Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic
Christian Angelo Gallano

Christian Angelo Gallano

Cybersecurity Specialist
Quezon City

Summary

Protects enterprise environments through vulnerability management, incident response, and control design across SIEM, XDR, Microsoft Defender, and cloud security platforms. Leads risk assessments, audit remediation, and SaaS reviews while documenting standards and coordinating with third-party MSSPs. Strengthens security operations with proactive monitoring, awareness training, and sustainable compliance controls.

Overview

7
7
Certifications
8
8
years of professional experience

Work History

Cybersecurity Analyst

Medulock LLC
08.2024 - Current
  • Developed and implemented security policies to enhance organizational data protection.
  • Conducted regular security assessments to ensure compliance with industry standards.
  • Analyzed security incidents to identify vulnerabilities and recommend corrective actions.
  • Conducted regular vulnerability assessments to identify weaknesses and implement appropriate countermeasures.
  • Streamlined security monitoring processes using advanced threat detection tools.
  • Improved threat detection with deployment of state-of-the-art intrusion detection systems.
  • Enhanced data integrity and confidentiality by designing and applying comprehensive encryption strategies.
  • Collaborated with cross-functional teams to address emerging threats effectively.
  • Educated employees on cybersecurity awareness through training sessions, significantly reducing instances of human error-related breaches.
  • Led cybersecurity awareness training sessions, increasing employee understanding of potential security threats and preventive measures.
  • Performed risk analyses to identify appropriate security countermeasures.
  • Developed and maintained detailed documentation on security processes, facilitating knowledge transfer and ensuring consistency in procedures.

PAG - L3 Security Analyst

Your Employee Offshore (YEMPO)
04.2024 - 08.2024
  • Formulate and outline standard operating procedures and protocols.
  • Analyzes risks and establishes security standards, procedures, and controls to mitigate risks.
  • Managed threat identification and mitigation processes to enhance organizational security posture.
  • Guarantee conformity with internal and external audit standards (e.g., folder analysis, access privilege inspection, account scrutiny, SaaS appraisal)
  • Ensured compliance with internal and external audit standards through folder analysis, access privilege inspection, account scrutiny, and SaaS appraisal.
  • Administers and tracks Microsoft Defender solutions and services, XDR, Cloud Applications, EASM, etc.
  • Administers Google Chronicle SIEM platform
  • Administers infosec self-service platform
  • Point of contact for third-party MSSP contractor Deloitte
  • Execute SaaS analysis for potential software providers
  • Conducted risk analysis and assessments to inform proposed corrective actions and strengthen security measures.
  • Establishes security controls risk assessment framework and program that meet regulatory requirements, ensuring documented and sustainable compliance

Uzado Inc. - System and Security Engineer

Outsourced Quality Assured Services Inc | Uzado Inc.
03.2023 - 04.2024
  • Identify and outline system security specifications.
  • Mentored new cyber defense team member to enhance team capabilities and knowledge sharing.
  • Safeguarding data through secure storage and consistent backups.
  • Implementation of Patches. (Monthly Windows Patches KB’s, Firewall Patches and etc.)
  • Configuring and maintaining the networked computer system, including hardware, system software, and applications.
  • Diagnosing and resolving hardware, software, networking, and system issues when they arise.
  • Administer network servers and technology tools.
  • Monitoring system performance to ensure everything runs smoothly and securely.
  • Facilitated seamless user onboarding and offboarding to improve employee experience and system security.
  • Reinforced security framework by integrating access controls, backups, and firewalls to safeguard sensitive data.
  • Coach and develop fellow CDF members to achieve professional objectives
  • Manage Data and Backup Recovery. (Netapp and Snapshot on Vcenter).
  • Upgraded components to improve system performance.
  • Replacing and upgrading defective or outdated components when necessary.
  • Creates rules and policy as per request on Exchange, Intune, Sharepoint and etc.
  • Adherence to client’s corporate policies.
  • Support diverse clientele and initiatives.
  • Intermediary for technology vendor's technical support.
  • Creation of Monthly CDF Schedule

Uzado Inc. - SOC Analyst

Outsourced Quality Assured Services Inc | Uzado Inc.
01.2022 - 03.2023
  • Security Management: The Hive Project (SIRP), Logz.io, SNYPR Securonix, AV USM Appliance, AV USM Central, Qualys Vulnerability Management, Kaseya DarkWeb ID, SentinelOne EDR
  • Worked in a 24x7 Security Operations Center.
  • Conducted proactive monitoring, investigation, and mitigation of security incidents to enhance organizational security posture.
  • Continuously monitoring and interpreting threats using the IDS and SIEM tools.
  • Analyzed security event data from network using AV USM Appliance, AV USM Central, SNYPR Securonix, and Logz.io to identify and respond to threats.
  • Analyze security event data from the network thru (AV USM Appliance, AV USM Central, SNYPR Securonix, Logz.io)
  • Perform incident monitoring, response, triage and initiate investigations
  • Perform investigations and evaluations of network traffics, read and interpret logs, sniffer packets, and PCAP analysis with RSA Security analytics and MPManager
  • Create and track incidents and request using ticketing tool: (Freshdesk, Freshservice)
  • Perform daily health check at the end of every shift
  • Recognize potential, successful, and unsuccessful intrusion attempts and compromises through reviews and analyses of relevant event detail and summary information.
  • Ensure the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies, through monitoring of vulnerability scanning devices.
  • Investigated malicious phishing emails, domains, and IPs using open-source tools, recommending effective blocking measures based on thorough analysis.
  • Use Vulnerability Assessment tools such as Qualys to perform security testing and IP Scan
  • Conduct research on new and evolving threats and vulnerabilities using security blogs.

IT Administrator

Staff Domain
04.2021 - 01.2022
  • Office 365 Global Administrator – Provisioning of MS license to users, Exchange Administrator, MS Teams Administrator.
  • Exchange Administrator – Manages shared mailboxes.
  • MS Teams Administrator – Adds users internal and guest users, Manages users, creation of policies, and creation of MS Teams channel.
  • Huawei Firewall – Created and modified DNS records, DHCP scopes and reservations, created VLANs, and assigned bandwidth to optimize network performance.
  • Huawei Firewall – Creation and modifying DNS records, DHCP scope and reservation, Creation of VLAN, Assignment of bandwidth.
  • Datto RMM – Creation of Sites, Creation of components, Automates Jobs, Job Scheduling, Manages Devices, and it can be used as a remote desktop platform as well.
  • Datto RMM Network – Implementation of created VLAN and activation of dataports.
  • Teramind Administrator – Implementation of Policies, Creation of Departments and Scheduling of Employees shift.
  • Waived quarantined files and applications after receiving change management request and approval from CTO and clients for whitelisting.
  • Cylance Protect – Waived quarantined files/application to facilitate it must have change management request along with the approval of CTO and clients for whitelisting applications/files.
  • ZOHO Ticketing Tool – Manages incoming IT Tickets, handling priorities, and creation of resolutions.
  • IT Reports – Created weekly and monthly IT reports, providing insights and suggestions for policy and procedure improvements in hardware and software deployment.
  • IT Incident Reports - Ensure that the incident management process is followed, and that incident and problem records accurately reflect actions taken to restore service; and that changes to Configuration Items are recorded.
  • Vendor Management – Served as liaison between technical contacts to facilitate communication and resolve issues.
  • Asset Management – Responsible for updating, tracking, and securing of all assets

IT Specialist

Clearbridge Medical Group Philippines
07.2020 - 03.2021
  • Installations of various software, configure printers, perform file restoration, and document all changes and issues.
  • Management of Clinic Management System and Laboratory Information System server.
  • Calibration of Sysmex and Vitros machines.
  • Extraction of items in Clinic Management System and Laboratory Information System.
  • Provides technical and troubleshooting assistance related to computer hardware and software.
  • Installations of various software, configure printers, perform file restoration, and documenting all changes and issues.
  • Administered MySQL database, supporting data integrity and accessibility for applications.
  • Creation of Knowledge Base.
  • Providing primarily support to the management and staff through IT Service Request form.
  • Proper coordination and escalation to vendors.
  • Provides orientation to the end user on how to operate our CMS and LIS systems.
  • Provided technical support and troubleshooting for computer hardware and software issues, enhancing user productivity.
  • Managed IT assets across the company, ensuring optimal utilization and tracking.
  • Orients employees on navigating various systems.

IT Associate

TDCX
05.2018 - 01.2020
  • Provided primary support for operations by creating accounts, sending credentials, troubleshooting connectivity issues for operational tools, and performing Active Directory cleanup.
  • Active Directory administering user’s accounts unlocking network accounts, resetting passwords, adding of Application and Security Group membership delegation, and adding users to their appropriate organizational unit groups or distro based on their job distinction.
  • Administered Microsoft Exchange, Dynamics 365, and Skype for Business, managing users, distribution lists, groups, mailboxes, and storage effectively.
  • Administered G-Suite Administrator performs management on Users, Groups and enrolled Chromebook and Chromebook Device.
  • JAMF administrator and performs MDM and Apple Device Enrollment.
  • Managing of Network Shared Drive Folder and provisioning access to the user upon request and must have their business justification and the approval of their supervisor on the request.
  • Provides technical and troubleshooting assistance related to computer hardware and software.
  • Creation of IT Standard Operating Procedure and for future knowledge based.
  • Achieved 99% SLA no violated tickets.
  • Proper coordination and escalation to vendors.
  • Ticket Management.

Education

Bachelor of Science - Information Technology (Undergraduate)

Polytechnic University of The Philippines
Sta. Mesa Manila
05.2001 -

Diploma - Information Communication Technology

Polytechnic University of the Philippines
Sta. Mesa Manila
05-2018

High School Diploma -

St. Joseph Catholic School
Philippines
05.2001 -

Skills

  • Google Chronicle SIEM, Logzio SIEM, Alienvault SIEM and SYNPR Securonix
  • CrowdStrike MXDR, SentinelOne MXDR and Cybereason MXDR
  • Microsoft Defender Administration
  • Qualys Vulnerability Management
  • Active Directory Administration
  • vMware Administration
  • Incident Triage
  • Threat Investigation
  • Log Analysis
  • Vulnerability Remediation
  • Security Awareness Training
  • Patch Management
  • Audit Support
  • Standard Operating Procedures
  • Access Control Management
  • Security Policy Documentation
  • SaaS Appraisal

Certification

Fortinet Network Security Expert (NSE 1): Network Security Associate

Timeline

Cybersecurity Analyst

Medulock LLC
08.2024 - Current

PAG - L3 Security Analyst

Your Employee Offshore (YEMPO)
04.2024 - 08.2024

Uzado Inc. - System and Security Engineer

Outsourced Quality Assured Services Inc | Uzado Inc.
03.2023 - 04.2024

Uzado Inc. - SOC Analyst

Outsourced Quality Assured Services Inc | Uzado Inc.
01.2022 - 03.2023

IT Administrator

Staff Domain
04.2021 - 01.2022

IT Specialist

Clearbridge Medical Group Philippines
07.2020 - 03.2021

IT Associate

TDCX
05.2018 - 01.2020

Bachelor of Science - Information Technology (Undergraduate)

Polytechnic University of The Philippines
05.2001 -

High School Diploma -

St. Joseph Catholic School
05.2001 -

Diploma - Information Communication Technology

Polytechnic University of the Philippines
Christian Angelo GallanoCybersecurity Specialist