About
Cyber Security Professional with over 5 years of experience in Vulnerability Management, Risk Assessment, Endpoint Security, and Compliance. Experienced in performing authenticated and unauthenticated vulnerability scans across Windows, Linux, and Network environments. Strong expertise in CVSS-based risk prioritization, remediation tracking, zero-day vulnerability management, external attack surface monitoring, and executive reporting. Proven ability to collaborate with cross-functional teams to strengthen security posture and reduce organizational risk exposure.
Skills & Expertise (9)
Work Experience
Vulnerability Management Engineer
Egon Zehnder
May 2024 - Mar 2025
Performed asset reconciliation between Tenable (servers) and CrowdStrike (workstations) to ensure accurate inventory coverage. Created and managed RITM tickets in ServiceNow for asset onboarding and decommissioning. Scheduled and executed authenticated and unauthenticated scans; investigated failures by validating credentials and port accessibility. Prioritized vulnerabilities based on CVSS score, severity, exploitability, and business impact. Conducted remediation calls and performed post-remediation validation scans. Developed executive dashboards and bi-weekly risk reports.
Vulnerability Management Professional
Tata Consultancy Services
Jun 2020 - May 2024
Conducted agent-based and non-agent-based vulnerability scans across enterprise environments. Validated scan results and eliminated false positives before remediation assignment. Tracked remediation metrics and facilitated risk acceptance documentation where required. Designed and managed cookie banners in OneTrust aligned with GDPR and CCPA requirements. Categorized and validated cookies and ensured compliance with privacy regulations.
Vulnerability Management Analyst
Infosys
Apr 2025 - Present
Manage vulnerability assessments using Tenable for Windows, Linux, and Network devices through scheduled authenticated and unauthenticated scans. Prepare detailed vulnerability reports, dashboards, and executive PowerPoint presentations highlighting risk posture and remediation status. Utilize CrowdStrike Falcon for workstation vulnerability visibility and coordinate remediation with endpoint owners. Perform external attack surface monitoring using BitSight and CyCognito to identify exposed external IP risks. Export vulnerability data and analyze findings using pivot tables based on severity, CVSS score, and business impact. Create remediation tickets in Ivanti and coordinate with infrastructure teams to ensure timely closure. Monitor zero-day vulnerabilities and assess organizational exposure for proactive mitigation.
Education
Bachelor of Computer Applications - NSHM College of Management & Technology
2017 - 2020 · Afghanistan
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation