10/02/2025 updated

**** ******** ****
100 % available

Experienced Solutions Architect focussing on Cybersecurity and Agentic AI

United Kingdom
Worldwide
Masters In computer science
United Kingdom
Worldwide
Masters In computer science

Profile attachments

SA_CV_abhishek_mishra_ATS_3C.docx

JavaScriptControles de AccesoApple Certified Support ProfessionalApplication Programming Interfaces (APIs)Amazon Web ServicesAmazon CloudfrontAmazon Elastic Compute CloudAmazon S3Android Software DevelopmentApache HTTP ServerApache TomcatServer ApplicationApple IOSApplications ArchitectureSoftware ApplicationsArchitectureHTML5AuthenticationsMicrosoft AzureBig DataBoost (C++ Libraries)Business AnalysisC++ (Programming Language)Cascading Style Sheets (CSS)Content Delivery NetworksCloud ComputingConfiguration ManagementComputer SecurityDatabasesSecurity ControlsCryptographyIBM DB2Relational DatabasesIBM WebSphere DataPower SOA AppliancesEngineering Design ProcessDirect ConnectMulti-Factor AuthenticationAmazon DynamoDBMiddlewarePerformance ManagementGradleApache HadoopHadoop Distributed File SystemApache HiveIBM Cloud ComputingIBM Websphere Application ServerIdentity ManagementIdentity Verification ServicesInfrastructure ManagementWildFly (JBoss AS)Python (Programming Language)Key ManagementKnockout.jsLex (Software)PostgreSQLLong-Term MemoryMachine LearningApache MavenMicrosoft Foundation Class Library (C++ Libraries)Microsoft SQL ServersWindows APIModel BuildingMongoDBNode.jsNoSQLNumPyOAuthOpenIDOpenShiftOracle DatabasesPlatform As A Service (PAAS)Ping (Networking Utility)Public Key InfrastructureX.509Regulatory RequirementsAnsibleTensorFlowAkamaiZero Trust Network AccessRSA (Cryptosystem)Secure CodingService-Oriented ArchitectureSingle Sign-OnVaultStatisticsVirtualizationData/Record LoggingStandard Template Library (STL)Enterprise Application PlatformLoad BalancingApache CassandraChatbotsData ScienceCyberarkSpring CloudReact.jsApache SparkSpring BootSoftware SecurityDeep LearningRibbon (Software)ArchimateAWS LambdaFirewalls (Computer Science)AWS VPCBackendKerasTogafpandasMatplotlibBuild ManagementAmazon Relational Database ServiceAngularJSApache FlumeScikit LearnKubernetesAvroXgboostDaskHashicorpApache KafkaApache NifiIbm BluemixRoute53Privileged Access ManagementApi GatewayPuppetRestful ApiElastic BeanstalkDdosCrypto CurrencyMessengerSplunkAppdynamicsApi ManagementDockerElastic Load BalancingMicroservices
My experience spans over 21 years across various roles that have encompassed solutions architecture, business analysis, technical design, application architecture, development across mobile and enterprise applications. I am a hands-on individual, proficient in architecture, design and implementation using a variety of languages and tools.


1) Information Security
 
  • Implementation of enterprise-wide standards for modern authentication with Microsoft Azure AD and federation other Identity providers such as AWS Cognito, Ping, and Auth0.
  • Token exchange solutions to help cross-communication between modern and legacy applications.
  • Management of credentials for human, machines and service accounts. Privileged access management, Single Sign On.
  • Dynamic service account credentials,
  • Zero Trust Architecture, Continuous access evaluation, PDP/PEP Infrastructure.
  • Password-less login, multi-factor authentication, location-aware access control.
  • Identity assurance, passport/government identity verification.
  • Design and implementation of technical security controls to meet regulatory requirements for the management of identities and credentials.
  • Access governance systems. Request, review, and reconciliation of access rights and entitlements for human and service accounts.
  • Credential vault technologies (CyberArk, Hashicorp, Azure Key Vault, AWS Secrets Manager)
  • Public Key Infrastructure, X509 and OpenSSH certificates, Certification authorities.
  • MITRE ATT&CK framework, TTPs, Cyber Threat Intelligence.
  • RSA and Elliptic-curve key generation, and secure exchange.
  • IBM Advanced Crypto Service Provider (ACSP)
  • SafeNet Luna HSM, Thales nShield HSM.
  • Knowledge of common SEI CERT secure coding guidelines, OWASP TOP 10 application security vulnerabilities, and the  CIA (Confidentiality, Integrity, Availability) triad of information security.
  • Knowledge of cryptographic algorithms (AES, 3DES, PGP, PKC, RSA, EC-DSA), hash functions (MD5, SHA), and key exchange protocols (Diffie-Hellman)
  • HMAC-SHA message digests, HTTP Mutual Auth, SSL Pinning, Key Management.

2) Cloud, Virtualization, and Middleware Technologies
 
  • Azure App Service, Azure Service Bus, Azure Storage, Azure Key Vault, Azure Kubernetes Service.
  • Amazon Web Services EC2, ECS, ELB, S3, CloudFront CDN, Elastic Beanstalk, VPC, Route53, CloudHSM, DirectConnect, Amazon API Gateway, AWS Lambda
  • Red Hat OpenShift V2, V3.
  • Docker, Kubernetes.
  • PaaS with OpenShift V3 on AWS Cloud.
  • IBM Bluemix/IBM Cloud. IBM WebSphere DataPower SOA Appliance.
  • Load balancers (F5 LTM, F5 GTM, IBM IHS)
  • Firewalls (F5, Imperva WAF)
  • Akamai/Kona DDOS protection.
  • Configuration Management with Puppet, Ansible.

3) Microservice/SOA/ REST APIs
  • Development of RESTful micro services with Node.JS, Spring Boot, Eureka, Ribbon, Hysterix, Zuul.
  • Service configuration management with Spring Cloud Config, UrbanCode.
  • JBOSS, Apache Tomcat, IBM WebSphere ND, IBM WebSphere Liberty application servers.
  • IBM API Connect API gateway, Kong API gateway, Amazon API Gateway. Azure API Management.
  • REST API authentication and authorization methods such as OAuth2, OIDC,, IP whitelisting. Mutual-auth, API Keys.
  • Application logging to Splunk and performance management with AppDynamics.

4) Machine Learning, Data Science and Big Data.
  • Machine learning model building with LightGBM, CatBoost, XGBoost, SVM.
  • Distributed training with Dask.
  • Bayesian Hyperparameter optimization with HyperOpt, BayesOpt.
  • Training and deploying deep learning models with Keras (Google TensorFlow backend)
  • Python 3, Scikit-learn, NumPy, Pandas, Matplotlib.
  • Cloud-based model training and deployment with AWS SageMaker.
  • NLP with Amazon Comprehend
  • Building chatbots with AWS Lex and integration with Facebook messenger.
  • Hortonworks Hadoop stack
  • Apache Spark, Apache Avro, Apache Flume, Apache NiFi.
  • Apache Kafka, Apache MirrorMaker,
  • Apache Hive, Hadoop HDFS. Tableaux.

5) Architectural Frameworks & Tools
  • Knowledge of TOGAF, EA3, ArchiMate.
  • Knowledge of Troux enterprise application repository.

6) Databases
  • RDBMS (Azure PostgreSQL, Oracle 11g, IBM DB2, MS SQL server, Amazon Aurora, Amazon RDS)
  • NoSQL databases (Azure Cosmos DB, Amazon DynamoDB, MongoDB, Apache Cassandra)

7) Other Development
  • iOS & Android application development.
  • AWS Integration with iOS & Android applications.
  • Developing desktop applications with C++/VC++ (MFC) with WinAPI, STL, Boost and MFC.
  • HTML5, CSS, JavaScript, Node.JS, Knockout.js, ReactJS, AngularJS, WinJS.
  • Build management tools Gradle, Maven.


 

Languages

EnglishNative speaker

Project history

Senior Architect (Director), Identity & Access Management - UBS

UBS Business Solutions AG

Banking & Financial Services

>10.000 team member

I worked as a service/domain architect in the IAM space. The domain I am responsible for encompasses
identity providers, SSO solutions, location-aware access control, enterprise vault technologies, PKI
systems, MFA systems, password-less login, management of service accounts, human and application
account credentials, and physical buildings access control. My key contributions in his role are as
follows:

* Lead architect for a regulatory technical security control to address the ownership, lifecycle
management, credential management, and access right management of application service accounts
across the enterprise.
* I lead a cross-divisional bank-wide API security working group of that is responsible producing
patterns and guidance for the adoption of modern authentication (OAuth2/OIDC) with Microsoft
Azure Active Directory, adoption of service mesh technology, and migration from Apigee to Azure
API Management across the enterprise.
* Headed the IAM working group. This was a forum to discuss current and future concerns and align
strategy across application access control, infrastructure access control and access governance.
* Architecture, design, and rollout of a password-less login solution for employees to enable 2FA
access to Citrix workspace desktops. This solution leverages software provided by Transmit
security to replace traditional Windows passwords with a strong mobile app-based 2FA login
experience and was heavily relied upon during the pandemic to support remote working.
* Architecture and design of enterprise service account credential storage strategy leveraging a
mix of Hashicorp vault, CyberArk and Azure key vault.
* Design of enterprise-wide standards to cover the lifecycle, storage, and cryptographic
requirements for the use of tokens in the bank.
* Design of dynamic service account credential strategy, using multiple vendor and in-house
products.
* Architecture of a solution to replace an older employee building access control system with a
more cost-efficient option from Thales.
* Architecture and design of a mobile-app based customer identity assurance as a service offering
to support the onboarding activities of new wealth management customers. This service allows
customers to use their government issued identity documents and an app on their mobile phones to
verify their identity. Solution was based on software from iProov biometric solutions and Regula
forensics.
* Participating in IAM-specific vendor/product evaluation.
* Participating with Microsoft to shape and evaluate new product features built by Microsoft in
Azure to address UBS needs.
* Architecture and design of tools and processes to manage the request, review, and reconciliation
of permissions requested by application teams on Azure AD service principals and managed
identities.
* Creation of patterns to promote adoption of Zero Trust Architecture principles within the bank.
* Creation of patterns to leverage Azure API Management for internal and external microservices.
* Creation of security event logging and monitoring requirements for applications and identity
providers, corelating these requirements with MITRE ATT&CK TTPs,

Security & Fraud Solutions Architect - Lloyds Banking Group

Lloyds Banking Group

Banking & Financial Services

>10.000 team member

I worked as a solutions architect with the Security, Authentication & Fraud lab within Lloyds
Banking Group. I have worked on the following:

* Worked with the Payments, Fraud, & Financial Crime theme to design and deliver into production a
solution that allows customers on low-risk payment journeys to self-serve fraud alerts using an
out-of-band authentication mechanism. This involved:
* Building a number of RESTful micro services to build a CIBA (Client Initiated Backchannel
Authentication) compliant OOB auth mechanism in the bank,
* Building a number of integration layer micro services to allow the retail authenticated
payments journeys to integrate with the OOB authentication services
* Modification of the banks retail cross channel transactional fraud detection engine.
* Development of micro services to suspend/cancel/release payments and suspend/reinstate
mandates.
* Capacity planning, infrastructure uplift, application logging, service monitoring.
* Integration with Hortonworks Hadoop-based Big Data platform for service analytics and
Tableaux reporting.

* Worked with the Strong Customer Authentication (SCA/PSD2) team to design and build a primary
customer step-up authenticator mechanism for 128 journeys spanning retail banking, business
banking, open banking, and cards. This is a high-availability Category A service capable of
sustaining 1200 transactions per second.

* Worked with the Mobile security team to build an asymmetric cryptography-based transaction
signing mechanism on the Lloyds, Halifax, and Bank of Scotland mobile app. This involved working
with a third-party supplier as well as creating micro services to manage key exchange, key
storage , key rotation, and digital signature validation.

* Worked with the Mobile security team to build a server-side security product that captures
real-time behavioral, malware, and usage data from the banks mobile apps to make a decision on
whether the device running the app can be trusted at the point a transaction is made.

* Worked with the Big Data Insights team to build a generic data ingestion pipeline from micro
services into Hadoop clusters. This involved using Apache Flume, Kafka, Spark, Hive.

* Worked with third-party security service provider CallSign to integrate their AWS-hosted services
with the banks systems via AWS DirectConnect.

* Architectural governance and Infrastructure solution design for abovementioned items, including
F5 GTM/LTM configuration, Firewall configuration, DNS setup, API gateway onboarding, and MA-TLS
setup.

Solutions Architect - Barclays Bank PLC

Barclays PLC

Banking & Financial Services

>10.000 team member

(Received award for Outstanding Contribution to the Barclays Launchpad platform).

I have worked as a solutions architect on the Barclays Launchpad team. The Launchpad product won the
Banking Technology Innovation award 2016. My day-to-day responsibilities involved:

* E2E (end-to-end) design involving data on mainframes, Ab Initio ETL processes, PaaS service
layers, Internet Facing Environments (IFE), CMS, Mobile gateways, Web servers, Application
Servers, Logging (Splunk), Application Monitoring (AppDynamics) and Databases (Oracle, Mongo).
* Managing relationships with third-party vendors.
* Building solutions to allow third-party vendors to provide Docker containers that will be spun up
on OpenShift V3 pods and connected to other up-stream services.
* Creating solutions to integrate PFM (personal finance management), behavioral and biometric
security technologies provided by third-party vendors.
* Creating strategies to auditing vendor-provided Docker images.
* Providing leadership to bring together business, application, infrastructure and data
requirements into a single set of solutions options and recommendations.
* Providing clear choices and recommendations to stakeholders to facilitate business and technical
decision making.
* Managing key relationships with stakeholders across multiple business units.
* Reviewing use cases and related requirements documents for technical feasibility and logical
consistency.
* Identifying and documenting key architectural decisions in Confluence and ensuring these are
shared and aligned with governance standards.
* Creating High-Level Design (HLD) and Detailed-Design (DD) documents. Securing approval from
different departments within the bank.
* Building and maintaining relationships with individuals from Security, GIS, Data Privacy,
Compliance, ETL, Data, and Fraud teams.
* Ensuring solutions are fit for purpose and strategically aligned as well as meeting relevant
standards and regulatory requirements.
* Liaising with service and configuration management teams to build relevant xPaaS environments,
and integrate relevant monitoring systems with software deployed onto these environments.

Portfolio


Contact form

Log in to get in touch

You need to be logged in to use the contact form.

Sign upLog in