🔐 Security & Compliance Work
This section outlines my hands-on involvement in security operations, risk management, and compliance-driven activities within fintech and regulated environments. My work focuses on reducing security risk, supporting audit requirements, and strengthening organizational security posture without disrupting business operations.
🔎 Vulnerability Assessment & Risk Identification
- Conducted structured network and application-level vulnerability assessments to identify misconfigurations, exposed services, and outdated components.
- Evaluated findings based on risk impact and exploitability, prioritizing issues that posed real operational or business risk.
- Worked closely with infrastructure and application teams to validate findings and recommend practical remediation steps.
🌐 Network & Infrastructure Security
- Reviewed and maintained firewall rules, access controls, and network segmentation to minimize attack surface.
- Supported secure remote access mechanisms and monitored security logs to detect abnormal or suspicious activity.
- Assisted in strengthening production and disaster recovery environments by aligning infrastructure changes with security controls.
📑 Governance, Risk & Compliance (GRC) Support
-
Participated in third-party security assessments by gathering technical artifacts, reviewing security controls, and validating compliance requirements.
-
Assisted in policy review and refinement, ensuring technical practices aligned with internal standards and external expectations.
-
Maintained audit-ready documentation such as network diagrams, access control summaries, and security process descriptions.
🧠 Security Awareness & Operational Support