We provide IT Staff Augmentation Services!

Security Engineer Resume

5.00/5 (Submit Your Rating)

SUMMARY

  • A highly motivated Information security professional with over 3 years of experience in Application Security and Vulnerability Management.
  • Proficient in App Sec Vulnerabilities including OWASP Top 10
  • Good knowledge of DevSecOps and integrating security controls in the CI/CD pipeline environment.
  • 3+ years’ experience in application development within a secure SDLC
  • An efficient team player in a challenging and creative environment with excellent capacity to adapt new technologies and skills.
  • Knowledge of security assessment tools such as Burp Suite, or Wireshark
  • Hands on experiences with system security penetration testing and vulnerability assessment methods such as DAST, SAST, Open Source Analysis, IAST
  • Comprehensive understanding of the HTTP protocol, Secure Software Development Lifecycle (SSDLC)
  • Hands - on application security assessment experience using commercial tools like Veracode, Burp Suite. good knowledge in Java/J2ee, vulnerability management process, and methodology

TECHNICAL SKILLS

Security tools: Burp Suite, Veracode. Kali, WiresharkOther tools Selenium with Eclipse, Jira, SQL, Jenkins, Virtual Box

PROFESSIONAL EXPERIENCE

Confidential

Security Engineer

Responsibilities:

  • Responsible for managing all aspects of the Vulnerability Risk Management Program including vulnerability identification, analysis, remediation coordination and reporting
  • System security penetration testing and vulnerability assessment methods such as DAST, SAST, Open Source Analysis, IAST
  • Evaluate operational effects of security system attacks.
  • Assisting the development teams in mitigating the vulnerabilities before it gets to production.
  • Performed daily security maintenance and activities for enterprise systems.
  • Inform product teams of discovered vulnerabilities to ensure remediation
  • Contributor in developing security awareness materials, security presentations, and information security training sessions
  • Ensuring security issues are successfully dealt with and mitigated.
  • Incorporate security into application and infrastructure design patterns and the building of security controls into the CI/CD process.

Confidential

Security Engineer

Responsibilities:

  • Conducted manual security assessments on web applications.
  • Identified critical vulnerabilities and developed proof-of-concept exploits that allowed the business to understand the risk, resulting in speedy remediation
  • Prepare and document test plans for security evaluations.
  • Worked with DevOps, Development and QA to ensure code, platform, and application are secure against real-world threat actors before being promoted into production
  • Generated technical reports containing security based findings.

We'd love your feedback!