Amir Jafari

Angestellt, Cyber Security Engineer Team Lead, Middle East Bank

Abschluss: Master of Science, Sheffield Hallam University, Sheffield, United Kingdom

Tehran, Iran (Islamische Republik )

Über mich

I am a Cyber Security Engineer with ten years of experience working in web application penetration testing, Vulnerability Assessment, Security auditing, and Risk Management. I love to dig into cybersecurity solutions to protect every part of the IT environment, from cloud solutions, data, and networks to end-user devices. To achieve this, I focus on delivering key results, working as part of a team, learning new concepts, and quickly adapting to new environments. Currently, I work as the Cyber Security Engineer Supervisor at Middle East Bank, developed a comprehensive framework for assessing the security of network infrastructure and information systems following methodologies and references such as OWASP, gaining an 80% improvement in threat and vulnerability management. My specialties include Penetration Testing, Vulnerabilities Assessment, Network Security, ISO/IEC 27001, Information Security Audit, PCI DSS, Risk Analysis, Cloud Security, Python, Linux, Secure Coding, CI/CD, and AWS

Fähigkeiten und Kenntnisse

Penetration Testing
Vulnerabilities Assessment
Network Security
ISO/IEC 27001
Information Security Audit
PCI DSS
Risk Analysis
Cloud Security
DevSecOps
Python
Linux
SCADA
Data Loss Prevention
ISO
Audit
Information technology
Cloud Computing
Vulnerability
Data security
Analysis
Research
IT-Security
Web Security
Information Security Management System
Burp Suite
SSDLC
Application Security
Informatik
Sicherheitssysteme
CISSP
API Security
AWS
ISO 27001
Identity & Access Management
SIEM
Network Solutions
Network Infrastructure
decision-making skills
Communication skills
Emotional Intelligence
Negotiation skills
Creativity
Presentation skills
Teamwork

Werdegang

Berufserfahrung von Amir Jafari

  • Bis heute 5 Jahre und 3 Monate, seit März 2019

    Cyber Security Engineer Team Lead

    Middle East Bank

    •Developed a comprehensive framework for assessing the security of network infrastructure and information systems following methodologies and references such as OWASP, gaining an 80% improvement in threat and vulnerability management •Implemented an automated vulnerability management system for 1000 servers, databases, firewalls, switches, routers, and 800 Microsoft windows laptops using Nessus and Nmap vulnerability assessment tools, saving 20+ hours per month of manual scanning

  • 1 Jahr und 1 Monat, März 2018 - März 2019

    Senior Cyber Security Engineer

    Dadeh Pardazan Semaye Aftab (DSA)

    • Managed and created rules and policies for 600 end-users in Data Loss Prevention (DLP) software to prevent exposure of sensitive data outside of authorized channels, decreased security breaches by 80% • Performed assessments of systems and networks within the network environment through internal vulnerability scanning and identified 100+ vulnerabilities, reducing the company's security risks by 30%

  • 1 Jahr und 9 Monate, Juli 2016 - März 2018

    Cyber Security Engineer

    MAPNA Group

    • Implemented Cisco Identity Services Engine (ISE) integration with external identity sources using LDAP and RADIUS to control network access rights for 1000+ endpoints through the posture services • Designed group policies and access control lists to ensure compatibility with organizational standards to restrict information, system, and component access to 1500 authorized employees or machines

  • 3 Jahre und 3 Monate, Mai 2013 - Juli 2016

    Cyber Security Analyst

    Asan Andish Co.

    • Characterized and analyzed network traffic to identify anomalous activity and potential threats to network resources, saving the entire company over 1,500 computers and servers from destruction • Established, implemented, and maintained an information security management system (ISMS) based on the ISO/IEC 27000 series standards to ensure compliance with 114 controls and 30 security policies

  • 11 Monate, Juli 2012 - Mai 2013

    Cyber Security Specialist

    Tous Staadt

    • Developed cybersecurity plans for the National SCADA project, including 450 Routers, 4 Firewalls, two Data Centers, and 400 remote substations using Cisco Safe secure architectural framework to ensure secure deployments for the entire network environment • Wrote and updated Business Continuity and Disaster Recovery plans (BCP/DRP) to meet NIST 800-34, including business impact analyses, strategy selection, and documentation of business continuity and disaster recovery procedures

Ausbildung von Amir Jafari

  • 1 Jahr und 2 Monate, Sep. 2010 - Okt. 2011

    Master of Science in Computer Networking

    Sheffield Hallam University, Sheffield, United Kingdom

    Distinction, Ranked first amongst 14 MSc Computer Networking students during the academic year 2010/11

  • 5 Jahre und 10 Monate, Sep. 2002 - Juni 2008

    Bachelor of Science in Computer Engineering

    Tarbiat Moallem University (Kharazmi University), Tehran, Iran

Sprachen

  • Englisch

    Fließend

  • Deutsch

    Grundlagen

21 Mio. XING Mitglieder, von A bis Z