Profilbild von Rupesh Sendge Lead Information Security  Architect, Information Security Analyst, Information Security Analyst aus Muenchen

Rupesh Sendge

verfügbar

Letztes Update: 19.02.2024

Lead Information Security Architect, Information Security Analyst, Information Security Analyst

Abschluss: Master of Science
Stunden-/Tagessatz: anzeigen
Sprachkenntnisse: Deutsch (gut) | Englisch (Muttersprache)

Skills

Information Security, IT Security, DDOS, cloud, HSM, hybrid cloud, scalability, cloud security, Firewall, SIEM, Splunk, Qualys, Penetration testing, azure, PCI, FW, VMware, PCI DSS, API, Web Applications, Mobile Apps, IOT devices, NFC, penetration test, PCI- DSS, Key Management, PKI, Linux, Web server, Load Balancing, Linux virtual server, Database, Nexpose, clustering, intrusion detection system, VPN, Cloud computing, Logic, Android, SYMBIAN, GPRS, UMTS, Application development, Bluetooth, Java Application Testing, test case, 2G, Excel, broadcasting, telecommunication, X.509, LDAP, SSL, Kerberos, IPSEC, Smartcards, Biometric devices, TPM, MySQL, Maria DB, Percona Xtra DB, Security Onion, Alienvault, QRadar, Logrhythm, Scripting languages, Bash, Python, Ubuntu, Opensuse, Backtrack, Microsoft Windows, TCP/IP, LAN, WLAN, SSH, GSM, CDMA, BLE, Wireshark Network Analyser, Nessus, Rapid 7, Metasploit, Intrusion, Detection System, Snort, AIDE, APPArmor, Cisco 2900, 2960, Juniper SSG 320, PaloAlto, Web Servers, Apache, Nginx, ITIL V3, PCI-DSS, TÜV, OWASP, SANS, ITIL, ISO 27001, ISACA, Enterprise Architecture, TOGAF, SABSA, LeanIX, Fundamentals of Transaction Processing (Visa), ITIL foundation, CEH, AWS security Speciality

Projekthistorie

01/2020 - bis jetzt
Lead Information Security Architect
Wirecard Service Technologies (Banken und Finanzdienstleistungen, 500-1000 Mitarbeiter)

  • IT Security Projects: DDOS solution implementation, Bot mitigation tool.
  • Building technical architecture Artifacts for DLP solution using Netskope.
  • Member of IT Architecture Board at Wirecard, Work closely with Principal and Enterprise architects on several complex deliverables to ensure continuous improvement and solution designing on a global scale.
  • Design Crypto zone architecture focussing on integration of cloud and on prem HSM solution as a service.
  • Consulting and architecting leading-edge IT security solutions to support Wirecard's Hybrid cloud infrastructure.
  • Implementation of infrastructure provisioning strategies with a focus on automation, high availability and scalability, continuous consultation on cloud security topics, and datacentre re-design.
  • Security Architecture: Cisco ACI integration with F5
  • IT Security Operations: Automated Firewall change, AD, SIEM (Logrthythm, Splunk).
  • Responsible for complete vulnerability Management lifecycle, Remediation, Reporting for internal, external (ASV) using Qualys.
  • Implemented CIS Benchmarking standard on Infrastructure level.
  • Performing vulnerability assessment, Risk assessment and GAP Analysis.
  • Performing Web application and network layer Penetration testing.
  • Integration of Qualys vulnerability tool with azure security center and Archer GRC tool
  • Custom defined search queries implementation using Search Processing Language (SPL).
  • Firewall and application review.
  • Audit Support: Bafin, PCI, ISAE.

09/2018 - 12/2019
Senior Information Security Analyst
Wirecard Service Technologies GmbH

Wirecard Service Technologies GmbH, Munich (Germany)

* IT Security Projects: Cisco ACI Integration with Palo alto FW and VMware.
* Security Architecture: Cisco ACI.
* IT Security Operations: Firewall change, AD, SIEM (Logrthythm, Splunk).
* Defined and managed the implementation of PCI DSS Compliance.
* Responsible for complete vulnerability Management lifecycle, Remediation, Reporting for internal,
external (ASV).
* Implemented CIS Benchmarking standard on Infrastructure level.




* Performing vulnerability assessment, Risk assessment and GAP Analysis.
* Performing Web application and network layer Penetration testing.
* RFI's for Integration of third party applications with PCI applications.
* Defining KPI's requirement and implementing dash boards on Qualys with other vendor products
via API(Remedy),
* Custom defined search queries implementation using Search Processing Language (SPL).
* Firewall and application review.
* Audit Support: Bafin, PCI, ISAE.


Business sector: Finance-Payment Service Provider

10/2016 - 08/2018
Information Security Analyst
Wirecard Technologies GmbH

Wirecard Technologies GmbH, Munich (Germany)

* Defined and managed the implementation of PCI DSS compliance.
* Responsible for complete Vulnerability Management, Remediating and reporting for internal,
external scan (ASV) and Benchmarking using Qualys.
* Conducted vulnerability assessment, risk assessment.
* Penetration testing: Web Applications, Mobile Apps, IOT devices, NFC Devices.
* Performing RFI for integration of third party application with PCI application.
* Firewall and application review.
* Coordination with external penetration testers for performing external and internal penetration test
against infrastructure and application and its remediation activities.
* Involved in complete PCI- DSS audit lifecycle: Information gathering, evidences providing to
Auditors, Remediation activities, Compensating controls, ROC, AOC.

Business sector: Finance-Payment Service Provider

03/2015 - 09/2016
IT Security Administrator
Wirecard Technologies GmbH

Wirecard Technologies GmbH, Munich (Germany)

* IT Security Projects: Cisco ACI Integration with paloalto FW, NFC Payments.
* Security Architecture: Cisco ACI.
* IT Security Operations: Firewall change, AD, SIEM.
* HSM Administration & Key Management: Safenet, Thales.
* PKI Administration: Nexus.
* Access Control Management: AD, User-id access management in paloalto FW.
* SIEM Administration: Qradar, Log rhythm, Migration of SIEM from Qradar to Logrhythm.
* Audit Support: Bafin, PCI, ISAE.


Business sector: Finance-Payment Service Provider

09/2013 - 02/2015
Junior IT Security Administrator

* IT Security Projects: AD User-id integration paloalto FW.
* Security Architecture: Proxy integration and implementation of SIEM.
* IT Security Operations: Firewall change, AD, SIEM.
* HSM Administration & Key Management: Safenet, Thales.
* Access Control Management: AD, User-id access management in paloalto FW.

01/2013 - 09/2013
Linux System Administrator
Novalnet AG

Business sector: Finance-Payment Service Provider


01/01/2013-14/09/2013 Linux System Administrator
Novalnet AG, Munich (Germany)

* Designing and configuring high availability network infrastructure and System configuration.
* Firewall administration and maintenance.
* Defined and managed the implementation of PCI DSS compliance.
* Preparing PCI Self-Assessment Questionnaire.
* Remediating Web server, based on vulnerability included in PCI ASV scan report.
* Load Balancing with Linux virtual server.
* Database Redundancy architecture configuration.
* Updating and maintaining Disaster Recovery Plan.
* Conducted vulnerability assessment and Penetration testing using Nexpose.


Business sector: Finance- Payment service provider.

03/2010 - 12/2012
Security Engineer
Uniscon GmbH

Uniscon GmbH, Munich (Germany)

* High Availability clustering for web server.
* Administration of sealed could proxy architecture.
* Providing and documenting detailed report about security flaws and related fixation.
* Conducted and reviewed security risk assessments.
* Firewall administration and load balancing.
* Design and implementation of application based intrusion detection system for sealed cloud
architecture.
* Design and implementation of continual improvement model of defence.
* Setup VPN network and provide access for work from home users.
* Administration of intrusion detection system/ Intrusion prevention system (Alienvault).


Business sector: Cloud computing security and privacy.

08/2007 - 12/2008
Project coordinator
G Logic Technologies Pvt ltd

G Logic Technologies Pvt ltd, Hyderabad (India)

* Supporting projects on Android, BREW, SYMBIAN offshore development and testing for Qvantal
Technologies, Finland.
* Training employee's accordance to the project requirement, steering them in the
* Platforms like GSM, GPRS, and UMTS and with the Technologies like BREW, SYMBIAN and
Android.
* Guiding Employee's work for enhancement of in house testing and Application development
according to 3GPP, GCF and OMA.
* Providing detailed information for the Project members about the designing phase and testing
phase of the project development life cycle.


Business sector : Mobile Communications - Test, Verification and Development

05/2006 - 06/2007
Test System Operator
Cetecom GmbH

Cetecom GmbH, Munich (Germany)

* Performance of SIM, SIM Application Toolkit (SAT), RF testing, Bluetooth testing on GSM, GPRS,
Java Application Testing, tests using the test systems ORGA IT3, ANITE SAT8, ANITE RAMS.
* Responsible for database handling for test case results according to GCF certifications Tests are
done mainly with 2G and 3G Mobile phones which are in the development/conformance phase.
* Responsible for Performing RF system Calibration and Reporting on Anite RAMS.
* Interacting with Vendors like AGILENT, ANRITSU and ORGA related to technical setup issues.


Business sector: Mobile Communications - Test, Verification and Certification.

06/2001 - 10/2004
Network Administrator
Excel Media Private Ltd

Excel Media Private Ltd, Hyderabad (India)

* Worked in network operations. Was a part of TAC team and provided L1 and L2 technical support
to the customers.
* Firewall administration, Router administration, Switch configuration.
* Conferencing with network users about how to solve problems.
* Diagnose hardware and software problems, and replace defective components.
* Run and configure network cables, troubleshoot connectivity issues, create users and configure
other related issues.


Business sector: Television broadcasting and telecommunication.

Reisebereitschaft

Verfügbar in den Ländern Schweiz
Profilbild von Rupesh Sendge Lead Information Security  Architect, Information Security Analyst, Information Security Analyst aus Muenchen Lead Information Security Architect, Information Security Analyst, Information Security Analyst
Registrieren