Parthiv
Shah, Director Vulnerability Management, Corporate Information Security,
Depository Trust & Clearing Corp. (DTCC)
Parthiv Shah
has over fourteen years of experience in information technology
and information security as a practitioner and leader of technology
functions and information security functions for global financial
service firms. Parthiv has helped design and to implement an enterprise
wide information security program for the Depository Trust and Clearing
Corporation (DTCC) based on risk management best practice, COBIT
and ISO 27001 standards. He has implemented an information security
vulnerability management process (from 7 layers of OSI model perspective;)
He has supported, designed implementation of a security program
for application security. Prior to joining DTCC, he was Vice President,
Information Security for Investec (US) Inc. responsible for the
implementation of an enterprise wide Information Technology and
Information Security program. He has managed various large online
banking related projects from architecture design, implementation
and management. He was in-charge of a large trading floor environment
and production datacenter along with BCP including Confidentiality,
Integrity and Availability of the trading floor and related environments.
Parthiv went to CUNY University where he received his BS in Computer
Science. He holds CISM and CCNA certifications.
In addition, Parthiv has experience in computer operations, Internet
online systems, and secure system/network administration with specialties
in Intrusion Detection Systems (IDS), Design and implementation
of Incident Response Process (IRP) based on ITIL incident management,
various Firewall Systems, Vulnerability Assessments/Penetration,
Hacking tools, Intrusion techniques, Vulnerability Management process,
BCP design and implementation process etc. He has developed numerous
corporate information security policies for various corporations;
performed security assessment of various customers sites based on
ISO27001 controls; has hands-on experience of large trading floor
environment as well as datacenter management; has performed TCP/IP
security re-designs for Investec (US) Inc., a project including
initial discovery, design, and implementation of new TCP/IP addresses
for all internal, external, firewall and DMZ regions of the enterprise
in a three-phase, systematic approach.
|