Pawan J Sonela

Pawan j sonela

bookmark on deepenrich
location of Pawan J SonelaPune/Pimpri-Chinchwad Area
Followers of Pawan J Sonela949 followers
  • Timeline

  • About me

    Cyber Security Manager

  • Education

    • Government college of engineering , amravati

      2007 - 2011
      Bachelor of technology (b.tech.) electronics and telecommunication 7.18

      Activities and Societies: Advertisement Lead , Football . Robotics , Contraption.

  • Experience

    • Tata consultancy services

      Jul 2011 - Jun 2015
      Network security engineer
    • Mphasis

      Jul 2015 - Apr 2016
      Senior security engineer

      Key Result Areas:  Working as part of network and security team and responsible to maintain network and security for the Mphasis infrastructure by managing customer’s network and security devices. Worked closely with the design Team to implement multiple projects as per customer’s requirement. Engaged 3rd party vendors to fix priority and escalated incidents. Communicated with internally and clients regarding technical details related to change or incident in an understandable manner.Key Projects:  Checkpoint Implementation and Upgradationo Project Details: Worked with technical teams to Hardware replacement of End-of-life IPSO devices to new checkpoint appliances and upgradation of 460 firewalls from R77.30 to R81.o Skill Used: Checkpoint Firewall, IP Networking, Routing, Switching o Devices: Checkpoint Hardware appliances including 4200, 4400, 4600, 4800 and 5800o Status: Successfully Completed  VPN Migration:o Project details: Worked with implementation teams to migrate VPN from legacy an out-of-support Net Screen firewall to Checkpoint Firewalls o Skills Used: Firewall (Checkpoint and Net screen ), Stakeholder co-ordination.o Status: Successfully Completed Awards and Achievements:  Bagged star of the Quarter Award for Automating repeating tasks Show less

    • Hsbc glt

      Apr 2016 - Aug 2017
      Information security risk senior analyst

      Key Result Areas:  Working as a member of IT cyber security team and responsible to maintain cyber security posture for theHSBC infrastructure by managing network security devices like Routers, Firewall, WAF, IDS, Proxy, DLP, and monitoring tools like SIEM and Solarwinds  Communicated with Team members, senior management and client regarding technical details related to change or cyber incident in an understandable manner Worked closely with the cyber security architect to complete multiple projects as per organisation requirement  Liaised with vendors regular basis to ensure that vulnerability management can be performed on the production environment Key Projects:  Third Party Security Review ( TPSR )o Project Details: Worked with vendors and third parties to periodically assess their security posture by completing the third party security review ( TPSR )o Skill Used: IT compliance, Cyber Security Architect, Networking, Application and Network Securityo Status: Successfully Completed TPSR for 13 vendors and third party Skyboxo Project Details: Skybox is one of the firewall assurance tool so reviewed, designed and deployed it as per the bank standardso Skill Used: Tools, Networking, Application and Network Securityo Status: Successfully Completed Firewall Assurance Tool Deployment Automation: o Project Details: Automated manual tasks like Daily backup and health check-up, VPN reporting and other manual tasks o Skills Used: Planning, Automation, Networking, Firewall, Load Balancer, Routing, Switching, IP networkingo Status: Successfully completed Show less

    • Wipro

      Sept 2017 - Oct 2022

      Key Result Areas:  Working as Cloud and Cyber Security Architect for one of the largest Bank in UK Create and review the designs/architecture based on organisation Cyber Risk Posture Work with the vendors and technical teams to remediate the risk poses to the customers. Manage customer expectation for challenging project and achieved customer satisfaction rate of 98% Communicated the progress to both internal and external stakeholders. Worked with Technical Team for Priority Cyber Incident and fault detection, identification and diagnosis.Key Projects: Cloud Data Exfiltration Prevention: o Project Details: Worked with Client and Internal security teams, vendors and cloud providers toimplement ambitious complete cloud Exfiltration prevention across the environment.o Skills Used: Planning, Communication, Cloud (AWS, Azure, GCP, IBM ) Vendor Management, Proxy , Firewallo Status: In-progress WSS Cloud Proxy Design and Deployment: o Project Details: Found security issue in customer environment, prepared and presented technical solution with WSS Cloud proxy, worked with technical team to successfully deliver the solutiono Skill Used: WSS Proxy, Azure AD, Checkpoint and Network o Status: Successfully Completed  Azure Virtual Desktop (AVD): o Project Details: As a cyber security architect, reviewed and approved the design for AVD deployment to remediate the offshore VDI with AVD solution.o Skills Used: Planning, Communication, Azure, Networking, Network Security, Azure, IT Complianceo Status: In-progress Garrison Isolation Appliance Design and Deployment: o Project Details: Found gap in customer environment, presented technical solution for web isolation solution, worked with technical team to successfully deliver the solutiono Skill Used: Garrison Isolation Appliances, ADFS, Bluecoat Proxy, Checkpoint and Networko Status: Successfully CompletedAwards and Achievements:  Bagged multiple Star of the Quarter and Star of the Month awards Show less

      • Security Architect

        Sept 2017 - Oct 2022
      • Cyber Security Architect

        Nov 2019 - Feb 2022
      • Cyber Security Specialist

        Nov 2018 - Oct 2019
      • Senior Technical Specialist

        Sept 2017 - Nov 2018
    • Cybernara

      Jan 2021 - now
      Cyber security consultant
    • Quantiphi analytics limited

      Oct 2022 - May 2024
      Security architect

       Working as Security Architect to optimise the solution based on Cost, Simplicity, Security and Resources. Advised and collaborated with IT and business leaders to develop and implement layered security controls for protecting the privacy, confidentiality, integrity and availability of customer information, corporate data and networks. Eliminated risks and achieved zero service disruption during various migration, coordinating with diverse teams from both organizations for results. Developed organization-wide PCI-DSS policy to ensure compliance with requirements. Created and reviewed the designs/architecture based on organisation security standards – Both On-premises and Cloud. Define and implement technical cyber security standards in the region to maximize security infrastructure effectiveness and efficiency. Implement and revamp cyber security processes and procedures to strengthen defense and incident response capabilities. Conduct forensics investigations on cyber security incidents for management and regulatory reporting.As part of Red team, identify vulnerabilities, weaknesses, and potential entry points that malicious hackers could exploit and proactively improve an organization's overall security posture by mimicking real-world attack scenarios. Design and conduct cyber security risk assessments or tests to identify security exceptions and design practical compensating controls.Create and review the designs/architecture based on best practises and compliance in AWS/Azure/GCP Cloud.Define, design, evaluate and maintain the enterprise IT Security ArchitectureLead and drive the development and implementation of the security architecture in accordance with the firm's technology roadmap. Evangelize the benefits of architecture, accepted best practice techniques, standards and tools to the Group and external suppliers where necessary.Work on the RFP/Qs for diverse client across the geography from the technical and delivery perspective Show less

    • Deloitte

      Nov 2023 - now
      Cyber security manager
  • Licenses & Certifications

    • Ccsa

      Checkpoint services, inc.
    • Security+

      Comptia
      Jun 2017
    • Ccna

      Cisco
    • Az-500 security technologies

      Microsoft
    • Big ip irules developing for ver 11.x

      F5 networks
    • Itil foundation

      Exin
    • Prince2 practitioner

      Exin
      Aug 2016
    • Az-103 azure administrator

      Microsoft
    • F5-101

      F5 networks
    • Prince2 foundation

      Exin
      Aug 2016