Sapna Singh

Sapna Singh

Software Developer

location of Sapna SinghIndia

Connect with Sapna Singh to Send Message

Connect

Connect with Sapna Singh to Send Message

Connect
  • Timeline

  • About me

    Principal Cyber Security Architect at Honeywell

  • Education

    • International Institute of Information Technology Hyderabad (IIITH)

      2010 - 2012
      MSCLIS Cyber Law & Information Security
  • Experience

    • Other

      Jan 2008 - Aug 2010
      Software Developer
    • Educational Institute

      Jan 2008 - Aug 2010
      Lecturer

      • Responsible for taking classes of MCA, PGDCA, B.Tech Courses.• Experienced trainer for programming languages (C, C++, Visual Basic, Java, PHP), RDBMS and networking courses.

    • BLC Noida

      May 2011 - Jun 2011
      Security Intern

      Web Application Security testing of MAT BI ( Business intelligence tool). Developing algorithm to secure the sensitive data transfer .

    • Cognizant

      Jun 2012 - Aug 2013
      Security Analyst

      • Identification of potential vulnerabilities and suggestion for controls to mitigate them.• Perform Vulnerability Assessment and Penetration Testing• Perform forensic investigation of reported incidents by using Forensic tools like Encase Enterprise version 7.0, Encase E-discovery, open source tools sleuth kits and autopsy on MAC OS, Linux, windows environment and android mobile phones. Investigation involves servlet installation in target machine, image acquisition, and analysis and report preparation.• Signature analysis & configuration in Intrusion Prevention System.• Perform various audits like HR, Admin, and Network functions based on company followed Security standards and ISO27001. The audit scope also covers site certification audits and connects audits based on customer security requirement.• Handle request approval comes for firewall inbound traffic and hosting of web applications in DMZ. The approval process involves understanding the business requirements and security aspects.• Develop minimum security baseline documents.• Simulated denial of service attack on the network infrastructure in order to ensure readiness of response in case of any security incident. Tools used to perform DOS attack were Hping, scapy, Hulk and automated python scripts.• Participate in Proof of concept phase for testing product’s compatibility with the existing network infrastructure and product evaluation based on requirement. Prepared test cases to evaluate Symantec data insight and data loss prevention. • Developed various scripts to automate the backup process for Websense Forensics module on daily basis. • Developed a tool in ruby, python, PHP to parse firewall logs and display the output in various format in frontend. Show less

    • Time Inc.

      Sept 2013 - Jun 2018

      • Establish leadership and own the Security Incident management process & Response.• Strengthen the attack detection and response processes by utilizing effective operational control of the environment, developing and integrating all resources, Threat Intelligence and other related processes.• Expertise in cloud security domain, cloud architecture review, implementation of cloud security products in co-ordination with Cloud security Vendors, continuous monitoring of cloud deployment, incident response and root cause analysis of cloud threat vectors.• Responsible for Vendor Management and effective use resources. • Lead the implementation of various security products and effective utilization of products by incessant fine-tuning in line with emerging threats.• SME for Critical Incidents investigation by analysis of various logs sources, reverse engineering, malware analysis and forensics methodologies.• Develop and maintain processes and procedures used to manage SOC operations, Incident Response process and continuous improvement program.• Understanding of advance attack vectors, zero day vulnerabilities and latest threats. Based on this, propose signatures and work towards deployment support with respective security vendors.• Ensure Cyber Security Incident escalation process. Tracks, follows-up, and resolves incidents along with internal teams during investigation and mitigation.• Expertise on Containment, Remediation, Mitigation & Post Incident Activities.• Vulnerability management by identifying assets in organization and schedule them for scan. Follow up with asset owners for remediation.• Provide awareness and training in relevant areas. Show less • Perform incident response and network security monitoring using various technologies that may include IDS/IPS, Firewalls, Web Filtering, Security Monitoring tools and related products.• SME for various Critical Security Incidents investigations.• Expertise on performing Root cause analysis/Attack vectors of infection. • Experienced in end to end Security products implementation.• Skilled in Cloud security domain.• Vulnerability assessment of digital titles and Internet facing servers.• Web application assessment of third party applications.• Risk assessment of pixels ,javascripts, skimlinks used for advertisement, survey, polling and other business purposes.• Mobiles application penetration testing [Android].• Performed security assessment of few titles in migration of outdated and unsecure content management system to more reliable and secure content management system. Show less

      • Assistant Manager, Global Information Security

        Oct 2016 - Jun 2018
      • Team Lead

        Sept 2013 - Sept 2016
    • Deloitte

      Jun 2018 - Feb 2021
      Information Security Officer
    • Honeywell

      Mar 2021 - now
      Principal Cyber Security Architect
  • Licenses & Certifications

    • Blockchain: Foundations and Use Cases

      Coursera
      Feb 2019
    • Aviatrix Certified Engineer - Multi-Cloud Network Associate

      Aviatrix
      Sept 2020
      View certificate certificate
    • Algosec ASMS Administrator

      AlgoSec
    • Certified Ethical Hacker C|EH v7

      EC-Council
    • Oracle Cloud Infrastructure Foundations 2020 Certified Associate

      Oracle
      Jul 2020
      View certificate certificate
    • Certificate of Cloud Security Knowledge (CCSK)

      Cloud Security Alliance
      Dec 2016
    • AWS Certified Security Speciality

      Amazon Web Services (AWS)
      Jun 2020
    • Certified Information Systems Security Professional (CISSP)

      ISC2
      Aug 2014
    • Oracle Cloud Infrastructure 2019 Certified Architect Associate

      Oracle
      Jul 2020
      View certificate certificate
    • Qualys Guard Certified Specialist

      Qualys
  • Honors & Awards

    • Awarded to Sapna Singh
      Aspiring CXOs Award 2024 CXO Junction Feb 2024 Cloud Technology Execellence Category
    • Awarded to Sapna Singh
      Infosec Maestro Award 2023 CIOAXIS Oct 2023
    • Awarded to Sapna Singh
      Cyber Security Women Influencer of the Year Security BSides Bangalore Jun 2023
    • Awarded to Sapna Singh
      Cloud Security Champion of the Year 2022 CSA Alliance Bangalore Chapter & Cyber Frat Dec 2022
    • Awarded to Sapna Singh
      Cyber Security Community Contributor of the Year 2022 Women in Cyber Security Middle East Nov 2022
    • Awarded to Sapna Singh
      Cyber Security Community Supporter of the Year 2020 Women in Cyber Security Middle East November 1, 2020
    • Awarded to Sapna Singh
      Elevate - People Piller: All-IN Deloitte Middle East February 1, 2020 For contribution in eminence activities through advocacy of women advancement.
    • Awarded to Sapna Singh
      Exceptional Performance Cognizant Technology Solutions April 1, 2013 For outstanding contributions and exceeding expectations.
    • Awarded to Sapna Singh
      Institute's Gold Medal (Indian Institute of Information Technology, MSCLIS Cyber Law & Information Security) IIITA Sep 2012 For Academic Excellence.
    • Awarded to Sapna Singh
      Prof. Dr. Ing. Matthias Kleiner Gold Medal for Academic Performance and Innovative Achievements IIITA Sep 2012 For Academic Performance and Innovative Achievements
  • Volunteer Experience

    • Technical Lead

      Issued by Women in Cyber Security Middle East on Jul 2018
      Women in Cyber Security Middle EastAssociated with Sapna Singh
    • Core Team Member

      Issued by Women in CyberSecurity {W-CS} on Jul 2019
      Women in CyberSecurity {W-CS}Associated with Sapna Singh
    • Core Team

      Issued by BSides Bangalore on Feb 2023
      BSides BangaloreAssociated with Sapna Singh
    • Women in Cyber Kuwait Lead

      Issued by Deloitte on Jul 2018
      DeloitteAssociated with Sapna Singh