Pratik Desai

"Global Cybersecurity Leader | Expert in SIEM, Cloud Security, Email Security, Threat Analysis, Incident Response & Vulnerability Management | Certified in Azure, Proofpoint, Securonix, Qualys, Zscaler, LogRhythm"

Pune District, Maharashtra, India

About

Accomplished and proactive Senior Global IT Security Specialist with a proven track record of over 10 years in devising and executing effective security solutions. Skilled in conducting comprehensive risk assessments, enforcing security protocols, and ensuring alignment with regulatory requirements. Eager to apply my wealth of experience to fortify the security framework of a distinguished organization. As a proactive threat hunter, I am proficient in threat analysis and incident handling. I am well-versed in implementing and configuring tools such as Endpoint Detection and Response, Next Generation SIEM solutions, Secure Email Gateway, Password Vault, and Proxy Solution. I am also conversant with Firewall administration, malware protection, and intrusion detection and prevention systems. I hold a Master of Science in Computer Security and Resilience from the University of Newcastle Upon Tyne and a Bachelor of Technology in Computer Science from Symbiosis International University. Additionally, I hold several industry certifications, including Microsoft Azure Fundamental AZ900, Microsoft Security, Compliance, and Identity Fundamentals SC900, Securonix Administrator, Securonix Security Analyst, Qualys Vulnerability Management, Certified Network Security Specialist (CNSS), LogRhythm Platform Administration, and LogRhythm Security Analyst. My technical skills include proficiency in Next Generation SIEM solutions such as LogRhythm, IBM Qradar, Splunk, and Securonix, Endpoint Detection and Response solutions such as Microsoft Defender ATP, Carbon Black, and Crowdstrike Falcon, as well as Anti-Virus Solutions, Vulnerability Management Tools, Proxy Solutions, Secure Email Gateway, Firewall, Data Loss Prevention, and Cloud Security Controls. I hold expertise in managing cloud security posture for multiple customers by implementing access control policies, attack surface reduction rules, multi-factor authentication, and single sign-on. I design and implement defense in depth information security controls for customers and ensure appropriate data loss prevention policies are in place to safeguard the information and prevent data exfiltration. In conclusion, I am a talented individual with a strong desire to grow my technical skills and the ability to learn new technologies swiftly. I am always eager to take on new challenges and have a proven track record of success in the cyber security domain.

Experience

  • Senior Global IT Security Specialist at CANPACK INDIA PRIVATE LIMITED
    Oct 2023 - Present · 2 yrs 10 mos

    • Implemented and managed enterprise-wide security policies and procedures to mitigate cyber threats and ensure compliance with industry standards • Led a team of IT security professionals in designing and implementing proactive security measures, resulting in a significant decrease in security incidents • Collaborated with cross-functional teams to develop and implement incident response plans, ensuring a rapid and effective response to security breaches • Led the development and implementation of comprehensive cybersecurity strategies, aligning them with organizational goals • Conducted in-depth analysis of security threats and vulnerabilities, developing actionable mitigation plans • Coordinated with cross-functional teams to integrate and enforce security best practices across all departments • Regularly updated and maintained security policies, standards, and guidelines to adapt to emerging threats • Managed and optimized the deployment of Qualys Vulnerability and Patching solutions, reducing risk exposure • Spearheaded the implementation of Forcepoint Security Manager (DLP), enhancing data loss prevention capabilities

  • Tech Mahindra (5 yrs 10 mos)
    • ICT Cyber Security Specialist
      May 2022 - Oct 2023 · 1 yr 6 mos

      • Preparing and maintaining documentation, policies, and instructions, and recording operational procedures. • Design and implement Defense in Depth information security controls for the customers. • Providing guidance and recommendations for selecting and implementing security technologies and solutions. • Developing and implementing security plans and procedures to protect the organization's assets, such as data, and intellectual property. • Ensuring real-time detection of known cyber security threats by leveraging available Threat Intelligence such as MITRE ATT&CK, Cyber Kill Chain Process and latest advisories. • Identifying possible security threats and determining the best security measures. • Advising on compliance with relevant laws, regulations, and industry standards related to information security. • Perform Security assessment to identify potential loopholes in the applications that could lead potential data exfiltration. • Responsible for configuring and managing below mentioned cyber security controls: 1. Secure Email Gateway solution like; Proofpoint and Trend Micro 2. Proxy solutions like; Zscaler 3. Perimeter Security solution such as Palo Alto and Fortigate Firewalls 4. End-point Detection & Response (EDR) solutions like; Microsoft Defender ATP, Carbon Black and CrowdStrike Falcon. • Periodically testing the organization's security systems and network to ensure they are functioning properly and effectively.

    • ICT Security Specialist (Promoted on 15th May 2022)
      2018 - 2023 · 5 yrs

      Subject Matter Expert for implementing and managing SIEM & UEBA (Defense in Breadth) cyber security solutions like IBM’s Qradar, Splunk, LogRhyhtm and Securonix Next Generation SIEM. Implemented Endpoint Detection & Response solutions such as Microsoft APT, Carbon Black, Crowdsrike Falcon. Configured Secure Email Gateway solution like Proofpoint, Office 365, and Trend Micro Email Gateway. Implemented and configured Proxy solutions like Zscaler and Bluecoat, Perimeter security solution such as Palo Alto and Fortigate Firewalls and End-point Detection & Response solutions like MS Defender ATP, Carbon Black and CloudStrike Falcon. Certified in Qualys Vulnerability Management tool which enables in identifying critical vulnerabilities and ensure their timely patching to prevent exploitation by the attackers. Managing Cloud Security posture for multiple customers by implementing Access Control policies, Attack Surface Reduction rules, Multi-Factor Authentication and Single Sign-ON. Design and implement Defense in Depth information security controls for the customers. Ensuring appropriate Data Loss Prevention policies are placed in CASB solutions like Netskope to safeguard the information and to prevent Data Ex-Filtration. Perform in depth cyber security incident investigation and to recommend appropriate actions to mitigate and resolve the incidents. Ensuring real-time detection of known cyber security threats by leveraging available Threat Intelligence from multiple sources such as MITRE ATT&CK, Cyber Kill Chain Process and latest advisories.

    • Associate Security Consultant
      Apr 2021 - May 2022 · 1 yr 2 mos

      • Conducting security assessments to identify potential vulnerabilities and threats to the organization's information systems, facilities, and operations. • Subject Matter Expert for implementing and managing Security Information and Event Management Solution (SIEM) & UEBA (Defense in Breadth) cyber security solutions like IBM’s Qradar, Splunk, LogRhythm and Securonix Next Generation SIEM supporting multiple customers. • Managing Cloud Security posture for multiple customers by implementing Access Control policies, Attack Surface Reduction rules, Multi-Factor Authentication and Single Sign-ON. • Ensuring appropriate Data Loss Prevention policies are place in Cloud Access Security Broker (CASB) solution like Netskope to safeguard the information and to prevent Data Ex-Filtration. • Well versed with Static and Dynamic Malware analysis to understanding the tactics used by adversaries and implement cyber security controls to prevent system from getting compromised. • Investigating security breaches and incidents and recommending actions to prevent similar incidents from occurring in the future. • Providing training and education to employees on security awareness and best practices. • Staying up to date on the latest security threats and trends and recommending appropriate countermeasures. • Providing guidance and recommendations for selecting and implementing security technologies and solutions.

  • SecurView, Inc. (1 yr 9 mos)
    • Security Analyst
      Aug 2017 - Sep 2018 · 1 yr 2 mos

      • Subject Matter Expert for managing SIEM Security Information and Event Management Solution (SIEM). • Implementing Use-Cases to detect cyber security attacks in real-time. • Identifying and mitigating potential threats, such as viruses, worms, and other types of malwares. • Investigation of daily Security alerts and events. Taking necessary actions to mitigate them within the agreed SLA. • Monitoring network traffic to detect potential threats and then responding to these threats promptly. • Ensuring that the company's digital assets are protected from unauthorized access. • Generating reports for IT administrators and business managers to evaluate the efficacy of the security policies in place. • Creating documentation and planning for all security-related information, including incident response and disaster recovery plans. • Responsible for implementing and enforcing security policies and procedures, as well as educating users on how to protect against security threats.

    • Security Analyst (L2), Security Operation Center (SOC)
      2017 - 2018 · 1 yr

      Subject Matter Expert for managing SIEM Security Information and Event Management Solution (SIEM). Implementing Use-Cases to detect cyber security attacks in real-time. Identifying and mitigating potential threats, such as viruses, worms, and other types of malwares. Investigation of daily Security alerts and events. Taking necessary actions to mitigate them within the agreed SLA. Monitoring network traffic to detect potential threats and then responding to these threats promptly. Ensuring that the company's digital assets are protected from unauthorized access. Generating reports for IT administrators and business managers to evaluate the efficacy of the security policies in place. Creating documentation and planning for all security-related information, including incident response and disaster recovery plans. Responsible for implementing and enforcing security policies and procedures, as well as educating users on how to protect against security threats.

  • IT Security Analyst at Norsk Hydro
    Feb 2015 - Aug 2017 · 2 yrs 7 mos

    • Monitoring ICT systems and networks for security threats using various tools and techniques. • Responding to security incidents and working to mitigate the damage caused by them. • Evaluating and testing new security technologies. • Running Vulnerability scans using Nessus Vulnerability Scanner and keeping up to date on the latest security threats and vulnerabilities. • Collaborating with other teams, such as IT, to ensure the overall security of the organization. • Analysing alerts triggered on Security Information and Event Management Solutions (SIEM) i.e., IBM Qradar and taking appropriated actions to mitigate the threats in timely manner. • Providing training to staff on security best practices and policies. • Keeping abreast of the latest security trends and technologies to provide effective security for an organization. • Responsible for ensuring the security of an organization's information and communication technology systems, networks, and data.

  • Jr. Analyst, Information Security Team at Sapa Shared Services (Now known as Hydro)
    2015 - 2017 · 2 yrs

    Monitoring ICT systems and networks for security threats using various tools and techniques. Responding to security incidents and working to mitigate the damage caused by them. Evaluating and testing new security technologies. Running Vulnerability scans using Nessus Vulnerability Scanner and keeping up to date on the latest security threats and vulnerabilities. Collaborating with other teams, such as IT, to ensure the overall security of the organization. Analyzing alerts triggered on Security Information and Event Management Solutions (SIEM) i.e., IBM Qradar and taking appropriate actions to mitigate the threats in a timely manner. Providing training to staff on security best practices and policies. Keeping abreast of the latest security trends and technologies to provide effective security for an organization. Ensured the security of an organization's information and communication technology systems, networks, and data.