Security Test Analyst Resume
Detroit, MI
SUMMARY
- 7+ years of experience as a Security Analyst, and proficient in Security Testing, Web Application Testing, Network Penetration Testing, Cloud Architecture and Configuration Review, Threat Modeling, Risk Management, Identity and Access Management, and Vulnerability Assessment.
- Experience in Developing and Implementing Information Security Policies and guidelines as per OWASP Top 10 guidelines and SANS Secure Coding guidelines.
- Experienced and proficient in Security Framework of OWASP, BSIMM, Secure SDLC, along with expertise in OWASP Top 10, SANS 25, CWE and CVSS.
- Familiar with industry standards and control frameworks, risk assessment frameworks, security assurance auditing standards, best practices guidelines, such as ISO/IEC 27001, NIST CSF, FAIR, SSAE 16/18, CSA, CIS Top 20 etc.
- Hands - on Experience using a wide variety of security tools that include Kali Linux, Acunetix 360, Burp Suite, Nessus Professional, Cobalt Strike, Metasploit, Wireshark, Lophtcrack, Snort, Cain and Abel, Nikto, Dirbuster, NMAP, OpenVas, W3AF, BeEF, SQLmap, John the Ripper, Aircrack-ng, Hydra, Ettercap, Maltego.
- Capable of identifying flaws like Injection, Cross-Site Scripting (XSS), Insecure Direct object reference (IDOR), Security Misconfiguration, Sensitive data exposure, Broken Access control, Vulnerable and Outdated Components and Unvalidated redirects.
- Proficient in C, C++,Python, HTML, Javascript, CSS, XML, Powershell and Bash Shell Scripting.
- Executed Wireless penetration Testing (WPA, WPA2, WEP) using Aircrack-ng, airgeddon, trackerjacker, Cain and Abel.
- Real-time traffic analysis, network IDS and packet dissection using WireShark.
- Skilled at preparing detailed assessment reports with remediation, recommendations, and presenting the findings to the clients and also re-testing the security issues, once the fix of the respective vulnerability has been implemented.
- Excellent verbal and interpersonal, negotiation, judgment, decision making and problem solving skills.
- Experience in ticketing systems like Service Now, JIRA, Remedy and HP Quality Center.
- Recognised as a strong leader and an excellent team player. Committed to forming strong and productive teams.
TECHNICAL SKILLS
Core Expertise: Web Application Testing, Mobile Application Testing, Network Penetration Testing, Source Code Review, Cloud Architecture and Configuration Review, Wireless Penetration Testing, Container Security, Secure Coding practices, Threat Modeling, Risk Management, Identity and Access Management, and Vulnerability Assessment.
Programming, Scripting, Mark-up Languages: C, C++,Python, HTML, Javascript, CSS, XML, Powershell and Bash Shell Scripting.
Tools: used: Kali Linux, Acunetix 360, Burp Suite, Snyk, Sonarqube, HCL Appscan, Nessus Professional, Cobalt Strike, Metasploit, TheHarvester, Empire, Mimikatz, Netcat, Wireshark, Lophtcrack, Snort, Cain and Abel, Nikto, DirBuster, nmap, Open Vas, W3AF, BeEF, SQLmap, John the Ripper, Aircrack-ng, airgeddon, trackerjacker, Hydra, Ettercap, Maltego.
Standards familiar with: OWASP Top 10, WASC 40, SANS 25, ISO/IEC 27001,PCI DSS, NIST CSF, FAIR, SSAE 16/18, CSA, CIS Top 18 etc.
PROFESSIONAL EXPERIENCE
Confidential, Detroit, MI
Security Test Analyst
Responsibilities:
- Confidential INC, is a services based company delivering business solutions via information technology consulting for its clients by combining dedicated, focused, ethical efforts with experienced I/T professionals.
- Worked on the development and implementation of new system security plans to ensure NIST control requirements are met, conducted risk assessments, and drafted new information security policies and procedures.
- Assessment and review of security logs to ensure compliance with CIS benchmark policies and procedures, and identify potential anomalies.
- Provided root cause analysis and remediation techniques for clients in regards to security incidents and governance documents.
- Worked hand in hand with the team to have a proper artifact collection and brief to clients examples of artifacts that will satisfy assessment requirements.
- Completed penetration tests on network systems and configured and updated antivirus servers
- Provided concise and professional deliverables for architecting and implementing Enterprise-level logging and security event information management solution.
- Identified issues on sessions management, Input validations, output encoding, Logging, Exceptions, Cookie attributes, Encryption, Privilege escalations.
- Responsible for web application vulnerabilities (OWASP TOP 10, SANS) to review application source code to find its security vulnerabilities (CSRF, XSS, SQL Injection, Privilege Escalation, etc.) and recommend remediation.
- Managed PCI (Payment Card Industry) Compliance Program and ensures cardholder data security standards meet PCI DSS (Payment Card Industry Data Security Standards) requirements. Serve as the initial point of approval for the acceptability of PCI evidence.
- Developed risk assessment reports to identify threats and vulnerabilities. Assessed threats, risks and vulnerabilities from emerging security issues to advise pertinent stakeholders on appropriate measures.
- Created risk assessments based on CIS Benchmarks and CVSS scoring methodology and provided remediation
- Performed routine vulnerability scans against specified systems, analyzed the results, and worked with business units to remediate systems.
- Planned project activities viz. scoping, estimation, tracking, change management, delivery management and post implementation support.
- Timely update of the project status to required stakeholders of the project.
Confidential, Chicago, IL
Security Test Analyst
Responsibilities:
- Confidential provides public relations services to businesses, using a cloud-based, or software as a service (SaaS) model.
- Confidential offers social media monitoring and engagement and media publicity services.
- Coordinated with the IT Director and security teams of Confidential, to develop and maintain IT security policies, architecture, and security across the organization, including performing audits of security systems to maintain compliance with standards and protocols.
- Performed risk management and threat analysis using Xvigil, a Dark Web Monitoring tool and forwarded the findings to Cyber Forensic Investigations or Security Incident Response team to further investigate and remediate findings.
- Identified and evaluated the risks during review and analysis of system development life cycle (SDLC), which includes the design, testing /QA and implementation of systems and upgrades.
- Conducted IT security controls risk assessment that include reviewing organizational policies, standards and procedures and provide advice on their adequacy, accuracy and in compliance with the Payment Card Data Security Standard (PCI DSS).
- Maintained and Executed AWS Cloud Information security strategy to proactively identify risk and drive remediation.
- Worked with the project teams on implementing the defined policies within the AWS (IAM) solutions cloud infrastructure.
- Performed live packet data capture with Wireshark to examine security flaws. Used LDAP injections techniques for exploiting Web applications that use client supplied data.
- Performed dynamic and static analysis of web applications using Acunetix 360.
- Analyzed systems for potential vulnerabilities that may result from improper system configuration, hardware or software flaws, or operational.
- Scanned financial database for Confidential 's clients for vulnerabilities based on the RESTful architectures.
- Reviewed security documentation and made recommendations. Assisted in a conference call meeting with the Developer to mitigate vulnerability findings.
- Performed analysis on security data and conducted data visualization to create comprehensive technology risk reports for the IT department.
Confidential
White Hat Hacker
Responsibilities:
- Delivered information security consulting services that include vulnerability assessments and penetration testing of different applications, to confirm the presence of web-related vulnerabilities.
- Efficiently assessed 100 Web and Mobile Application assessments following OWASP, WASC and SANS standards.
- Communicated and enforced security policies, procedures, and safeguards for all systems and staff, based upon NIST.
- Skilled at preparing vulnerability disclosures and recommended solutions to fix them according to the front-end and back-end technologies.
- Collaborated with vendors to perform penetration tests on network devices, operating systems and databases.
- Performed analytical support of security incident calls across the enterprise.
- Vulnerability Management, collaborated with other team members to scan the application for vulnerabilities and threats.
- Reporting, Metrics, Deliverables - Provided concise and professional deliverables for architecting and implementing
- Enterprise-level logging and security event information management solution.
- Helped to research open-source intelligence feeds for current and emerging threat information.
- Investigated logs and payloads for server crashes/core dumps, DDoS attacks, SQL/XSS, SPAM, etc
- Provided root cause analysis and remediation techniques for clients in regards to security incidents and governance documents.
- Identified flaws like SQL Injection, Cross-Site Scripting (XSS), Insecure direct object reference, Security Misconfiguration
- Sensitive data exposure, Functional level access control, Cross Site Request Forgery (CSRF), Unvalidated redirects.
Confidential
Penetration Security Tester
Responsibilities:
- Performed penetration testing on BFIL’s infrastructure and vulnerability assessment of database servers.
- Recommended IT security improvements to achieve system confidentiality, integrity and availability.
- Developed risk assessment reports to identify threats and vulnerabilities.
- Assessed threats, risks and vulnerabilities from emerging security issues to advise pertinent stakeholders on appropriate measures.
- Actively listened to customers, handled concerns quickly and escalated major issues to the supervisor.
- Performed routine vulnerability scans against specified systems, analyzed the results, and worked with business units to remediate systems.
- Experience in implementing security in every phase of SDLC. Excellent knowledge in OWASP Top 10 2017, and WASC THREAT CLASSIFICATION 2.0 methodologies.
- Involved in Analysis and Design phase to diligently understand client requirements, document specifications and sign on the objectives.
- Scheduled vulnerability scans against specified systems, analyzed the results, and worked with business units to remediate systems.
Confidential
Information Security Auditor
Responsibilities:
- Confidential is a leading application security provider helping businesses across fintech and blockchain technology, securing applications, through Web and Mobile application security assessments
- API security assessments, Blockchain security audits, Smart Contract audits, Compliance Management etc.
- Worked on various technologies, good at understanding the business of the applications.
- Identified various scenarios for security and regression testing.
- Acquainted with various approaches to Grey and Black box security testing
- Identified Critical, High, Medium, Low vulnerabilities in applications based on OWASP Top 10 and SANS 25 and prioritizing them based on the criticality.
