Information Security Analyst Resume
Pittsburg, PA
PROFESSIONAL SUMMARY:
- Excellent knowledge in OWASP Top 10 2010, and WASC THREAT CLASSIFICATION 2.0 methodologies.
- Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, weak cryptography, authentication flaws etc.
- Vulnerability Assessment includes analysis of bugs in various applications spread across N - tier on various domains by using both manual and Automation tools.
- Analyzing the results of penetration testing, designing reviews, source code reviews and other security tests.
- Experience using a wide variety of security tools to include Kali-Linux, Metasploit, Burp Suite Pro, Wireshark, Snort, Nmap, Cain and Abel, Nitko, Dirbuster, IBM AppScan, Nessus, Open Vas, W3AF, BeEF, Etthercap, Maltego.
- Involved in implementing and validating the security principles of minimum attack surface area, least privilege, secure defaults, avoiding security by obscurity, keep security simple, Fixing security issues correctly.
- Experience with TCP/IP, Firewalls, LAN/WAN.
- Strong knowledge in Manual and Automated Security testing for Networks and Web Applications.
- Good Knowledge in Amazon Web Service (AWS) concepts like EMR and EC2 web services which provides fast and efficient processing of Teradata Big dataAnalytics
- Ability to meet commitments and manage priorities in a fast-paced environment.
- Experience in Big data security .
- Ability to take data driven decisions using operational intelligence tools like Splunk.
- Experience in developing custom UDF's for Pig and Apache Hive to in corporate methods and functionality of Java into Pig Latin and HiveQL
- Experience with various operating systems like Windows, Linux.
- Have Experience on Integrating SAST tools like HP fortify with devops by using Jenkins
- Ability to communicate technical topics and facilitate discussions with the peers.
- Ability to implement and operate processes and methodologies in a manner that effectively supports business and information security objectives.
- SOX Compliance Audit experience on controls like User access management, Change Management, Incident Management
- Contribute to formalization of architectural framework standards for cloudhosting environment through the release of new products and enterprise applications
- Ability to coordinate with geographically diverse teams to drive results.
- Actively search for potential security issues and security gaps that are Confidential the ability of detection by any security scanner tool. Initiate and develop new mechanisms to addresses unidentified security holes & challenges.
- Good Experience in exploiting the recognized vulnerabilities.
- Quick Learner, committed team player with interpersonal skills and enjoy challenging environment with scope to improve self and contribute to the cause of the organization.
- Excellent problem-solving and leadership abilities.
- Strong written and verbal communication, interpersonal and presentation skills.
- An Information Security Analyst Professional with experience of 6+ years in penetration testing and vulnerability assessments on various applications in different domains. Involved in Software Development Life cycle (SDLC) to ensure security controls are in place.
TECHNICAL SKILLS:
Tools: IBM AppScan Standard Edition,HP Web Inspect, Acunetix, Burp proxy, Parosproxy, Wire shark, OWASP, Web Scarab, map, Metasploit, Burp Suite,SQLmap, OWASP ZAP Proxy and HP Fortify,DIR-Buster, Acunetix Web Scanner, SQL Injection Tools, Havij, CSRFTester AND Kali Linux, Fortify, veracoad,Webgoat SSL implementation, RSA implementation,Splunk, Stealth Watch,PKI (Public key infrastructure)Encryption algorithms
Platforms: Windows 98/2000/XP/Vista/Windows 7, Windows Server 2000/2003/2008
Database: My SQL 5.0
Packages: MSOffice
Network Tools: NMap, Wire Shark, Nessus, Qualys Guard
Network Enumeration: Maltego, Google Hacking, DNS, SMB, LDAP.
Port/Vulnerability Scanning: Nmap/Nmap Scripting Engine (NSE), Netcat, Nessus
Sniffing/ManintheMiddle: Wireshark, Ettercap, Cain
Web Application Vulnerability Scanning: Nessus, OpenVas, Vega, Acunetix, HP Web inspect, IBM AppScan.
Server/ClientSide Exploitation: Metasploit, Social Engineering Toolkit (SET).
Password Cracking: Hydra, Rainbow Crack, 0phcrack, John the Ripper, Pyrit
Web Application: Manual SQL Injection, Manual Cross Site Scritping(XSS), Cross site request forgery(CSRF), SQLmap.
Debuggers: Ollydbg, WinDBG.
Wireless: Aircrack-NG Suite and Kismet
WORK EXPERIENCE:
Information Security Analyst
Confidential, Pittsburg PA
Responsibilities:
- Worked in the development, optimization of critical operational programs and processes in support of web application security and production operations, including:
- Research opportunities for the mitigation of emerging vulnerabilities, know penetration testing techniques.
- Identifying the critical, High, Medium, Low vulnerabilities in the applications based on OWASP Top 10 and SANS 25 and prioritizing them based on the criticality.
- Ability to identify and dispute false positives regarding Botnet’s, Malware and Honeypot detection.
- Created and maintained clear comprehensive documentation of process and procedure.
- Monitoring and management of key internet security reputation metrics.
- Ability to create and contribute to strategic plans for continuous process / program improvement.
- Contribute to formalization of architectural framework standards forcloudhosting environment through the release of new products and enterprise applications
- Integrated HP fortify tool in SDLC by implementing it in the build servers to ensure it operates with devops
- Application Security Review of all the impacted and non-impacted issues.
- Applied knowledge of information security services/analysis concepts, practices and procedures.
- Experienced in Load Balancing with MQ Clusters and increased availability with High Availability Clusters.
- Skilled using tools like Burp Suite, Acunetix Automatic Scanner, NMAP, Dirbuster, Qualysguard, Nessus, IBMappscan, SQLMap, HP Fortify for web application penetration tests and infrastructure testing.
- Conductedpenetrationtests on applications using automated and manual techniques with tools such as Core Impact, Metasploit, Burpsuite, WebInspect, Kali Linux, CheckMarks, NetSparker and many other open source tools as needed.
- Worked with support teams to address findings as a result of the tests.
- Providing fixes & filtering false findings for the vulnerabilities reported in the scan reports.
- Assisted developers in remediating issues with Security Assessments with respect to OWASP standards.
Information Security Analyst
Confidential, Charlotte NC
Responsibilities:
- Conducted application penetration testing of 50+ business applications.
- Conducted Vulnerability Assessment of Web Applications.
- Responsible for leading in the research, mitigation, and coordination of actions designed to reduce information security risk across internet facing presence.
- Coordinate with dev team to ensure closure of reported vulnerabilities by explaining the ease of exploitation and the impact of the issue.
- Monitor the network and investigate the reported securityincidents and reported machine compromises using securitytools like Splunk and Stealth Watch
- Automation of static analysis using Jenkins just bs to kickoff the and upload the scan results during the build cycle of the project.
- Security assessment of online mobile applications to identify the vulnerabilities in different categories like Input and data Validation, Authentication, Authorization, Auditing & logging.
- Update with the new hackings and latest vulnerabilities to ensure no such loopholes are present in the existing system.
- Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, cryptographic attacks, authentication flaws etc.
- Skilled using Burp Suite, Acunetix Automatic Scanner, NMAP, Dirbuster, Qualysguard, Nessus, IBMappscan, SQLMap, HP Fortify for web application penetration tests and infrastructure testing.
- Conductpenetrationtests on systems and applications using automated and manual techniques with tools such as Core Impact, Metasploit, Burpsuite, WebInspect, Kali Linux, CheckMarks, NetSparker and many other open source tools as needed. Work with support teams to address findings as a result of the tests.
- Change Management to highly sensitive Computer Security Controls to ensure appropriate system administrative actions, investigate and report on noted irregularities.
- Conduct network Vulnerability Assessments using tools to evaluate attack vectors, Identify System Vulnerabilities and develop remediation plans and Security Procedures.
- Identifying the critical, High, Medium, Low vulnerabilities in the applications based on OWASP Top 10 and SANS 25 and prioritizing them based on the criticality.
- The experience has enabled me to find and address security issues effectively, implement new technologies and efficiently resolve security problems. With having strong Network Communications, Systems & Application Security (software) background looking forward for implementing, creating, managing and maintaining information security frameworks for large scale challenging environments.
Environment: Java, .Net, Oracle DBA.
Security Engineer (Penetration Testing/Vulnerability)
Confidential, Reston, VA
Responsibilities:
- Extensive Interaction with Onsite Coordinator in understanding the business issues, requirements, doing exhaustive analysis and providing end-to-end solutions.
- Doing multiple level of testing before production to ensure smooth deployment cycle.
- Creation of Generic Scripts for testing and reusability.
- Application Security Review of all the impacted and non-impacted issues.
- Providing KT to Development team for better understanding of Vulnerabilities.
- Ensuring compliance with legal and regulatory requirements.
Penetration Tester
Confidential
Responsibilities:
- Established vulnerability assessment practice, proactively ensuring safety of client-facing applications and minimizing client audit findings.
- Performing security analysis and identifying possible vulnerabilities in the key derivation function, create Vulnerability Assessment report detailing exposures that were identified, rate the severity of the system & suggestions to mitigate any exposures & testing known vulnerabilities.
- Having real time experience in DDos, Sql Injection protection, XSS protection, script injection and major hacking protection techniques
- To address and integrate Security in SDLC by following techniques like Threat Modeling, Risk
- Management, Logging, Penetration Testing, etc.
- Providing fixes & filtering false findings for the vulnerabilities reported in the scan reports.
- Adding new vulnerabilities to the Vulnerability Database for various platforms with proper exploits.
- Scan Networks, Servers, and other resources to validate compliance and security issues using numerous tools
- Assisting in preparation of plans to review software components through source code review or application security review
- Assist developers in remediating issues with Security Assessments with respect to OSWASP standards.
Security Engineer
Confidential
Responsibilities:
- OWASP Top 10 Issues identifications like SQLi, CSRF, XSS.
- Preparation of risk registry for the various projects in the client. the development team on the secure coding practices.
- Conducted research, mitigation, and coordination of actions designed to reduce information security risk across internet facing presence.
- Providing details of the issues identified and the remediation plan to the stake holders
- Identification of different vulnerabilities of applications by using proxies like Burp suite to validate the server-side validations
- Execute and craft different payloads to attack he system to execute XSS and different attacks.
- SQL Map to dump the database data to the local folder.
- Identified issues on sessions management, Input validations, output encoding, Logging, Exceptions, Cookie attributes, encryption, Privilege escalations.
