Safia Naaz

Tech Risk & Controls I Cyber Security Specialist | VAPT | AWS Security Speciality | AWS Solutions Architect | AWS Cloud Foundation | ECSA | CEH | ITIL | QualysGuard

Role
Tech Risk and Controls at 摩根大通
Location
Hyderabad, TG, IN
LinkedIn followers
500 followers
Information TechnologyView LinkedIn profile

About Safia Naaz

Safia is a seasoned Security Specialist with over 12+ years of expertise in vulnerability assessment, penetration testing, and governance, risk, and compliance (GRC). Her extensive background in risk management and controls enables her to deliver strategic security solutions that protect organizations from evolving cyber threats while ensuring compliance and minimizing risk.Tech Risk & Compliance :Experienced Tech Risk and Control Professional with a strong background in identifying, assessing, and mitigating technological risks. Expertise in designing and implementing robust security controls, ensuring compliance with industry regulations, and monitoring IT infrastructure to safeguard business operations. Skilled in risk management frameworks, cybersecurity protocols. Adept at collaborating across teams to enhance risk posture and ensure resilient technology environments.VAPT : • Extensive experience in performing both manual and automated security testing on Web Applications, Web Services, APIs, thick clients, and security assessments of AWS environments. • Proficient in conducting Vulnerability Assessments on network assets to identify and mitigate potential threats using tools such as QualysGuard and Nessus. • End-to-End Implementation of Dynamic Application Security Testing (DAST) for web applications, APIs, and thick clients, employing both manual and automated testing methods. • Hands-on experience with a wide range of security tools, including HP WebInspect Enterprise Edition, IBM AppScan, QualysGuard VM, BurpSuite Pro, OWASP CSRF Tester, SQLMAP, Wireshark, SSLyze, SSLScan, Kenna Security, and others. • Led client demos and discussions focused on vulnerability mitigation, providing remediation consultations for fixing vulnerabilities and improving overall security posture. • Streamlined the vulnerability management lifecycle for clients by providing detailed descriptions and effective remediation guidance for identified vulnerabilities. • Experience in network vulnerability scanning, prioritizing vulnerabilities, sharing reports with asset owners, and offering remediation consultations as needed. • Collaborated with asset owners to ensure vulnerabilities were addressed and resolved within the agreed Service Level Agreements (SLAs). • Worked across diverse industry sectors, including Banking, Pharmacy, Retail, and Media. • Defined security controls in the QualysGuard PC module for regular network compliance, scanning servers, sharing findings with asset owners, and ensuring closure of vulnerabilities.

Experience

  1. Tech Risk and Controls

    摩根大通

    May 2024 — Present · Hyderabad, IN

    Governance, Risk & Control Leadership: Oversaw governance of key control domains including vulnerability management, security configurations, and security operations, addressing KPI, KRI, and CORE audit findings. Responsible in establishing end-to-end governance frameworks for vulnerability management and penetration testing, ensuring comprehensive coverage from assessment to remediation. Evaluating and applying risk management principles for effective vulnerability prioritization and remediation.• AWS Assets Drift Monitoring: Implemented drift monitoring for public cloud assets, resolving critical CORE issues across 200+ applications and establishing central governance.• Non-Standard Database Assets Drift Monitoring: Developed secure configuration baseline and custom drift solutions for non-standard databases (KDB, INFLUXDB, INFORMIX, H2, Neo4J, TIMES TEN ORACLE), improving enterprise security posture across assets, in 400+applications. Defined Control Procedure to capture the security requirement and effectively bridge the audit gaps reported in CORE.• Automation & Process Optimization: Led initiatives to automate risk and control workflows, enhancing operational efficiency and supporting continuous improvement.• Cybersecurity Audits & Compliance Management: Led cybersecurity audits and assessments in coordination with internal audit teams; managed RFI responses and ensured timely submission of audit evidence and documentation.• Executive Reporting & Risk Communication: Developed and presented cybersecurity reports, dashboards, and risk metrics to executive leadership, control owners, and key stakeholders to support governance and decision-making.• Tools & Platforms: Alteryx, RSA Archer, CORE, GTCR, Lucidchart, Microsoft Word, Microsoft PowerPoint, Confluence.

Education

  • Krupajal Engineering College

    Bachelor of Technology (B.Tech.), Applied Electronics & Instrumentation

    2007 — 2011

Skills

  • Application Security
  • Ceh
  • Qualys
  • Vulnerability Management
  • Owasp
  • Web Application Security
  • Vulnerability Assessment
  • Information Security Management
  • Network Security
  • Security
  • Vulnerability Scanning
  • Information Security
  • Penetration Testing
  • Vulnerability

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Safia Naaz — Tech Risk and Controls at 摩根大通 in Hyderabad, TG, IN | Unifers