Rohit ramankol
Information Security Engineering Analyst
About
With over 6 years of experience, I possess solid expertise in Governance and oversight of Vulnerability Management activities to develop solutions to address control gaps and conducting through investigations into false positives. My comprehensive understanding end-to-end Vulnerability management. I am proficient in ensuring robust security measures by identifying and mitigating vulnerabilities.
Skills & Expertise (4)
Work Experience
Information Security Engineering Analyst
Optum-United Health Group (UHG)
Oct 2022 - Jul 2025
Conducting regular vulnerability Scans using Tenable.io, Rapid7 for end points and servers. Responsible for managing Rapid7 Insight VM tool and Tenable.io. Performed False positive investigations and IT vulnerability assessments in Rapid7 Tool, Tenable.io. Resolving authentication issues on servers and network devices. Handle security incident response related to false +ve and deferral request. Monitor the Daily Failed Audits for Infrastructure scanning and Vulnerability Management. Deployment, configuration and updating of vulnerability scanners. Creation of template for scanning as per requirement. Creation of Dashboards, Sites, Asset groups, Asset tags for scanning as per requirement. Case logging and troubleshooting with vendor technical team for critical cases. Vulnerability exception handling. Responsible for Incident Response, ensuring issues are triaged and addressed according to Service Level Agreements (SLAs). Responsible for preparing weekly and Monthly metrics for vulnerability assessment. Responsible for subnet reconciliation every week to maintain accurate network records. Managed regular patching for security sensors. Handling of contracts from offshore.
Security Analyst
IBM
Jun 2019 - Sep 2022
Performing False positive investigations, IT vulnerability assessments and monitoring remediation and report metrics to ensure management makes information risk aware decisions. Working in Vulnerability Analytics which will help in identifying the risk in our organization. Having Hands on experience in Rapid7, Tenable.IO & QualysGuard. Asset group creations and providing user permissions. Scheduling and running vulnerability scans and reports for weekly and monthly basis. Analyzing vulnerability reports and providing inputs to the respective teams. Regular follow up with infra team to track Vulnerability remediation by scheduling weekly remediation call. Provide the reports regularly to stakeholders and also with weekly and monthly summary reports. Vulnerabilities identified on every monthly presented to the client and discuss an action plan for remediation of Vulnerabilities identified in each month. Initiating ad-hoc scan for the critical advisories and sharing the findings with the respective team for them to act on the mitigation. Monitoring scanner statuses and coordinating with POCs to bring offline scanners online. Submitting reports to clients and platform teams for corrective actions on failed controls.
Education
BCA - GLOCAL UNIVERSITY
- 2019 ยท Afghanistan
Certifications
No certifications added yet