Application Security Analyst Resume
San Antonio, TX
SUMMARY
- Ethical Hacker with over 6 years of experience in the creation and deployment of solutions protecting applications, networks, systems and information assets for diverse companies and organizations.
- Adept in application security, penetration testing & secure code reviews.
- Knowledge of authentication technologies, policy formation, and security attack pathologies; exceptional knowledge of data network protocols, related topologies and best practices.
- Experience in training as a part of knowledgeable security professionals.
- As a Security Consultant involved in enhancing the security stature of the project by initiatives like Threat Modelling, Security awareness sessions, Dormant & Never Logged IDs clean - up.
- Well versed with information security concepts through with specialization in Information security.
- Monitor issue in continuity of business. Ensure it is not impacted and tested regularly.
- Manage application vulnerability management program for applications developed in various environments (ie. Java, DotNet, etc.)
- Overall, Experience in different InfoSec domains like Application security and Compliance & Audit.
- Excellent team player, enthusiastic initiator, and ability to learn the fundamental concepts effectively and efficiently.
- Ability to work in large and small teams as well as independently.
- Excellent communication, analytical, troubleshooting, customer service and problem solving skills; excels in mission-critical environments requiring advanced decision-making.
TECHNICAL SKILLS
Tools: BurpSuite, DirBuster, OWASP ZAP Proxy, Nmap, Nessus, Kali Linux, Metasploit, HP Web Inspect, HP Fortify SCA, IBM Appscan
Programming languages: Java,.NET
Web technologies: HTML, CSS, XML, JavaScript
Operating system: Kali Linux, Linux, Windows
Database system: MySQL, Oracle, MSSQL
PROFESSIONAL EXPERIENCE
Confidential, San Antonio, TX
Application Security Analyst
Responsibilities:
- Performing Static Assessments, Dynamic assessments for Web applications and Mobile Assessments for Mobile Apps using HP FoD.
- Documentation of reports from various assessments and Risk documentation.
- Explain findings, their description, risk, mitigation strategies, and references during reviews.
- Worked and initiated the OWASP Dependency Check tool in the organization to identify the known vulnerabilities in project dependencies like libraries, Frameworks and other third party software/services.
- Conducting FFIEC Risk Assessments for internet(External) customer facing interfaces which need authentication.
- Conducting Threat Modeling to identify design centric flaws in an application’s architecture.
- Conducting APP Sec-EIS Security Questionnaire for Agile Projects
- Maintaining various types of Metrics and CSFs to measure the success in applications security.
- Experience on multiple tools to include Burp Suite, Tenable Nessus, SQLMap, DirBuster, ZAP Proxy, nmap, and OWASP Dependency Check.
- Worked on SAFE Code Security Stories to the unique needs of Agile architects, developers and testers to give an overview of OWASP Top 10 Vulnerabilities and sample methodologies that may be beneficial.
- Consult with application developers, administrators and management to ensure that proper security controls are identified, implemented, and tested.
- Ensure systems are in compliance with PCI DSS. Propose standards and methods to improve the security testing processes.
- Strong Hands-on Experience in Penetration Testing, Vulnerability Testing, Security Analysis.
- Experienced in performing user administration activities such as setting up user login Ids and assigning and resetting passwords, locking and unlocking users.
- Regularly performed research to identify potential vulnerabilities and threats to existing technologies, and provided timely, clear, technically accurate notification to management of the risk potential and options for remediation.
- Proficient in most application scan penetration tools using commercial and non-commercial applications and methodologies such as OWASP Top 10, HP WebInspect, HP Fortify SCA, OWASP Dependency check.
- Good Knowledge Experience on IBM AppScan.
Environment: JAVA, .NET, Android and iOS, MS SQL, Burp Suite, Dirbuster, HP Forify SCA, HP WebInspect, Nmap, Nessus, OWASP Dependency Check.
Confidential, Bowie, MD
Pen tester
Responsibilities:
- Provided security implementation for authorization, by controls like principle of lease privilege, Relinquishing privilege when not in use, Non Guessable tokens, forced browsing.
- Performed semi-automated and manual Web Application and Network Penetration Testing utilizing multiple tools to include Burp Suite, NetSparker, Tenable Nessus, SQLMap, AppDetective, Custom Scripts, metasploit, nmap, netcat, and other tools within the Kali Linux toolset.
- Maintaining and performing all Network configurations.
- Experienced in configuration and debugging applications like Web Server, FTP Server, Firewall Configuration, Mail Server and customization.
- Expertise in Maintaining all the Printer configurations and password protection to all the users’ in order to prevent them from unauthorized access.
- Strong Hands-on Experience in Penetration Testing, Vulnerability Testing, Security Analysis.
- Checking the site vulnerable to SQL injection.
- Identified attacks like SQLi, XSS, CSRF, RFI/LFI, logical issues.
- Experienced in performing user administration activities such as setting up user login Ids and assigning and resetting passwords, locking and unlocking users.
- Using various Firefox add-ons like Flag fox, Live HTTP Header, Tamper data to perform the pen test.
- Network scanning using tools like Nmap and Nessus.
- Diagnosed and troubleshot UNIX and Windows processing problems and applied solutions to increase client security.
- Regularly performed research to identify potential vulnerabilities and threats to existing technologies, and provided timely, clear, technically accurate notification to management of the risk potential and options for remediation.
- Proficient in most application scan penetration tools using commercial and non-commercial applications and methodologies such as OWASP Top 10, IBM Appscan.
Environment: JAVA, PHP, MS SQL, Apache Kali Linux, Burp Suite, Dirbuster, IBM Appscan Enterprise, Nmap, Nessus.
Confidential, Baltimore, MD
Application security Analyst
Responsibilities:
- Analyzed product requirements, outlined test plans and conducted tests.
- Supervised product quality.
- Conducted penetration testing and security tests.
- Formulated scripts to test systems.
- Managed validation security testing.
- Identified vulnerabilities of applications by using proxies like Burpsuite to validate the server side validations.
- OWASP Top 10 Issues identifications like SQLi, CSRF, XSS.
- The ability to balance risk mitigation with business needs.
- Executed different payloads to attack the system using XSS.
- Identified issues on sessions management, Input validations, output encoding, Logging, Exceptions, Cookie attributes, Encryption, Privilege escalations.
- Provided and validated the controls on logging like Authentication, profile modification, logging details, log retention, duration, log location, synchronizing time source, HTTP logging.
- Identified vulnerabilities, recommend corrective measures and ensure the adequacy of existing information security controls.
- Educated business unit managers, IT development team, and the user community about risks and security controls.
- Prepared detail practices and procedures on technical processes.
- Participated security research, analysis and design for all client computing systems and the network infrastructure.
- Developed, implemented, and documented formal security programs and policies.
Environment: ASP, MS SQL, MY-SQL, Apache, OWASP ZAP Proxy, Dirbuster, HP Fortify, Nmap, Nessus, SQL Map, Metasploit.
Confidential
Security Engineer
Responsibilities:
- Interacting with related technical groups for resolving the pending hardware problems Provided basic operations and engineering support for information security systems and services, including Windows and Linux servers, endpoint security, computer forensics, vulnerability/penetration assessments, and security information and event management (SIEM).
- In-depth understanding of the OSI Reference Model and its security implications.
- Capable of designing, configuring, and maintaining network security devices with adherence to industry, best practice, and PCI standards.
- Experienced in Firewall implementation, firewall management, network management and troubleshooting connectivity, routing, and configuration issues with routers, switches, firewalls.
- Perform operating system, network and application vulnerability assessments to identify security exposures in the environment.
- Checking for uploading java scripts & html tags.
- Checking for source code disclosure exploit.
- Worked in the area of LAN & WAN. Monitoring and optimizing the Network Performance.
- Created, modified & deleted users, roles and assigned appropriate authorizations for application access.
- Established security policies for systems, and designed and managed secure networks for clients.
- Validate Input validations, sessions management, client protocol controls, cryptography, Logging, Information leakage.
- Increased efficiency of risk assessment engagements.
- Researched new attack vectors and mitigating solutions.
- Provided guidance to regional security teams.
- Provided analysis/opinions to senior management/project teams on “hard-to-solve” problems.
- Used Burp Suite, Dirbuster, HP Fortify Nmap tools on daily basis to complete the assessments.
- Engaged with development teams and promote secure design/development early in the SDLC.
Environment: JAVA, Asp.net, MySQL, Apache Kali Linux, Burp Suite, Dirbuster, Microsoft Visual Studio, HP Fortify, Nmap.
