM, McAfee, Jamf Pro and Oomnitza for Help Desk workflow improvements.
Created security assessment methodology for workstations and servers using Qualys.
Performed weekly vulnerability scans and reporting in Qualys.
System Engineer / Information Security Analyst
American Tower Corporation
Boston
03.2010 - 05.2016
Company Overview: Global telecommunications company
Architected, designed and implemented of System Center 2012: Configuration Manager, Deployed and created new VM guests with Windows Systems Administrator using Customized ISO Images templates.
Designed and implement Microsoft Endpoint Protection to replace Symantec antivirus for 10,000 workstations and 1,200 servers.
Designed and implement MS BitLocker to replace Checkpoint endpoint encryption.
Designed and implement Orchestrator Runbooks for Windows server automation.
Assisted in maintenance of hardware and server OS for 1,200 Microsoft servers across 22 sites worldwide.
Responsible for enterprise monitoring 1,200 Windows servers 2003, 2008, 2012 and Red Hat 4 and 5.
Redesigned and implemented new OU structure, GPOs, deployed MS DFS management tools.
Conducted periodic network monitoring and intrusion detection analysis using Rapid 7 to determine if there have been any attacks on the system.
Designed self-service Application Catalog for global deployment.
Responsible for troubleshooting and maintaining overall clients/agents and server health for entire SCCM and SCOM infrastructure.
Created specialized SMS collections and reports to efficiently gather the required data and centralize it in one location.
Designed and implement and document WSUS/SUP solution for Microsoft Security patch compliance.
Write PowerShell and bash scripts to do system checks, system maintenance, app updates, and configuration management.
Engage and coordinate global services and changes with respective managers to archive package updates, like the Office 365 migration.
Designed and implemented Backups and recoveries for SCCM 2012 and SCOM 2012.
Package, advertise and deploy third party security updates.
Built security awareness as well as incident response and escalation programs.
Configured SCOM clients and reporting for SCCM environment.
Deployed SCOM new agents and troubleshot agent failures.
Configured Group Policy Objects to create a secure Windows Infrastructure.
Customized monitoring tools to define system performance thresholds and watch specific applications.
Design and develop firewall configurations according to security best practices using Check Point (NGFW).
Education
Master’s degree - Information Technology concentration in Cybersecurity
Clark University
Worcester, MA
Bachelor’s Degree - Computer Science
Clark University
Worcester, MA
Skills
Process development
Technical expertise
Staff management
Work prioritization
Deadline management
Team leadership
Vulnerability assessment
Incident response
Penetration testing skills
Security awareness training
Security policy development
Certification
Administering and Deploying System Center Configuration Manager
Certificate in UNIX Systems Administrator, 2001 Worcester Polytechnic Institute, Worcester, MA
Core Qualifications
Detail oriented security engineer with over 10 years of experience.
Strong experience developing various operating system patching strategies for Windows (7, 10), windows Server (2008, 12, 16, 19), Red Hat (6, 7) Linux and MacOS, using SCCM, WSUS, RHSM and AWS Patch Manager.
Proficient experience using vulnerability scanning tools like Tenable Nessus, Qualys and Rapid 7.
Extensive Experience in operation support and incident response using Splunk, Azure security tools, Carbon Black, CrowdStrike, SolarWinds SAM, Snort, McAfee ePO, Nmap and Wireshark.
Experience Implementing NIST Cybersecurity framework and ISO 27001.
Timeline
Senior Engineer
Hanover Insurance
09.2019 - Current
IT Security Engineer
UMASS Medical School
04.2017 - 09.2019
Senior Security Engineer
Decision Resources Group
05.2016 - 04.2017
System Engineer / Information Security Analyst
American Tower Corporation
03.2010 - 05.2016
Master’s degree - Information Technology concentration in Cybersecurity