We provide IT Staff Augmentation Services!

Penetration Tester Resume

3.00/5 (Submit Your Rating)

Portland, OR

SUMMARY:

  • Accomplished IT Security professional with 5+ years of work experience assisting organizations in successfully completing enterprise - wide security projects. Experienced in performing risk assessments, penetration testing and network / application vulnerability assessments. Vulnerability assessment and penetration testing using various tools like Burp Suite, DirBuster, OWASP ZAP Proxy, NMap, Nessus, Kali Linux and Metasploit.
  • Proven track record of streamlining security processes, designing and implementing efficient security solutions. Involved in implementing and validating the security principles of minimum attack surface area, least privilege and secure defaults, avoiding security by obscurity, keep security simple and fixing security issues correctly.
  • Experience in Threat Modeling during Requirements gathering and Design phases. Performed software Licensing audit.
  • Experience with Security Risk Management with TCP-based networking. Experience with TCP/IP, Firewalls, LAN/WAN. Static Code Analysis during development phase. Quick learner, committed team player with interpersonal skills and enjoys a challenging environment with scope to improve myself and contribute to the cause of the organization.

TECHNICAL SKILLS:

Tools: IBM AppScan Standard Edition, HP Web Inspect, Acunetix, Burp proxy, Paros proxy, OWASP, Web Scarab, Metasploit, Burp Suite, SQL map, OWASP ZAP Proxy and HP Fortify, DIR-Buster, Acunetix Web Scanner, Kali Linux, Fortify, Veracode.

Web Technologies: HTML, JavaScript

Platforms: Windows 98/2000/XP/Vista/Windows 7, Windows Server 2000/2003 Database My SQL 5.0

Packages: MSOffice

Network Tools: NMap, Wire Shark, Nessus

PROFESSIONAL EXPERIENCE:

Confidential - Portland, OR

Penetration Tester

Responsibilities:

  • Conducted security assessment of PKI Enabled Applications.
  • Skilled using Burp Suite, Acunetix Automatic Scanner, NMAP for web and mobile application penetration tests.
  • Acquainted with various approaches to Grey Black box security testing.
  • Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, weak cryptography, authentication flaws etc.
  • Actively search for potential security issues and security gaps that are beyond the ability of detection by any security scanner tool.
  • Initiate and develop new mechanisms to addresses unidentified security holes and challenges.
  • Real-time Analysis and defense.
  • Vulnerability assessment (VA), Security policy, and network and security audit.
  • Configuration and management of Cisco IDS, Checkpoint firewall.
  • Good knowledge of network and security technologies such as Firewalls, TCP/IP, LAN/WAN, IDS/IPS, Routing and Switching.
  • Monitor, Analyze and respond to security incidents in the infrastructure. Investigate and resolve any security issues found in the infrastructure according to the security standards and procedures.

Confidential - San Jose, CA

Security Engineer

Responsibilities:

  • Manual penetration testing of the applications and APIs to identify the OWASP Top 10 vulnerabilities and SANS 25.
  • the development team on the secure coding practices.
  • Black box pen testing on internet and intranet facing applications.
  • OWASP Top 10 Issues identifications like SQLi, CSRF, and XSS.
  • Preparation of risk registry for the various projects in the client.
  • Providing details of the issues identified and the remediation plan to the stake holders.
  • Grey Box testing of the applications.
  • Verified the existing controls for least privilege, separation of duties and job rotation.
  • Involved in a major merger activity of the company and provided insights in separation of different client data and securing PII.
  • Identification of different vulnerabilities of applications by using proxies like Burp suite to validate the server side validations
  • Identified issues on sessions management, Input validations, output encoding, Logging, Exceptions, Cookie attributes, encryption, Privilege escalations.
  • Execute and craft different payloads to attack he system to execute XSS and different attacks.
  • SQLmap to dump the database data to the local folder.
  • Environment: Nmap, Nessus, Burp Suite, DirBuster and Hp Fortify

Confidential

Security Engineer

Responsibilities:

  • Perform application and infrastructure penetration tests, as well as physical security review and social engineering tests for our global clients.
  • Review and define requirements for information security solutions.
  • Perform security reviews of application designs, source code and deployments as required, covering different types of applications (web application, web services, thick client applications, SaaS).
  • Participate in Security Assessments of networks, systems and applications.
  • Work on improvements for provided security services, including the continuous enhancement of existing methodology material and supporting assets.
  • Experience creating test cases, running test cases, automate test cases and logging/verifying defects.
  • Acquainted with various approaches to Grey, Black box security testing.
  • Penetration testing based on OWASP Top 10.
  • Skilled using Burp Suite, Acunetix Automatic Scanner, NMAP, Metasploit, WebInspect, Kali Linux, CheckMarks, DirBuster, IBM appscan, for web application penetration tests.
  • Responsible for performing static code analysis of application source code.
  • Participated in review meetings on daily, weekly and monthly basis for software development, i.e. relying on agile scrum development model.
  • Generated and presented reports on Security Vulnerabilities to both internal and external customers.
  • Capturing and analyzing network traffic at all layers of the OSI model.
  • Security assessment of online applications to identify the vulnerabilities in different categories like Input and data Validation, Authentication, Authorization, Auditing and logging.
  • Providing fixes and filtering false findings for the vulnerabilities reported in the scan reports.
  • Adding new vulnerabilities to the Vulnerability Database for various platforms with proper exploits.
  • Scan Networks, Servers and other resources to validate compliance and security issues using numerous tools.
  • Conducted onsite penetration tests from an insider threat perspective.
  • Actively involved in the release management process to ensure all the changes of the application had gone to security assessment.
  • Addressed and integrated Security in SDLC by following techniques like Threat Modeling, Risk Management, Logging, Penetration Testing, etc.

Confidential

Jr. Security Engineer

Responsibilities:

  • Perform threat modelling of the applications to identify the threats.
  • Identify issues in the web applications in various categories like Cryptography, Exception Management.
  • Worked on installation, configuration, administration and troubleshooting of LAN/WAN infrastructure.
  • Risk assessment on the application by identifying the issues and prioritizing the issues based on risk level.
  • Collaborate with team members to audit the application prior moving to production.
  • Provide explanation of the security requirements to the design team in initial stages of SDLC to minimize the efforts to rework on issues identified during penetration tests.
  • Providing remediation to the developers based on the issues identified.
  • Revalidate the issues to ensure the closure of the vulnerabilities.
  • Verify if the application has implemented the basic security mechanisms like Job rotation, Privilege escalations, Lease Privilege and Defense in depth.
  • Using various add on in Mozilla to assess the application like Wappalyzer, Flagfox, Live HTTP Header, Tamper data.

We'd love your feedback!