Summary
Overview
Work History
Education
Skills
Languages
Accomplishments
Certification
References
Timeline
GeneralManager
Ashlee Naidoo

Ashlee Naidoo

Security Consultant
Rolleston,Christchurch

Summary

I'm an IT Security Specialist with over 20 years of experience focused on keeping tech environments safe, including work on AWS Cloud, and ensuring both applications and infrastructure are secure. My background includes managing application support, overseeing system administration, planning for disaster recovery, and taking proactive steps to prevent outages, all to keep systems running smoothly. I'm adept at approving secure app designs, minimising technical risks, and upgrading systems securely. I also create secure application guides, analyze technical incidents in detail, and assess risks to make sure new technologies are safely introduced. Beyond technical skills, I have lead security teams, handle executive meetings, mentor junior staff, and deliver projects on time, prioritizing security and risk management at every step.

Overview

21
21
years of professional experience
4
4
Certification

Work History

Senior Security Consultant

Department of Internal Affairs (DIA)
Wellington , NZ
2023.07 - Current

As a seasoned Security Consultant with the Department of Internal Affairs, my expertise encompasses identifying and mitigating vulnerabilities across diverse systems through in-depth assessments of existing security measures. I adeptly navigate both physical and cyber security landscapes, pinpointing threats and formulating robust strategies for enhanced protection. My role involves aligning with key security frameworks and standards (SASBA, NZISM, NIST) to ensure regulatory compliance and bolster security postures. I facilitate businesses in vendor onboarding in compliance with the GCDO 105 process and offer specialised consulting and advisory services, including certification and accreditation processes, vendor interactions, and security-focused architectural design reviews.

I contribute significantly to architectural planning, support Business Continuity and Disaster Recovery planning, and identify and prioritise High-Risk High-Value assets for timely certification and project delivery. My efforts are crucial in integrating log data with Security Information and Event Management (SIEM) systems for operational security enhancements, safeguarding organisational assets, data, and personnel against security threats through strategic and comprehensive measures.

Senior Security Consultant

Grant Thornton New Zealand
Wellington , NZ
2022.06 - 2023.07

In my role as a Senior Security Consultant at Grant Thornton NZ, my contributions were critical in the provision of comprehensive cybersecurity services, including penetration testing, rigorous compliance certification audits, and in-depth strategic IT health evaluations for a varied portfolio of clients, spanning both the private and public sectors. My experience facilitated the navigation of complex regulatory landscapes, employing SOC 2 Type 1 and Type 2, ISAE 3402, and PCI DSS assessments, underpinned by an understanding of NZISM and NIST standards to maintain unparalleled security integrity. I led the charge in orchestrating Certifications and Accreditations (C&A), executing meticulous security architectural reviews, and formulating bespoke in-house security training initiatives. My efforts in risk assessment and procedural refinement were instrumental in forging strategic alliances with external security vendors. Additionally, my guidance enabled clients to significantly advance their cybersecurity frameworks through the application of Forrester Maturity Frameworks, thus delivering secure, compliant, and anticipatory security solutions.

IT Security Analyst

Silverstripe
Wellington , NZ
2021.11 - 2022.05

Within the dynamic IT Security Team at Silverstripe, my role as an IT Security Analyst was pivotal, collaborating directly with the Chief Information Security Officer (CISO) to architect and implement robust security measures safeguarding our organisation's IT infrastructure. This includes the protection of networks, hardware, and software against cyber threats, thereby enabling a secure, collaborative, and efficient information security environment. This role positions me at the heart of Silverstripe's security initiatives, where my expertise not only contributed to the protection and resilience of the IT environment but also empowered our teams to develop and maintain secure solutions, reinforcing our commitment to cybersecurity excellence.

Senior Support Engineer

Silverstripe
Wellington , NZ
2020.10 - 2021.11

In my role as a Senior Support Engineer within the Platform Support team, I provided both first and second level support to a wide range of clients, encompassing internal and external customers. Tasked with handling a high volume of work, my focus remained steadfast on achieving outstanding customer satisfaction through quality service and rapid response times. My responsibilities were multifaceted, including operational and technical support to platform clients, bespoke teams, as well as CWP and SSP support, facilitated through the proficient use of helpdesk systems such as Freshservice and Mantis. This role demanded versatility, offering 24/7 support on a scheduled roster, addressing a spectrum of client requests ranging from bug fixes, setup requests, and troubleshooting, to general maintenance, security issues, migrations, minor enhancements, and support for clients' development teams. I prioritised issue resolution in accordance with urgency and importance, actively contributed to the release activities of the Silverstripe product, and efficiently managed pull requests, ensuring rigorous testing and QA processes were followed. Additionally, I played an active role in process improvement within the wider Platform Squad, aiming to enhance platform operations, identifying automation opportunities, and supporting the integration of new team members, all towards elevating the team's performance and service excellence.

Intermediate Support Engineer

Silverstripe
Wellington , NZ
2020.03 - 2020.09

The role involves being part of the Platform Support Squad and covers most customer support interactions, as well as Application and Infrastructure support. In the role, I respond to a high volume of work with a focus on high customer support & satisfaction. This involves building key relationships with various internal and external customers, as listed below:

  • Product Development Squad
  • Product Owner
  • Solution Architects & Service Delivery Team
  • Common Web Platform clients (various New Zealand Government departments including DIA)
  • Silverstripe Platform clients (Local New Zealand and International clients, including ISPs) & Silverstripe partners

Senior IT Security Operations Engineer

Standard Bank of South Africa
Johannesburg , ZA
2017.07 - 2020.02

In my role at Standard Bank as a Senior IT Security Operations Engineer, I was responsible for the comprehensive support and management of risk and security applications critical to the IT operations. This entailed a deep understanding of both the business processes these applications facilitated and the underlying technologies they utilised, such as server management, application software, and infrastructure.

This role allowed me to blend technical expertise with strategic foresight, contributing significantly to the bank's security posture and operational excellence.

Education

First Class Diploma - Computer Graphics & Web Design

College Campus
South Africa
2001-12

Skills

  • Security Consulting & Advisory
  • Security Frameworks & Standards Compliance
  • Vulnerability Assessment & Risk Management
  • Security Strategy Development
  • Certification & Accreditation Processes (C&A)
  • Architectural Security Reviews
  • Security Information and Event Management (SIEM) Integration
  • Access Control
  • Incident Response
  • Penetration Testing
  • Compliance Management
  • High-Risk High-Value Asset Management
  • Intrusion Detection
  • Access Management
  • Cybersecurity
  • InfoSec
  • Risk Management
  • Application Security

Languages

English
Native/ Bilingual
Afrikaans
Limited

Accomplishments

Secured over NZ$ 5 354 000 by maintaining systems and ensuring availability to avoid customer fraud taking place on security applications for internet banking and mobile banking and resolved a new application problem with one of the major retailers and retained to the client with high monetary/transaction value.

Certification

  • ISC2 Certified in Cybersecurity - October 2023
  • ICAgile Certified Professional - April 2023
  • AWS Certified Cloud Practitioner - August 2019
  • Linux Essentials Professional Development Certification - November 2017

References

References available upon request.

Timeline

Senior Security Consultant

Department of Internal Affairs (DIA)
2023.07 - Current

Senior Security Consultant

Grant Thornton New Zealand
2022.06 - 2023.07

IT Security Analyst

Silverstripe
2021.11 - 2022.05

Senior Support Engineer

Silverstripe
2020.10 - 2021.11

Intermediate Support Engineer

Silverstripe
2020.03 - 2020.09

Senior IT Security Operations Engineer

Standard Bank of South Africa
2017.07 - 2020.02

First Class Diploma - Computer Graphics & Web Design

College Campus
  • ISC2 Certified in Cybersecurity - October 2023
  • ICAgile Certified Professional - April 2023
  • AWS Certified Cloud Practitioner - August 2019
  • Linux Essentials Professional Development Certification - November 2017
Ashlee NaidooSecurity Consultant