| Supriya - Cyber Security Engineer |
| [email protected] |
| Location: Raleigh, North Carolina, USA |
| Relocation: Yes |
| Visa: GC |
| Resume file: Supriya Boyapati Cybersecurity_Engineer SOM_1789051630234.docx Please check the file(s) for viruses. Files are checked manually and then made available for download. |
|
Supriya Boyapati
Cell: 919-371-8468 Email ID: [email protected] Raleigh, NC Sr CyberSecurity Engineer Professional summary: Senior Cybersecurity / Security & Compliance professional with 11+ years of experience in cybersecurity, GRC, risk management, vulnerability management, application security, cloud security, security assessments, and enterprise security across healthcare, financial services, government, and highly regulated environments. Extensive experience with NIST CSF, NIST SP 800-53, FISMA, FISCAM, A-123, ISO 27001, PCI-DSS, SOC 1/SOC 2, and CIS Benchmarks, aligning security controls and compliance requirements with organizational and government security standards. Strong GRC expertise covering security controls, compliance requirements, governance processes, security gap analysis, risk assessments, policy reviews, control validation, audit readiness, evidence collection, and remediation planning. Experienced in analyzing, defining, and refining security and compliance requirements for system enhancements, new initiatives, applications, infrastructure, cloud environments, and enterprise technology solutions. Proven ability to develop audit-ready security requirements, user stories, workflows, use cases, acceptance criteria, and control requirements, integrating cybersecurity requirements throughout Agile SDLC and Secure SDLC processes. Extensive experience developing, documenting, implementing, and evaluating security controls, performing control effectiveness reviews, identifying control gaps, developing remediation strategies, and validating corrective actions. Strong experience maintaining System Security Plans (SSPs), Security Assessment Reports (SARs), authorization packages, security policies, procedures, technical standards, control documentation, audit evidence, and compliance artifacts. More than five years of experience supporting Disaster Recovery (DR) and Business Continuity Planning (BCP) for critical systems, including DR plan development, documentation, maintenance, testing, recovery validation, and resilience improvement. Experienced conducting Business Impact Assessments (BIAs) by evaluating critical business processes, application dependencies, operational impacts, recovery priorities, technology dependencies, and continuity requirements. Strong experience defining and evaluating Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) based on system criticality, business requirements, application dependencies, data protection, and recovery strategies. Experienced supporting DR/BCP tabletop exercises, simulations, recovery testing, and continuity exercises, documenting test results, identifying recovery gaps, and coordinating corrective actions to improve organizational resilience. Extensive enterprise vulnerability management experience across applications, APIs, infrastructure, networks, cloud environments, containers, Kubernetes, internal systems, and internet-facing assets. Strong expertise analyzing vulnerability findings using CVSS, exploitability, business impact, asset criticality, and organizational risk, while managing remediation prioritization, validation, tracking, and closure through JIRA and ServiceNow. Hands-on experience with Qualys, Nessus, IBM AppScan, Burp Suite, HP WebInspect, OWASP ZAP, Nmap, and Metasploit, supporting vulnerability scanning, security assessments, validation, and remediation activities. Extensive Application Security experience covering OWASP Top 10, XSS, CSRF, SQL Injection, authentication and authorization weaknesses, API security, SAST, DAST, SCA, CWE, CVE, CVSS, and secure code review. Strong experience integrating security and compliance requirements into Agile SDLC, Secure SDLC, DevSecOps, CI/CD, UAT, testing, and release processes, using Azure DevOps, GitHub, Jenkins, JIRA, and ServiceNow. Strong understanding of web application architecture with experience securing Java, .NET, APIs, microservices, cloud-native applications, authentication, authorization, session management, WAF, and application security controls. Proven experience supporting security audits, compliance assessments, control testing, policy reviews, evidence collection, auditor requests, remediation tracking, and demonstration of control effectiveness across regulated enterprise environments. Experienced developing compliance, risk, vulnerability, security-control, and performance reports using Power BI, Excel, Splunk, ServiceNow, JIRA, and SQL, providing actionable metrics and dashboards to leadership. Strong cross-functional leadership and systems-analysis experience partnering with program offices, business stakeholders, application teams, infrastructure, cloud, DevOps, security operations, audit, compliance, and enterprise risk teams, while providing mentorship and communicating security, compliance, risk, and resilience requirements to leadership. Technical Skills: Security Tools WAF (Web Application Firewall), OWASP ZAP Proxy, Paros Proxy, Splunk SIEM, IBM Appscan, Metasploit, AWS, HP Web Inspect, SQLMAP, Dir buster, Wireshark, Qualys Guard, Nexus IQ Server, Snyk. DLP, Netskope, CyberArk, CrowdStrike, JSON, Jira, GitHub Network Auditing Tools Nmap, Nessus SAST and DAST Tools IBM AppScan Enterprise (ASE), HP Web Inspect, Qualys Guard, Burp Suite Pro, HP Fortify, Checkmarks, Veracode, Nmap, Hping3. Programming Languages Java. Databases MySQL, Oracle, MSSQL. Scripting Languages HTML, JS. Operating System Kali Linux, GNU/Linux, Windows. Quantitative risk analysis tools ISF s IRAM, FAIR (factor analysis of information risk) Cybersecurity Frameworks NIST CSF, PCI-DSS, ISO 27001 Tools MS Office, ServiceNow Professional Summary: CVS Healthcare, Chicago, IL Oct 23 - Present Sr. Cyber Security Engineer Responsibilities: Lead enterprise security, compliance, risk, and vulnerability-management initiatives across application, infrastructure, cloud, API, and hybrid environments, ensuring alignment with organizational security standards and regulatory requirements. Define, analyze, and refine security and compliance requirements for enterprise applications, system enhancements, technology initiatives, and infrastructure changes, translating business and technical requirements into actionable security controls. Apply NIST CSF, NIST SP 800-53, FISMA, ISO 27001, SOC, PCI-DSS, and organizational security standards to assess security controls, identify compliance gaps, and develop risk-based remediation strategies. Develop and maintain security controls, policies, procedures, technical baselines, compliance requirements, governance documentation, and audit artifacts, ensuring controls are properly documented and validated. Develop and maintain System Security Plans, Security Assessment Reports, authorization documentation, control implementation evidence, risk documentation, and compliance packages supporting security assessments and audit activities. Support security and compliance assessments, internal and external audits, control testing, evidence collection, policy reviews, auditor requests, remediation tracking, and control-effectiveness validation across regulated enterprise environments. Support Business Continuity and Disaster Recovery initiatives for critical systems, including Business Impact Assessments, recovery planning, DR documentation, recovery procedures, testing, validation, and continuous improvement of organizational resilience. Define, document, and evaluate Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) based on business criticality, system dependencies, operational requirements, data protection needs, and recovery strategies. Participate in DR/BCP tabletop exercises, simulations, recovery testing, and continuity exercises, documenting results, identifying recovery gaps, and coordinating corrective actions with business and technical stakeholders. Lead enterprise vulnerability assessments using Qualys, Nessus, IBM AppScan, Burp Suite, HP WebInspect, OWASP ZAP, Nmap, and Wireshark, validating findings and prioritizing risks based on severity and business impact. Manage vulnerability remediation across 5,000+ enterprise assets, analyzing CVSS, exploitability, asset criticality, business impact, and organizational risk while coordinating remediation activities and validating vulnerability closures. Conduct application security assessments and secure code reviews for Java, .NET, APIs, microservices, and cloud-native applications using SAST, DAST, and SCA technologies aligned with OWASP Top 10 and Secure SDLC practices. Assess common application vulnerabilities including XSS, CSRF, SQL Injection, authentication and authorization weaknesses, API vulnerabilities, and session-management issues, providing actionable remediation recommendations to development teams. Integrate security and compliance requirements into Agile SDLC, Secure SDLC, DevSecOps, UAT, testing, CI/CD, and release processes using Azure DevOps, GitHub, Jenkins, JIRA, and ServiceNow. Conduct security risk assessments, application risk assessments, cloud security assessments, security architecture reviews, compliance gap analyses, and security-control evaluations, recommending practical mitigation strategies. Perform Azure and AWS security assessments covering IAM, RBAC, network security, encryption, logging, monitoring, Azure Policy, Key Vault, Security Groups, VPC, Network ACLs, and cloud security posture management. Develop and evaluate security controls for web applications, APIs, cloud platforms, and enterprise infrastructure, including WAF, firewall, access-control, segmentation, authentication, encryption, and other defensive controls. Develop compliance, risk, vulnerability, remediation, control-effectiveness, and performance reports using Power BI, Excel, SQL, Splunk, ServiceNow, and JIRA, providing leadership with actionable security and compliance metrics. Collaborate with program offices, business stakeholders, application development, infrastructure, cloud engineering, DevOps, security operations, audit, compliance, and enterprise risk teams to resolve security and compliance issues and communicate risks effectively. Provide senior-level guidance and mentorship on security requirements, compliance obligations, vulnerability remediation, control implementation, DR/BCP, risk mitigation, audit readiness, and Secure SDLC practices while driving issues through identification, remediation, validation, and closure. Citizens Bank, TX Apr 21 - Aug 23 Sr. Cyber Security Engineer Responsibilities: Conducted enterprise cybersecurity risk assessments, compliance assessments, application security reviews, infrastructure assessments, and security audits across banking applications, cloud environments, and critical enterprise technology platforms. Defined and documented security and compliance requirements for application enhancements, infrastructure changes, cloud implementations, and technology initiatives, ensuring alignment with business, security, and regulatory requirements. Developed, documented, and evaluated security controls, control procedures, technical standards, security baselines, compliance requirements, and governance processes supporting regulated banking environments. Supported security audits and compliance assessments through control validation, evidence collection, audit documentation, remediation tracking, policy reviews, and demonstration of control effectiveness to internal and external stakeholders. Maintained security and compliance documentation including System Security Plans, Security Assessment Reports, authorization documentation, control evidence, risk assessments, remediation plans, policies, and audit artifacts. Supported Business Continuity and Disaster Recovery initiatives for critical banking systems, including recovery planning, DR documentation, business impact analysis, recovery requirements, testing, and validation activities. Defined and evaluated RTOs and RPOs for critical applications and technology services based on business criticality, system dependencies, operational requirements, data protection needs, and recovery priorities. Participated in DR/BCP tabletop exercises, simulations, recovery testing, and continuity exercises, identifying recovery gaps and coordinating corrective actions with business and technical stakeholders. Led vulnerability assessment activities across internal and internet-facing applications, APIs, servers, infrastructure, cloud workloads, and enterprise assets using Qualys, Nessus, Burp Suite, IBM AppScan, OWASP ZAP, and Nmap. Analyzed vulnerability results, validated findings, eliminated false positives and duplicates, and prioritized remediation using CVSS, exploitability, business impact, asset criticality, and enterprise risk. Managed the complete vulnerability remediation lifecycle, coordinating findings from identification through remediation, validation, and closure while tracking corrective actions through JIRA and ServiceNow. Conducted Application Security assessments using SAST, DAST, and SCA technologies including Checkmarx, IBM AppScan, Burp Suite, Fortify, SonarQube, Veracode, and Snyk throughout the Secure SDLC. Performed secure code reviews and application security testing for Java, .NET, APIs, and web applications, assessing OWASP Top 10 vulnerabilities including XSS, CSRF, SQL Injection, authentication weaknesses, and authorization issues. Integrated security and compliance requirements into Agile SDLC, Secure SDLC, UAT, testing, CI/CD, and release processes, collaborating with development and engineering teams to validate implementation of required security controls. Applied NIST CSF, NIST SP 800-53, CIS Benchmarks, PCI-DSS, ISO 27001, SOC controls, and banking security requirements to evaluate security controls, identify compliance gaps, and develop risk-based remediation strategies. Managed AWS and Azure security controls including IAM, RBAC, MFA, encryption, logging, monitoring, Azure Security Center, Microsoft Defender, Security Groups, VPC, Network ACLs, and cloud configuration controls. Conducted security architecture reviews, cloud assessments, container/Kubernetes assessments, and Infrastructure-as-Code reviews, identifying security-control gaps, configuration weaknesses, compliance risks, and required remediation actions. Managed WAF policies, API security controls, Zero Trust, CyberArk PAM, MFA, identity governance, and privileged-access controls, strengthening protection of critical banking applications and enterprise infrastructure. World Bank, Washington, DC May 18 Mar 20 Cyber Security Engineer Responsibilities: Analyzed vulnerability assessment and scan results, validated findings, eliminated false positives, and prioritized application and infrastructure vulnerabilities based on CVSS severity, exploitability, and business impact. Documented vulnerability remediation guidance and risk findings, providing actionable recommendations to application and infrastructure teams for addressing identified security weaknesses. Supported enterprise Vulnerability Management activities, tracking remediation efforts, coordinating with application development, infrastructure, and security teams, and helping ensure timely resolution of identified vulnerabilities. Developed threat models and security risk assessments, identifying application attack surfaces, security weaknesses, and appropriate security controls to reduce organizational risk. Performed detailed Web Application Security assessments covering OWASP Top 10 vulnerabilities, API security weaknesses, authentication and authorization issues, session-management weaknesses, and input-validation vulnerabilities. Conducted AWS cloud security assessments and security-control implementation, working with AWS IAM, VPC, Security Groups, Network ACLs, CloudTrail, AWS WAF, and firewall policies to strengthen cloud security posture. Supported implementation and tuning of AWS WAF security policies protecting internet-facing applications against SQL Injection, Cross-Site Scripting (XSS), bot attacks, and other application-layer threats. ADP, India Nov 16 Feb 18 Cyber Security Consultant Responsibilities: Experienced in analyzing Symantec DLP events and reports, deployment of Symantec DLP, Endpoint Prevent, Network Prevent for Email, and Network Prevent for Web and ITA. Performed Monthly and Quarterly scans Symantec DLP and done the escalation of critical data found on Shared devices. Created and optimized Sentinel Workbooks and dashboards to provide visibility into security posture, incidents, vulnerabilities and compliance metrics. Integrated XDR platforms with SOAR solutions to automate containment actions such as endpoint isolation, firewall blocking, user account disabling and IOC remediation. Experienced with Splunk Monitoring and Reporting. Monitor Splunk SIEM for incoming alert, validate and write correlation searches in Splunk. Used Security Information and Event Management (SIEM), Intrusion Detection & Prevention (IDS/IPS), McAfee Endpoint Encryption Data Leakage Prevention (DLP), forensics, sniffers and malware analysis tools. Managed existing Proofpoint Advanced Threat Protection, Email Protection platforms including Email Fraud Defense, Threat Response Auto-Pull, Targeted Attack Protection, Threat Response, Data Loss Prevention (DLP) and Encryption. Provided Azure Security and Compliance reviews and solutions for government systems to facilitate secure. Performed security monitoring and threat detection using Microsoft Sentinel for centralized log analysis, incident response and threat hunting activities. CSL Behring, India Jan 2014 Aug 16 Cyber Security Engineer Responsibilities: Assist in the implementation and maintenance of cybersecurity measures to protect systems, networks, and data from unauthorized access, vulnerabilities, and threats. Monitor security logs and alerts from various security tools and systems to identify potential security incidents and report them to senior team members. Participate in vulnerability assessments and penetration tests to identify security weaknesses and assist in recommending appropriate remediation actions. Support the investigation and response to security incidents, including conducting initial analysis, gathering evidence, and assisting in the implementation of mitigation strategies. Assist in the configuration and management of network security systems and tools, such as firewalls, intrusion detection systems (IDS), and antivirus software. Contribute to the development and enforcement of security policies, procedures, and standards to ensure compliance with industry best practices and regulations. Assist in conducting security risk assessments and audits to identify gaps in security controls and recommend improvements. Education Masters in Information Technology JNTU - 2013 Bachelor of Technology - Jawaharlal Nehru Technological University, India- 2011 Keywords: continuous integration continuous deployment javascript business intelligence hewlett packard microsoft mississippi Idaho Illinois North Carolina Texas |