We provide IT Staff Augmentation Services!

Penetration Tester Resume

3.00/5 (Submit Your Rating)

Dallas, TX

SUMMARY

  • Security Analyst with 8+ yrs of experience in IT Security, Infrastructure support
  • Over four years of experience in large scale environments including hands on data and/or information security functions, specifically in application security, SEIM products, perimeter, malware, authentication and OS (Windows/Linux/OS X) security
  • Strong in providing major solutions in the areas of IT Security, Risk Management, Business Continuity/Disaster Recovery, and Incident Response
  • Experience in using broad spectrum of web application security testing tools like Acunetix, Metasploit, Burp Suite, Sqlmap, OWASP ZAP Proxy and HP Fortify etc.,
  • Well versed with OWASP top 10 and SANS 25 standards
  • Worked on QRadarVulnerability manager and Threat Manager (QVM and QTM)
  • Broad knowledge of hardware, software, and networking technologies to provide a powerful combination of analysis, implementation, and support
  • Proficient in analyzing different security threats to organizations by identifying the indicators that a security incident is underway, composing and creating security policies and procedures to be followed when an incident is detected, and investigation methods use to collect evidence for prevention and prosecution.
  • Experience as a privacy/security analyst, with applicable knowledge of regulatory compliance procedures related to SOX and PCI
  • Perform Vulnerability assessment and policy compliance and PCI compliance using Qualys and IBM App scan

TECHNICAL SKILLS

Operating Systems: Microsoft: Windows XP/Vista/7/Server 2003/Server 2008; Linux: CentOS, Red Hat, Fedora, Ubuntu Server/Desktop, Kali Linux; Backtrack 4 & 5; UNIX: Mac OSX Lion, FreeBSD, Mainframe Exp.

Web Technologies: HTML, JavaScript, Microsoft.Net, Java

OWASP/SANS Vulnerability: XSS, SQL Injection, CSRF, Security Misconfiguration, Sensitive Data Exposure, Insecure Direct Object Reference

IDS/IPS: McAfee Intrushield / NSM, McAfee e - Policy Orchestrator (ePO), Sourcefire, Motorola AirDefense WIDS, ISS SiteProtector

SIEMs: ArcSight ESM, IBM QRadar, RSA Envision, Splunk

Security Tools: App Scan, Wireshark, Snort, Tcpdump, Tcprelay, Nmap, Netcat, Iptables, Malwarebytes, Nessus, SQLmap, Acutenix, Burp Suite, Hydra, Aircrack-ng etc.

Protocols: Ethernet, LAN/WAN/MAN, TCP/IP, DNS, DHCP, FTP, TELNET, SMTP, POP3, SSH, UDP, ICMP, IPsec, HTTP/HTTPS, Network Topologies, Firewalls, VPNs, IDS, port scanning, and implementing Incident Response Procedures

PROFESSIONAL EXPERIENCE

Confidential, Dallas, TX

Penetration Tester

Responsibilities:

  • Responsible for penetration tests leveraging Kali Linux (Metasploit, Nessus, Nmap, Burp Suite, wireshark, etc.)
  • Create security testing plans and test cases
  • Oversee and execute security testing activities, ensuring testing goals/objectives are met
  • Researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; identifying integration issues
  • Ensure compliance with policies, procedures, and regulations (i.e. PCI DSS)
  • Conducted white/gray box penetration testing on the financial systems using Kali Linux, Cobalt Strike for OWASP top 10 Vulnerabilities like XSS, SQL Injection, CSRF, Privilege Escalation and all the test-case of a web application security testing
  • Used LDAP injections techniques of exploiting Web applications that use client supplied data
  • Used Websense to protect the company’s network from, malware and data theft, as well as prevent users from viewing inappropriate content.
  • Port scanned servers using NMAP and closed all unnecessary ports to reduce the attack surface.
  • Implemented Tenable Nessus, Tenable SecurityCenter, and customized audit compliance dashboards of system configurations and content for the Vulnerability / Configuration Compliance Management and Monitoring Programs.
  • Brute force assessment to insure strong passwords and encryption.

Confidential, Dallas, TX

Security Analyst

Responsibilities:

  • Evaluate and implement advanced security solutions for phishing protection, privileged account management, and security incident and event management (SIEM)
  • Troubleshoot and researched security incidents using SIEM applications, IBM QRadar Security Intelligence Platform.
  • Event analysis and correlation using multiple log sources including Windows / Linux / Cisco ASA systems and SIEM solutions
  • Utilized tools such as NMAP, Nessus, Qualys, and Nexpose to accomplish network reconnaissance and surveillance in preparation for exploitation.
  • Investigating logs and payloads for server crashes/core dumps, DDoS attacks, SQL/XSS, SPAM, etc
  • Selected and employed network exploitation capabilities, via both open source (Metasploit, Burp Suite, etc.)
  • Define, develop, and communicate processes for implementing security policies
  • Identify gaps & reports from Guardium for SOX and PCI audits
  • Create and support security awareness programs to inform and educate employees

Confidential

Security Analyst

Responsibilities:

  • Review and analyze alerts and logs from Firewalls (FW), Intrusion Detection Systems (IDS), Antivirus (AV), and other security threat data sources.
  • Served as the primary responder for managed security incidents pertaining to client firewalls and all network infrastructure component
  • Maintain SIEM/log analysis solution, including data collection, aggregations, and regular exception reporting.
  • Analyze and or escalate security threats found internally or via Managed Security Service Providers.
  • Evaluate and recommend solutions for data loss prevention (DLP), Data Masking/Hidding/Scrubbing
  • Reporting, Metrics, Deliverables - Provided concise and professional deliverables for architecting and implementing Enterprise-level logging and security event information management solution.
  • Design alerting, communications, work flows and training of other IT users.

Confidential

Network Administrator

Responsibilities:

  • LAN/WAN design, implementation and optimization using Cisco routers and switches
  • Installing, Configuring of Networking Equipment’s: Routers and Switches
  • Recommend and scheduling repairs to the LAN/WAN.
  • Managing VLANs and inter VLAN routing.
  • Configured VPN, ACL, and NAT in the Cisco ASA 5540 firewall to allow only authorized users to access the servers of the internal network
  • Used Layer 3 protocols like EIGRP and BGP to configure Routers in the network
  • Configure and Implement Remote Access Solution: IPSEC VPN, Remote Access
  • Upgrade, install and troubleshooting networks, networking hardware devices and software.
  • Develop and documenting system standards for computer and network devices.
  • Performing patch and malware installations on critical systems of company.

Confidential

IT Infrastructure Specialist

Responsibilities:

  • Providing Service support for new desktop Pc, Laptop, Software and Printer.
  • Install, troubleshoot in Desktop operating systems Windows 2000, XP, and Win7.
  • Install, upgrade, troubleshoot MS-Office 2000,xp, 2003, 2007
  • Install, upgrade authorized Software & Hardware in Windows Platform.
  • Install, upgrade, update Antivirus Symantec, MacAfee, E-scan.
  • Responsible for important data backup weekly and monthly schedule.
  • Configuring & Handling Outlook & Outlook Express and Data Backups.
  • Handling Norton Ghost for deploying OS to many Pc at One Time.
  • Installations and Troubleshooting Dot matrix, LaserJet printers, scanner.
  • Implementing & troubleshooting in network access LAN, WAN and Wi-Fi.
  • Providing Backend support for CCTV Camera installation and configuring.
  • Maintain a stable IT infrastructure to support all business operations over the world (around 300 servers included native and VM)
  • Work with application team to support all company’s applications
  • Provide tier 2 remote support for all network & application related issues across the board
  • Work and co-ordinate with IT vendors
  • 1st level support for Confidential and Apollo Health Street
  • Problem management process within Service Desk area
  • Troubleshooting problems reported by users
  • Working to tight deadlines and contracted Service Level Agreements
  • On- site and remote customer support
  • Active Directory management
  • MS SQL database management
  • Proactively monitoring and maintaining internal infrastructure and systems
  • Liaising with third party suppliers/product technical support
  • Applications support on servers
  • 1st line server and network equipment support
  • Writing and keeping technical documentation up to date

We'd love your feedback!