Sr. Security Engineer/analyst Resume
NJ
PROFESSIONAL SUMMARY
- Sr. Security Engineer having 11+years of total IT experience wif 5 years of development experience followed by over 6+ years of Security Engineering experience in Web, mobile and Cloud applications.
- Areas of Core strength are application security architecture, risk assessments, security design, threat modeling, secure coding, SAST/DAST/IAST, AWS Cloud security, security automation (CI/CD pipeline).
- Hands - on experience in conducting pen testing of both web, mobile and cloud applications.
- Well versed wif OWASP Top 10 and SANS25, having strong experience in Cryptography.
- Currently working directly wif various software development teams, engineering teams, system administrators in reviewing teh source code, identifying security vulnerabilities, triage and providing guidance to teh development teams to remediate teh vulnerabilities.
- Possess Excellent Communication and a Team Player.
TECHNICAL SKILLS
Metasploit Pro: AppDetect, AppRador, Oracle IdentityManager, Oracle Access Manager, JHijack, OAuth 2.0, SAML2.0, SQLMAP, Wireshark, WebScarab, Paros, Nmap, BMC BladeLogic, Tenable Nessus, Rapid7 Nexpose, Tripwire, Symantec DLP, DBProtect, HP ArcSight SIEM, DBProtect, e-DMZ Password Auto Repository (PAR), Varonis. Splunk ( SIEM)
DAST, SAST, IAST Security: IBM AppScan Enterprise, Veracode, Standard & Source editions, HP WebInspect, Fortify SCA, Checkmarx, QualysGuard, BurpSuite Pro, Acunetix, OWASP Zaproxy, Contrast Security IAST.
Network Security: Symantec DLP, Checkpoint, Palo Alto, Netcat, Tenable Nesses Security Center, Openvas, Cisco IDS/IPS, Symantec Endpoint Protection, Anti-virus. Apache, Encryption, Functional, Java Beans, Netscape, Proposals, Servlet, TIBCO
Cloud Security: Amazon Web Services and MS Azure,GCP
Middleware: TIBCO EMS, IBM WebSphere MQ, JMS
Pipeline: Jenkins, Maven, ANT, Gradle, RTC, GitHub, Aqua Container Security
Databases: Oracle, MS SQL Server, DB2, MySQ, MongoDB.
Operating Systems: Oracle Solaris UNIX, RedHat Linux, Kali Linux, Ubuntu
Servers: Weblogic Server, Linux, Windows Server 2008/2012, Netscape Application Server
Languages: Java, Python, C/C++, C#.NET, Perl, Struts2, Spring Framework, Servlets, JavaServerPages (JSPs), JMS, Java, UML. Mail API, JNDI, LDAP, JDBC, JTS, RMI, AWT, Swing, Socket Programming, IONA Orbix
PROFESSIONAL EXPERIENCE
Confidential, NJ
Sr. Security Engineer/Analyst
Responsibilities:
- Developed Application Security program (DAST, SAST, IAST) at teh enterprise level to identify, report and remediate security vulnerabilities from applications deployed in DEV, PRE-PROD and PROD environments.
- Designed, documented and executed maintenance procedures, including system upgrades, patch management (security patches) and system backups.
- Administered Linux servers which included user creation, patching, version upgrades, backup and recovery.
- Developed threat modeling framework (STRIDE, DREAD) for critical applications to identify potential threats during teh design phase of applications.
- Configured Active Directory (AD) to set up OUs and develop GPOs to enforce security policies at teh enterprise level.
- Implemented file system security by applying hashing techniques for protecting data stored in files on teh file servers.
- Providing Configuration management support in teh operation of a number of PKI systems deployed..
- Supported Business Public Key Infrastructure administration efforts on Venafi Encyption Director(VED).
- Developed and documented procedural documents for Certificate Governance dat outline teh process and procedures for executing teh Certificate Governance Program,
- Administered PKI, cryptography, certificate management and implemented dual keys to address segregation of duties issue between DBAs and security admins.
- Configured Gemalto ProtectDB to enable column level encryption for securing confidential customer data.Designed security architecture for web and mobile apps.
- Architect, Design and deliver Encryption, Key management and PKI Related solution
- Participate in development of roadmaps and participate in teh standards process for Identity and Access Management (IAM) solutions.
- Execute and track security process related activities including User ID management.
- Manage operations wifin teh IAM environment at teh client, including application patching and upgrades and certificate management.
- Implemented Multifactor Authentication (MFA) for AWS root accounts, including password rotation policies.
- Set up Access Keys and Secret Assess Keys for newly created users.
- Developed WACLS for AWS Web Application Firewalls (WAF) and configured teh rules and conditions to detect security vulnerabilities in teh Cloud Front.
- Performed vulnerability testing using tools such as Tenable Nessus Security CenterandQualysguard.
- Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, cryptographic attacks, authentication flaws etc.
- Counseled senior-level management on current privacy and security trends and recommendations to mitigate risk.
Confidential, FL
Security DevOps Engineer
Responsibilities:
- Implement all aspects of GCP(Google Cloud Platform) Infrastructure IAM, Security, Logging, Networking, Infrastructure as Code (IaC) using Terraform, CI/CD infrastructure Reviewed Qualys scan reports, performed teh triaging to eliminate false positives.
- Provided Technical Support to teh team and worked wif various information technologies like network devices, operating systems, endpoint security systems such as intrusion protection, antivirus solutions, and information security technologies.
- Implemented security controlsin accordance to NIST-800, CIS Benchmarks, FFIEC, ISO 27001 Frameworks.
- Worked wif DevOps tools such as Jenkins, Maven, ANT, GITHub, Python for CI/CD integration.
- Defined and deployed monitoring, metrics, and logging systems.
- Implemented systems dat are highly available, scalable, and self-healing on teh web, mobile and cloud platforms.
- Security incident response and perform necessary deep investigation and compromise containment
- Designed, managed, and maintained tools to automate operational processes.
- Developed Information Assurance (IA) designs to meet specific operational needs and environmental factors.
- Participated in teh implementation of AWS Cloud security for applications being deployed in teh Cloud.
- Configured Qualys scanner and performed both authenticated and unauthenticated scans.
- Enabled continuous monitoring for teh hosts using Qualys VM/VMDR.
- Developed WACLS and configured to rules and conditions to detect security vulnerabilities in teh AWS Cloud Front.
- Implemented OAuth2.0 andSAML authorization frameworks for granting permissions by third party Identify Providers.
- Experience wif SaaS applications in configuring and deploying to teh cloud platform Worked wif DevOps teams to automate security scanning into teh build process.
- Worked extensively wif software development teams to review teh source code, triage teh security vulnerabilities generated by IBM/HCLAppScan, BurpSuite, MicrofocusWebInspect, Fortify, Checkmarx and eliminated false positives.
- Troubleshoot network application inbound/outbound connectivity utilizing BluCoatproxies and Wireshark.
- Actively involved on Bridges in solving High / Severe incidents reported in teh application or in environment.
- Reported all my findings on teh incident status to teh higher management, clients in timely fashion.
- Held Responsibility for Securing and Maintaining 14 legacy applications, 10 geographically separated
Confidential, Piscataway, NJ
Security Analyst
Responsibilities:
- Provided project planning, guidance and technical expertise in program, policy, process, and planning; risk management, auditing, and assessments; A&A; and quality planning and control.
- Researched and analyzed non hacker methodology, system exploits and vulnerabilities to support Red Team Assessment activities.
- Performed advanced security testing of F5 load balancers, Websense V10K &BlueCoat Proxies using virtual machines, security tools, and URL generator.
- Assisted wif teh update and administration of all SOX audit requirements from an IT internal controls perspective.
- Performed security compliance assessments for all IT infrastructures (firewalls, VPNs, routers, IDS/IPs, DLP, Linux/Windows Active Directory security hardening).
- Provided wif Threat profiling of teh application to teh Client and prepared combined reports of level of risks, their trend, and frequency to teh client.
- Conducted white/gray box penetration testing on teh financial systems using Kali Linux, Cobalt Strike for OWASP top 10 Vulnerabilities like XSS, SQL Injection, CSRF, Privilege Escalation and all teh test-case of a web application security testing.
- Splunk licensing updates by adding new license under Admin and System and License Management.
- Ironport URL filtering for non bad URL content.
- Threat and virus scanning using Malware bytes from centralized console Enforcement of policies and procedures for users, admins, and management.
- Reverse engineering of malware using tools like malware, process hacker and so on Incident response tabletop exercise by documenting and alerting necessary personnel.
Confidential
Back-End Developer
Responsibilities:
- Functional and unit testing of teh developed code to provide quality product to end users.
- Follow teh SDLC rules and regulations to develop teh product/modules documenting teh key functionality.
- Code review, Code merging and deployment Management.
- Developed complete front & back end using JSPs & Servlets, Java Beans.
- Designed and developed TEMPeffective internal Web applications, relational database and stored procedures to analyze and monitor all activities related to Web-based sales.
- Developed application presentation layer, which is based on Spring MVC framework involving JSP, Servlets and HTML, CSS.
- Developed dis web application to store all system information in a central location.
- dis was developed using Spring MVC, jQuery, JSP, Servlet, Oracle 10g, HTML and CSS.
- Automated sales monitoring and credit/identity verification application processes, decreasing costs and improving quality.
- Created documents related to System Development Life Cycle (SDLC) deliverables.
- Assisted in business process design and documentation as needed for new technology solution implementations.
