We provide IT Staff Augmentation Services!

Senior Penetration Tester Resume

4.00/5 (Submit Your Rating)

Washington, DC

CAREER SUMMARY:

  • Senior technical and functional Consultant with 17+ years of experience in full life cycle implementations in both private and public sectors.
  • Highly skilled with gathering, analyzing, and managing business requirements, technical architecture design, development, implementation, testing and end user training.
  • Excellent verbal, written and interpersonal skills.
  • Experienced with penetration testing, web application security, and producing system vulnerability assessments.

RELEVANT TECHNOLOGY EXPERIENCE:

Siebel 7.x / 8.x, C#, Javascript, Node.js, Express, Mongodb, Ruby, Ruby on Rails, Python, HTML, CSS, Splunk, Wireshark, Tcpdump, Nmap, Powershell, Nessus, Webinspect, Metasploit, Burp suite, John the Ripper, Kali Linux, Amazon Web Services, hashcat

RELEVANT EXPERIENCE:

Confidential, Washington, DC

Senior Penetration Tester

Responsibilities:

  • Assist with the development of Secure Operation Center (SOC) mock exercises to test the SOC’s ability to detect, identify, and resolve incidents
  • Develop management briefings on SOC Exercise results including lessons learned and areas for improvement
  • Setup and deploy a raspberry pi to mimic a malicious device on the network
  • Assess data exfiltration identification capabilities
  • Work with the SOC to implement Indicators of Compromise
  • Assess Guest Wireless Network security
  • Setup and deploy a wifi pineapple in order to harvest credentials
  • Assess the ability for Guest Wireless clients to access internal resources
  • Assess the security of Active Directory and Identity Credential Access Management solutions
  • Utilize Burp Suite Professional to review SAML and session management implementation
  • Utilize Powershell Empire to simulate an exploited workstation in the enterprise
  • Perform Manual Web Application reviews
  • Manage Amazon Web Services (AWS) infrastructure to support penetration testing needs
  • Deploy AWS infrastructure to support agency’s github enterprise scanning initiative using gitrob
  • Deploy and maintain kali linux instances
  • Utilize scripting languages such as python, powershell, and ruby to support security assessments
  • Utilize hashcat to perform password attacks during penetration tests and to assess the password complexity of privileged accounts
  • Perform ad - hoc security assessments including network hardware in order to determine if a risk is posed when introducing certain software/hardware on the enterprise network

Confidential, Washington, DC

Development Team Lead

Responsibilities:

  • Serve as primary point of contact for the program’s Information Security Systems Officer (ISSO)
  • Work with ISSO to prioritize vulnerability remediation with development efforts
  • Review HP Fortify Webinspect scans and validate reported vulnerabilities
  • Validate SQL Injection vulnerability using Burp Suite Proxy in a .NET Web application
  • Identify and Remediate Poor Error Handling vulnerability (verbose error messages) and implement generic error messages in .NET applications
  • Harden non-domain servers by manually creating Windows Server security templates to meet the DHS Standard
  • Utilize Wireshark to capture and log passwords being sent in cleartext
  • Manage, coordinate, and implement migration from TECC data center to DC1 data center
  • Author MiDAS full build installation document
  • Facilitate the coordination of multiple teams including network engineers, application administrators, and system administrators
  • Manage and coordinate MiDAS development activities in a Kanban Agile Environment
  • Provide Tier 3 Help Desk support
  • Provide Siebel development and administration expertise

Confidential, Washington, DC

Systems Engineer

Responsibilities:

  • Lead facilitation sessions between Siebel and Tibco development teams to clarify requirements and make design decisions
  • Manage the Modeling effort using Unified Modeling Language (UML) including creating message classes and sequence diagrams
  • Test Lead for the Account Systems Engineering Team
  • Ensure client’s expectations are met by reviewing test artifacts and validating them against signed off requirements
  • Lead discussions with developers for defect resolution
  • Troubleshoot testing defects using SoapUI to test service inputs/outputs and document findings
  • Analyze and Validate that Tibco processes meet customer signed off low level design artifacts
  • Present findings of inaccuracies and inconsistencies to developers
  • Lead weekly meetings with client to discuss project milestones and action items in conformance with project plan and deliverables

Confidential, Washington, DC

Siebel Application Developer/Administrator

Responsibilities:

  • Delivered design recommendations and impacts based on the analysis of business requirements to the client
  • Maintain security posture of servers by identifying required patches and managing the deployment of these patches
  • Authoring and delivered various documentation during the release cycle, including the management of peer reviews and the submission of deliverables to the client
  • Experienced with the Information Technology Lifecycle Management (ITLM) process
  • Delivered excellent Tier 3 Help Desk support to the client
  • Communicated with customers of varying computer experience to address their issues
  • Documented changes to Tier 1 and Tier 2 knowledgebase documentation to assist in the efficiency of issue resolution
  • Lead Developer responsible for the delivery of configured Siebel Public Sector 7.8 components including the following tasks:
  • Delivered several eScripts to meet business requirements where user properties or a declarative alternative was not an option.
  • Utilized run time events in conjunction with business services to execute client’s business rules
  • Utilized business component user properties whenever possible to meet customer requirements
  • Modified .ifb files and created new Enterprise Integration Manager (EIM) attribute mappings for new and existing columns
  • Lead Siebel Administrator responsible for providing Siebel Administration support including the following tasks:
  • Increasing the log levels on various Server components to troubleshoot issues
  • Analyzing log files to determine point of failures
  • Managing repeating component jobs for optimal performance
  • Experience in High Availability architecture including Microsoft Clustering
  • Experience with Siebel Servers in Microsoft environment
  • Limited experience with Siebel Servers in AIX environment

Confidential, Washington, DC

Siebel Application Developer/Administrator

Responsibilities:

  • Delivered design recommendations and deliverables based on the analysis of the Adoption Case Management System’s Phase II, III, and IV business requirements
  • Delivered configured Siebel Public Sector 7.8 components that utilized Siebel’s security best practices and met client expectations including the following tasks:
  • Delivered several eScripts to meet business requirements where user properties or a declarative alternative was not an option
  • Utilized run time events in conjunction with business services to execute client’s business rules
  • Utilized business component user properties whenever possible to meet client’s requirements
  • To meet security requirements, created a workflow triggered by a Repeating Component Request in order to expire user accounts after a certain time of inactivity
  • To meet security data visibility requirements, created views utilizing user properties that manage data visibility
  • Created workflow processes to handle integration activities utilizing data maps and business services
  • Lead Siebel Administrator responsible for providing Siebel Administration support including the following tasks:
  • Analyzing log files to determine point of failures
  • Limited experience with Siebel Servers in AIX environment
  • Performed analysis of Siebel upgrade from version 7.8.2.5 to 8.1
  • Lead Siebel Developer responsible for the coordination and delivery of a Section 508 compliant Siebel Public Sector implementation to meet the Department of Homeland Security’s Section 508 Compliance Standards
  • Experienced with Siebel’s Section 508 capabilities
  • Responsible for providing Siebel 508 design considerations and impacts to development team
  • Experienced in dealing with Oracle’s Section 508 product group and discussing workarounds
  • Presented a report on Siebel’s Section 508 deficiencies to the client
  • Presented a demonstration of Siebel’s Section 508 capabilities to the client
  • Configured all Views and Applets to meet 508 Compliance standards

Confidential, Falls Church, VA

Senior Product Specialist

Responsibilities:

  • Siebel Configuration Lead on LCMS responsible for the design analysis and configuration of Siebel Public Sector to meet the needs of The Executive Office of United States Attorney’s (EOUSA) event management requirements.
  • Utilized the Siebel Object “Inventory” to manage storage locations and files.
  • Utilized run-time events to trigger workflows to automatically create file records when provided with a storage location
  • Configured the Siebel Object “Activities” to meet Event Management requirements.
  • Siebel Configurator on The Australian Department of Immigration and Citizenship (DIAC) Detention Portal project responsible for requirements gathering and design analysis in an effort to develop the to-be technical specifications for the Siebel Public Sector Implementation.
  • Utilized the Siebel Object “Auto Vehicles” to capture information regarding the apprehension of boats and passengers
  • Created Views to display Case information for a passenger that has been apprehended.
  • Quality Assurance lead on the DIAC Detention Portal project responsible for managing the configuration team’s workload and the implementation of resolutions to configuration and design documentation defects

Confidential, Rosslyn, VA

Federal IT and Management Consultant

Responsibilities:

  • Lead Tester for the Department of Homeland Security (DHS) Information Sharing Environment (ISE) project responsible for developing test procedures and managing meetings with the development team in order to develop criteria for acceptance, in an effort to conduct systems testing
  • Business Analyst for the Bureau of Economic Analysis (BEA) Reengineering project responsible for analyzing and developing accurate process data flows, functional requirements, wireframes and screen flows. Also responsible for holding client interviews in an effort to identify information needed to create these requirements and deliverables
  • Acting as a main point of contact and CMMI interviewee, responsible for the requirements development and requirements management process areas of the Confidential & Confidential CMMI Level 3 assessment. Responsibility included providing evidence of the company’s adherence to the standards established by SEI (Software Engineering Institute) according to CMMI Level 3
  • Responsible for managing and developing a secure web based requirements traceability tool as an artifact for CMMI Level 3 compliance. The tool was developed using Blue Ink (RAD application) in C# with a SQL Server back end (data model was built using Visio)

Confidential, Fairfax, VA

Advanced Consultant

Responsibilities:

  • Performed all installations and upgrades from Siebel 7.0 to 7.5.2, and applying appropriate patches to 7.5.3 for system fixes
  • Implemented a High Availability Architecture including load balancing and clustering software for the Production Environment. High Availability Environment consisted of the following:
  • One Siebel Web Server
  • Two clustered Siebel Gateways utilizing Microsoft Cluster Service
  • Two clustered Siebel Object Managers utilizing Microsoft Cluster Service
  • Two load balanced Siebel Object Managers utilizing Resonate
  • One Siebel Document Server
  • Familiarity gained with Cisco switch when setting up the Development environment
  • Working with all levels of client staff (from CTO to end user) in an effort to manage needs and expectations of client management
  • Functioning as team lead as well as a business analyst responsible for requirements gathering and design analysis of current technical environment in an effort to develop technical specifications for Siebel Implementation
  • Anticipating client support needs and developing and implementing plans to meet them
  • Utilizing fact-finding, analytical and problem-solving methods and techniques to resolve interrelated problems, identify trends, draw conclusions, and present alternatives and recommendations to management
  • Generating and presenting client deliverables including status reports and recommendations involving risks and design modifications to upper management
  • Developing documentation including Technical/Functional Specifications, Use Cases, Requirements Matrices and Technology concepts for clients and upper management
  • Developing and implementing User Training Manuals and Operation Plans in an effort to ensure productive user training and client understanding
  • Providing support during system testing and functionality of the Siebel database to ensure operating effectiveness and identify errors and risks with the system
  • Utilizing eScript when appropriate on various environments
  • Installation and Maintenance of environments using Siebel 7.7.2

We'd love your feedback!