Available for Leadership & Consulting Discussions

Divakar

Cybersecurity Leader in Secure Access,
Endpoint Protection & Modern Enterprise Defense

10+ years in cybersecurity, network & IT infrastructure · Master's in Cybersecurity · Team Lead — FortiSASE, FortiEDR & FortiClient EMS · Originally from India, rebuilding & leading from Canada since 2018

Status Team Lead – Service Delivery
Location Canada
Focus FortiSASE · FortiEDR · EMS

Built on Deep Infrastructure.
Focused on What's Ahead.

I am a results-driven IT and cybersecurity professional with over 10 years of progressive experience in network security, endpoint protection, secure access, and service delivery management. Having moved from building enterprise networks in India to leading secure access and endpoint protection operations in Canada since 2018, every role has been a deliberate step toward broader responsibility and sharper technical focus.

Today, I manage enterprise-scale security operations and lead high-performing technical teams delivering FortiSASE, FortiEDR, and FortiClient EMS. My work delivers measurable improvements in threat response, SLA performance, and operational efficiency. I bring deep expertise in ZTNA, SASE, EDR, and SIEM, built on a strong foundation in network infrastructure, incident response, and compliance frameworks such as NIST CSF, CIS Controls, and PIPEDA.

My Master's in Cybersecurity reinforced what years of hands-on work taught me: security is an operational discipline. The best defenses are the ones understood, maintained, and continuously improved by people who know the environment.

Looking forward, I am actively leveraging AI-assisted security operations, LLM prompt engineering, and workflow automation to modernize enterprise security programs—extending human analyst capacity to make security operations faster, more consistent, and more resilient at scale.

10+ Years in Cybersecurity & Infrastructure
3 Fortinet Platforms — Service Delivery Lead
M.Sc. Cybersecurity
Secure Access Endpoint Protection SASE Service Delivery Network Security AI-Driven SecOps

Platform Expertise & Service Delivery

My current work centers on three Fortinet security platforms, delivered as an operational service across enterprise environments. Each represents a distinct domain with its own operational rhythms, escalation paths, and continuous improvement cycles.

FortiSASE

Secure Access Service Edge

I lead service delivery operations for enterprise FortiSASE deployments, managing the secure internet access and private application connectivity layer for distributed workforces. My role covers operational health monitoring, policy lifecycle management, SLA adherence, and escalation ownership across customer environments.

Working with FortiSASE means operating at the intersection of SD-WAN, ZTNA, and cloud-delivered security — ensuring users connect securely and consistently whether they're in a corporate office, remote location, or on the road.

  • Service health oversight and proactive incident management
  • Policy design review and optimization for distributed user populations
  • Cross-functional coordination for onboarding and change management
  • SLA reporting, trend analysis, and continuous service improvement

FortiEDR

Endpoint Detection & Response

I oversee the operational management of FortiEDR deployments, with a focus on detection quality, response process efficiency, and the reduction of false positives that erode analyst confidence over time. My experience includes tuning detection policies, managing escalation workflows, and improving incident response playbooks.

Effective EDR isn't just about tooling — it's about building operational discipline around it. I work to ensure the platform generates signal that teams can act on, with response processes that are consistent, documented, and continuously reviewed.

  • Detection policy tuning and exclusion management
  • Incident response workflow ownership and playbook development
  • Platform performance monitoring and alert triage quality improvement
  • Coordination with security operations teams on escalated events

FortiClient EMS

Endpoint Management & Control

My work with FortiClient EMS centers on endpoint posture visibility, compliance enforcement, and the operational management of the EMS deployment as an enterprise-scale platform. I manage deployment health, software update cycles, and ensure endpoint telemetry flows cleanly into the broader security ecosystem.

A well-run EMS environment means every endpoint is accounted for, posture checks are enforced consistently, and the data coming out of the platform is reliable enough to inform security decisions.

  • EMS platform health and endpoint inventory management
  • Posture-based compliance enforcement and policy deployment
  • Telemetry integration with SASE and EDR environments
  • Update management and endpoint software lifecycle oversight

Network & IT Infrastructure

Foundation Layer

Before my current platform-focused role, I spent years building, managing, and securing enterprise network and IT infrastructure across India and Canada. This foundation — routing and switching, firewall administration, VPN, and systems management — underpins everything I do at the platform level.

Understanding infrastructure deeply means I can diagnose problems others might miss, communicate effectively with both technical teams and leadership, and approach platform security operations with genuine context about what's running beneath the surface.

  • Enterprise routing, switching, and firewall design and management
  • VPN infrastructure and remote access security
  • IT operations, systems administration, and service management
  • Incident response and network troubleshooting across distributed environments

Case Studies

Anonymized but representative engagements from enterprise service delivery work. Each reflects a real operational challenge — not a sales deck scenario.

FortiSASE

Distributed Workforce Secure Access Rollout

Challenge

A large organization with offices across multiple regions needed to replace legacy VPN infrastructure for a workforce that had become permanently distributed. Security policy was inconsistent across sites, and the existing architecture couldn't scale to support cloud application usage without significant performance degradation.

Approach

Led the operational planning and phased rollout of FortiSASE as the replacement secure access layer. This included defining policy architecture, coordinating user migration batches, and establishing monitoring runbooks to detect connectivity issues early. Change management was a significant workload — clear communication with end users and helpdesk teams was essential.

Platforms
FortiSASE ZTNA SD-WAN FortiClient EMS
Impact

Decommissioned legacy VPN infrastructure for the affected user population. Reduced connectivity-related support tickets in the weeks following migration. Established a repeatable rollout playbook used for subsequent regional expansions.

FortiEDR

EDR Operational Improvement & Detection Tuning

Challenge

An enterprise FortiEDR deployment was generating high alert volumes with significant false positive rates. Analysts were experiencing fatigue, critical alerts were taking longer to triage, and there was no documented standard for exclusion management or escalation. Confidence in the platform was eroding.

Approach

Conducted a systematic review of the alert landscape — categorizing detections by type, application, and business context. Developed a structured exclusion framework that balanced noise reduction with detection integrity. Rebuilt the incident response workflow with clear triage tiers, escalation criteria, and documented playbooks for the most common alert classes.

Platforms
FortiEDR SIEM Integration Incident Response Playbook Development
Impact

Measurable reduction in alert volume with no significant change to true positive detection rates. Faster mean-time-to-triage on critical events. Analyst confidence and platform trust improved. The exclusion framework and playbooks became the operational baseline for ongoing EDR management.

FortiClient EMS

EMS Deployment with Posture-Based Endpoint Control

Challenge

An enterprise environment lacked consistent endpoint visibility across its managed device fleet. The organization couldn't reliably enforce compliance requirements — outdated agents, missing patches, and unmanaged devices were connecting to the network without posture checks. There was no integrated view of endpoint health.

Approach

Deployed and configured FortiClient EMS to bring all managed endpoints under centralized visibility and control. Designed posture-check policies aligned to the organization's compliance baseline. Integrated EMS telemetry with the FortiSASE environment to enable posture-based access decisions — endpoints failing compliance checks received restricted access rather than a binary block/allow.

Platforms
FortiClient EMS FortiSASE Integration Endpoint Posture Compliance Enforcement
Impact

Full managed device visibility achieved within the defined scope. Posture-based access policies actively enforced across the connected user base. Compliance reporting available on demand. The EMS-SASE integration reduced manual access management overhead significantly.

Current Focus

Beyond day-to-day service delivery, I'm investing time in the intersection of AI-driven security operations and enterprise-scale automation. The security operations landscape is shifting — and the organizations that benefit most will be the ones that prepare their platforms and processes now.

AI-Assisted Threat Detection

Exploring how machine learning and behavioral analytics can augment analyst capacity — reducing dwell time and improving detection accuracy without adding noise.

Endpoint & SASE Telemetry

Deepening my work on unified telemetry across FortiEDR and FortiSASE — building richer context around user and device behavior for more informed security decisions.

Automation & Workflow Improvement

Identifying repetitive operational tasks that can be automated — from alert triage and enrichment to compliance reporting — to free up analyst time for higher-value work.

Cloud-Delivered Security

Following the maturation of cloud-native security architectures and understanding how FortiSASE and similar platforms fit into the broader SSE/SASE evolution.

Secure Enterprise Operations

Continuing to build operational frameworks that make enterprise security programs more consistent, measurable, and resilient — bridging the gap between platform capability and real-world operational execution.

Timeline

Mar 2025 – Present · Vancouver, BC

Fortinet | Team Lead, Service Delivery

Manage and mentor a team of solutions consultants and escalation engineers delivering FortiSASE, FortiEDR, and FortiClient EMS across North American enterprise accounts.

  • Oversee platform operations, incident response, service health monitoring, and continuous improvement programs — maintaining 99%+ SLA compliance across 50+ enterprise clients.
  • Define and execute ZTNA/SASE-aligned service delivery strategy; collaborate cross-functionally with engineering, product, and sales to drive escalation resolution and client retention.
FortiSASE FortiEDR FortiClient EMS Team Leadership Service Delivery
Feb 2024 – Mar 2025 · Vancouver, BC

Fortinet | Principal Solutions Consultant — EDR, EMS, SASE

  • Architected end-to-end SASE and EDR solutions aligned with Zero Trust, PIPEDA, and NIST; led pre-sales engagements and proof-of-concept evaluations for Canadian enterprise accounts.
  • Developed security roadmaps with client IT leadership to improve endpoint visibility, threat detection maturity, and incident response capability.
SASE & EDR Architecture Pre-sales & PoC Security Roadmaps
Apr 2023 – Feb 2024 · Vancouver, BC

Fortinet | Senior Solutions Consultant — Endpoint Security

Delivered enterprise EDR deployments and platform optimization across Canada; produced runbooks and SOPs that reduced mean time to detect (MTTD) and respond (MTTR).

EDR Deployments Platform Optimization MTTD / MTTR
Oct 2021 – Apr 2023 · Vancouver, BC

Fortinet | Escalation Specialist — Endpoint Security

Managed Level 2/3 escalations for FortiEDR and FortiClient EMS; performed malware triage, root cause analysis, and threat containment across multi-tenant environments.

L2/L3 Escalations Malware Triage Root Cause Analysis
Oct 2020 – Oct 2021 · Canada

NTT DATA Services | Security Analyst

  • Monitored and triaged security events via SIEM platforms for enterprise clients in regulated industries; conducted vulnerability assessments aligned with NIST CSF and CIS Controls.
  • Supported incident response activities: log analysis, forensic investigation, and post-incident reporting.
SIEM Vulnerability Assessments Incident Response
Mar 2019 – Aug 2020 · Vancouver, BC

New York Institute of Technology – Vancouver | IT Support Analyst

  • Administered DNS, DHCP, VPN, and Active Directory for campus network infrastructure; provided Tier 1/2 support across Windows and macOS environments.
  • Built a self-service knowledge base that reduced repeat ticket volume and improved first-call resolution (FCR) rates.
DNS, DHCP, VPN Active Directory Tier 1/2 Support
Jan 2016 – Dec 2017 · Chennai, India

TCTS | Senior Network Operations Engineer

  • Managed large-scale WAN/LAN infrastructure maintaining 99.9% uptime; resolved BGP, OSPF, VLAN, and firewall incidents under strict SLAs across multi-site enterprise environments.
  • Deployed proactive monitoring via Nagios and SolarWinds; reduced unplanned outages through early fault detection and automated alerting.
WAN/LAN Infrastructure BGP & OSPF Nagios & SolarWinds
Jan 2015 – Jan 2016 · Chennai, India

TCTS | Junior Engineer, Network Operations

Monitored network health across multi-site telecom infrastructure; configured routers, switches, and firewalls per change management procedures.

Network Monitoring Routers & Switches Change Management

Skills & Platforms

Security Platforms & Tools

  • FortiSASE, FortiEDR, FortiClient EMS
  • CrowdStrike, Carbon Black
  • Nmap, Wireshark, tcpdump
  • Netcat, Nessus, OpenVAS
  • Burp Suite, Metasploit

Security Domains

  • EDR, SASE, ZTNA
  • SIEM & Threat Intelligence
  • Endpoint Security
  • Vulnerability & Risk Management
  • Incident Response & Threat Forensics

Networking

  • SSL/TLS, DNS, DHCP
  • BGP, OSPF, VPN/IPSec
  • TCP/IP, LAN/WAN
  • Firewall Architecture
  • OSI Model

Frameworks

  • NIST CSF
  • CIS Controls
  • Zero Trust
  • MITRE ATT&CK
  • ITIL, PIPEDA

Core Competencies

  • IT Service Delivery Management
  • Cybersecurity Operations & Strategy
  • Team Leadership & People Management
  • SLA & Stakeholder Management
  • Change & Vendor Management

Cloud, Observability & AI

  • Azure AD, IAM, Cloud Security
  • Grafana, Prometheus, ELK Stack
  • Nagios, SolarWinds
  • n8n, Workflow Automation
  • LLM Prompt Engineering, AI SecOps

Tools

Chrome Extension

CBL — Clean Browse Ledger

Description

Strips tracking from URLs, logs cookies and consent, captures privacy policies. All local.

5 Key Features
  • Pre-load URL cleaning — strips utm_source, fbclid, gclid, msclkid, and affiliate parameters before the page loads, with a full before/after record saved to history.
  • Cookie inspection — snapshots all cookies for any domain with full detail: name, domain, path, expiration, remaining lifetime, secure, HttpOnly, SameSite, session vs. persistent, and partitioned flag.
  • Consent detection — automatically logs when you click cookie banner buttons (Accept All, Reject All, Save Preferences, etc.) with a confidence level and the button text.
  • Cookie policy analysis — when consent is detected, fetches the site's privacy policy and runs local keyword analysis to surface advertising cookies, data sharing, third-party vendors, opt-out language, and more.
  • 100% on-device — no network requests, no telemetry, no analytics, no cloud processing. All data stays in chrome.storage.local.

Let's Connect

I'm open to conversations about cybersecurity leadership opportunities, consulting engagements, and discussions with security practitioners, CISOs, and technology leaders. If you're building or improving an enterprise security program — particularly around secure access, endpoint protection, or managed security services — I'd be glad to connect.

Whether it's a role that needs someone who can lead operationally and think strategically, or a technical challenge where experience with Fortinet's security platform matters — reach out.

Divakar Manohar — Cybersecurity Professional | FortiSASE, FortiEDR & Fortinet Expert

Divakar Manohar is a senior cybersecurity professional and Team Lead based in Canada, with over 10 years of progressive experience in network security, endpoint protection, secure access, and service delivery management. He specializes in Fortinet security platforms — specifically FortiSASE, FortiEDR, and FortiClient EMS — and leads enterprise service delivery across these platforms, delivering measurable improvements in threat response and SLA performance.

His expertise includes SASE (Secure Access Service Edge), EDR (Endpoint Detection and Response), Zero Trust Network Access (ZTNA), SIEM, endpoint posture management, and incident response. He has a strong foundation in network infrastructure and compliance frameworks such as NIST CSF, CIS Controls, and PIPEDA. He is also actively leveraging AI-assisted security operations and workflow automation. He holds a Master’s degree in Cybersecurity.

Divakar Manohar is available for cybersecurity leadership roles, senior security operations positions, and consulting engagements. He is particularly well-suited for organizations running or evaluating Fortinet’s security ecosystem, SASE deployments, or endpoint protection programs.

Contact Divakar Manohar: hello@divakar.ca · LinkedIn · GitHub

Key terms: FortiSASE specialist Canada · FortiEDR engineer · Fortinet cybersecurity expert · SASE implementation Canada · EDR operations lead · cybersecurity team lead Canada · FortiClient EMS administrator · endpoint security Canada · ZTNA expert · secure access Canada · cybersecurity service delivery · SIEM · NIST CSF · AI SecOps