

Certified IT Security & Infrastructure Engineer with 12+ years of experience across Malaysia, India, and East Africa. Specialized in network security, cloud security, incident response, vulnerability management, and compliance (BNM RMiT, ISO 27001). Proven success in reducing security incidents by 45% through proactive controls and automation. Strong communicator with hands‑on experience in enterprise environments including MCIS Life, Hyundai, and Archer Transnational Systems. Certified in CCNP ENCOR, CPTE, CEH, AZ‑500, and Checkpoint, Palo Alto, Cisco, Fortinet, Sophos, Sonicwall Firewall.
• Leading enterprise security strategy and governance for MCIS Life’s critical systems and cloud workloads.
• Acting as the SME for BNM RMiT compliance, mapping controls across infrastructure, cloud, and application security.
• Designing and reviewing security architecture for new projects, integrations, and digital transformation initiatives.
• Managing SIEM, SOC workflows, incident response, and threat hunting activities.
• Overseeing identity & access governance including Azure AD/Entra ID, MFA, conditional access, and privileged access controls across all systems.
• Implementing network security controls across firewalls, segmentation, NAC/SAC/DAC, and secure remote access.
• Driving vulnerability management, patch governance, and remediation tracking across on prem and cloud environments.
• Collaborating with Infra, Cloud, DevOps, and Application teams to embed security-by-design.
• Preparing documentation, risk assessments, and audit evidence for internal and external audits.
• Supporting corporate environments with secure configurations, hardening, and monitoring.
• Acting as a primary point of escalation for all security incidents.
• Firewall Management: Configuring and maintaining firewalls to control traffic and protect networks from unauthorized access
• Intrusion Detection and Prevention Systems (IDS/IPS): Implementing and managing IDS/IPS to detect and respond to potential security breaches
• Network Segmentation: Designing and implementing network segmentation to limit the spread of threats and enhance security
• Switching : Configuration and maintenance of Cisco switches, including LAN / WAN, vlans, trunk links, L3 switching (OSPF), redundancy protocols like STP, VRRP, HSRP etc..
• Operating System Hardening: Securing operating systems (Windows, Linux) through configuration changes, patch management, and reducing attack surfaces
• Endpoint Protection: Deploying and managing endpoint security solutions, including antivirus, anti-malware, and endpoint detection and response (EDR) tools.
• Vulnerability Management: Using tools like Nessus, Qualys, and OpenVAS to identify vulnerabilities in systems and networks.
• Patch Management: Ensuring timely application of patches and updates to mitigate vulnerabilities and protect against exploits.
• Security Information and Event Management (SIEM): Designing and implementation of SIEM tools (Rapid7,Qualys) to collect, analyze, and correlate security event data for real-time threat detection.
• Log Management: Setting up and managing log collection, storage, and analysis to monitor security events and detect anomalies.
• Penetration Testing: Conducting penetration tests to identify and exploit vulnerabilities, providing actionable remediation advice.
• Ethical Hacking: Applying ethical hacking techniques to assess and improve the security posture of systems and networks.
• Security Audits: Conducting security audits and assessments to ensure adherence to policies, procedures, and regulatory requirements.
• Cloud Security Best Practices: Implementing security best practices for cloud environments (AWS, Azure, Google Cloud).
• Identity and Access Management in Cloud: Managing IAM in cloud platforms to ensure secure access control and user management.
• Data Protection in Cloud: Securing data in cloud environments through encryption, access controls, and regular audits.
• NAC: Managing NAC for controlling the unauthorized access and devices to get into the network.
• SAC: Implementing and managing SAC for controlling the unauthorized access over servers.
• DAC: Implementing and managing SAC for controlling the unauthorized access over database.
• Security solutions : Designing, implementation and manging the different security solutions like EPS , EDR , DLP , Document Security , Proxy etc.
• Server : Configured and managed VMware vSphere environments (vCenter, ESXi hosts, vMotion, HA/DRS. Conducted VM migration, backup/restore, and disaster recovery using VMware tools.
• Storage : Deployed and administered storage solutions (SAN, NAS; vSAN for VM datastores)
• Datacenter : Leading and managing the datacenter infrastructure.
· CCNP Encor – 350-401 , November 2024
· Cloud Security , AZ-500 , March 2023
· Sophos firewall Certification, January 2022
· Certified Penetration Testing Engineer, CPTE, October 2020
· N+ Certification Petknolinc, Vadodara, 01/2012
CCNA Certification, Petknolinc Vadodara, January 2012
Shah Swapnil B
Email: swapnilshh800@gmail.com | Phone: +91-9510407219 | Pune, Maharashtra
Profile
Professional Experience Highlights