Srsystems Engineer Resume
Austin, TX
SUMMARY:
- Over 8years of experience in financial and insurance industries, specialized in Web Application Security, Security Architecture &Design, Penetration Testing, Secure Coding, Application Security Controls and Validation, VulnerabilityAssessments, Regulatory Compliance and Secure Software Development Life Cycle (secureSDLC) of security scanning.
- Worked extensively with software development teams to review the source code, triage the security vulnerabilities generated by IBM AppScan, BurpSuite, HP WebInspect, and HP Fortify and eliminated false positives.
- Executed security assessments to ensure compliance to firm’s security standards (i.e., OWASP Top 10, SANS25). Specifically, security testing has been performed to identify XML External Entity (XXE), Cross - Site Scripting, ClickJacking, and SQL Injection related attacks within the code.
- Worked with Security Operations (SOC) and Incident Response (IR) teams to identify security incidents and follow through the process until the resolution. Monitor the security alerts originating from IDS/IPS and DLP.
- Worked with global security teams performing application and IT infrastructure security assessments in various environments including production and staging.
- Experience in working with agile projects where most of the testing types are being used including Regression testing, Functional testing, System testing, GUI testing, User Acceptance Testing (UAT) and Performance Testing.
- Experience in Installation, Configuration, Upgrade, Patches, and performance tuning on UNIX and system software & hardware in multiple environments.
- Knowledge of penetration testing for web applications.
- Extensive experience in preparing Test Plans, writing Test Cases, Test Execution and follow up efforts.
- Hands-on experience in developing threat models, security controls, threat analysis, creation of Vulnerabilitycontrol matrices and correspondingmitigation strategies.
- Working knowledge of Payment Card Industry (PCI), including OWASP Top 10 and SANS Top 25 software guidelines.
- Maintained Test Matrix, Requirement Traceability Matrix (RTM) to make sure that test plan was written for all the requirements and performed Gap Analysis.
- Good experience in performance tuning of SQL queries and identifying root cause of blocking queries with large number of records, improving the productivity of the system as a whole.
- Ability to handle multiple tasks and work independently as well as in a team.
- An efficient team player in challenging and creative environment with excellent capacity to adapt new technologies and skills.
- Experience in handling team, their day to day activities, status reporting and acting as a liaison between client/onshore team and offshore team.
- Determined, action-oriented and result-focused associate. Driven by new challenges and desire to be successful in all endeavours.
- Possess strong technical aptitude with strong analytical, work ethic, problem solving and communication skills.
TECHNICAL SKILLS:
DAST and SAST tools: IBM AppScan Enterprise, BurpSuite Pro, ZAP proxy, HP Fortify, HP WebInspect, Veracode, DBprotectPRO, AppDetective, Checkmarx, Nessus, Nexpose, Nmap, Wireshark, ImpervaSecureSphere, Scuba, tcpDump, Metasploit, Kali Linux
Encryption Tools: Safenet(Gemalto), Voltage, Vormetric, Orale TDE, MS SQL TDE, Venafi, Valut
Application Servers: Weblogic Server, Netscape Application Server, Windows Server 2003/2008 and Microsoft IIS
Languages: Java, COBOL,C/C++, C#, .NET
Scripting languages: Shell, Korn, Bash, Perl, Supr, Quiz, Quick
Version Control: GIT, TFS, SVN, Jenkins
Databases: Oracle, MS SQL Server
JIRA, BMC Remedy, Service: now
Web Servers: Apache Tomcat, Netscape Enterprise Server3.5.
HP: UNIX, RedHat LINUX, CentOS, Windows
Testing Tools: JMeter, TestNG, JUnit, QC/ALM, Bugzilla, Selenium
PROFESSIONAL EXPERIENCE:
Confidential, Austin, TX
SrSystems Engineer
Roles and Responsibilities:
- Generate, maintain, and destroy cryptographic keys of various lengths and types using HSMs such as Thales (Data Secure Module),SafeNet(Keysecure), and morevoltage (HSM).
- Safenet(Gemalto) Dual Authentication technical support. Deep knowledge on Gemalto products such as ProtectApp, ProtectFile, ProtectDB, Oracle TDE, MS SQL TDE.
- Worked extensively with software development teams to review the source code, triage the security vulnerabilities generated by IBM AppScan, BurpSuite, HP WebInspect, and HP Fortify and eliminated false positives.
- Executed security assessments to ensure compliance to firm’s security standards (i.e., OWASP Top 10, SANS25). Specifically, security testing has been performed to identify XML External Entity (XXE), Cross-Site Scripting, ClickJacking, and SQL Injection related attacks within the code.
- Worked with Security Operations (SOC) and Incident Response (IR) teams to identify security incidents and follow through the process until the resolution. Monitor the security alerts originating from IDS/IPS and DLP.
- Implemented Application Security program (DAST and SAST) at the enterprise level to identify, report and remediate security vulnerabilities from applications deployed in DEV, PRE-PROD and PROD environments.
- Performed the penetration testing of mobile (Android and iOS) applications, specifically, APK reverse engineering, traffic analysis and manipulation, dynamic runtime analysis.
- Reviewed source code (Java/J2EE/Spring/JavaScript) and developed security filters within IBM AppScan, HP Fortify for critical applications.
- Managed Information Security team in identifying, developing, implementing and maintaining information security processes across the organization to reduce risks, respond to incidents and limit exposure to liability to ensure reduced financial loss to the organization.
- Explored possibilities of new threats and remediation strategies with respect to emerging technologies and challenges related to IOT, Big Data/Hadoop and cloud computing
- Provided proof of concepts to the new demands of the customers, facilitating better communication and improved trust across various stake holders such as vendors, customers, organization management etc using open source tools such as Burp Suite, Checkmarx, HP WebInspect etc.
- Worked with lean and six sigma consultants at corporate level to implement better security procedures for increasing the responsiveness for the incidents and change management.
- Implemented file system security by applying hashing techniques for protecting data stored in files on the file servers.
- Administered cryptography, certificate management and implemented dual keys to address segregation of duties issue between DBAs and security admins.
- Worked with DevOps teams to automate security scanning into the build process.
Confidential, CA
Security Analyst
Roles and Responsibilities:
- Conducted security assessment to ensure compliance to firm’s security standards (i.e., OWASP Top 10). Specifically, manual testing has been performed to identify Cross-Site Scripting (XSS) and SQL Injection related attacks during the code review.
- Conducted monthly developer workshops to educate and train developers on secureSDLC, scan source code using IBM AppScan Source, triage and resolve the security vulnerabilities.
- Performed security assessments (asset inventory, scanning, manual code reviews, penetration tests) of applications using HP Fortify, IBM AppScan, and ZAProxy for compliance with policies, standards and best practices and worked with developers on vulnerability mitigation.
- Participated in the implementation of SafeNet product for encrypting customer credit card information using Public Key Infrastructure (PKI).
- Developed correlation rules for Security Incident and Event Management (SIEM) system. Reviewed the solution implemented for “log forwarding” from various network security devices to HP ArcSight central logging for alerting and security monitoring.
- Performed monitoring, research, assessment and engineering analysis (Security Operations Center) on Web Application Firewalls (WAF), Intrusion Detection and Prevention (IDS/IPS), Data Loss Prevention (DLP) tools as well as Anomaly Detection systems, Firewalls, Antivirus systems, proxy devices (HP ArcSight, Tripwire, Varonis, Palo Alto Networks, etc.) and responded to security incidents.
- Collaborated with global Network, Platform, Engineering, and Dev teams around architecture design and review.
- Reviewed security incidents of malicious code and performed root cause analysis to determine the risk and impact of the affected systems.
- Implemented application and database security program and provided subject matter expertise on code reviews, threat intelligence, third party/vendor security, compliance to security standards, and training.
- Experience with Identity and Access Management (IAM) and development of user roles and policies for user access management.
- Participated in developing project plans and road maps for enterprise wide security projects.
- Identified missing security patches in the infrastructure and provided recommendations for their resolution.
- Prepared technical documentation which included vulnerability reports, checklists, metrics, enrollment forms, DAST & SAST play books and user guides.
- Worked with Internet Engineering team in the design and configuration of BlueCoat Internet proxy. Implemented WebFilter database for URL content Filtering.
- Researched, initiated and drove the evaluation of tools, technologies, processes, policies, controls, standards to maintain and enhance the security of applications.
Confidential, CA
Security Engineer
Roles and Responsibilities:
- Enacted application security program and performed security assessments (threat modeling, code reviews, penetration tests) of applications/infrastructure for compliance with policies, standards and best practices and worked with teams concerned on vulnerability mitigation.
- Developed secure standard control libraries for use by development teams transversely across the organization using Java, .NET.
- Conducted security compliance audits covering Web Application Firewalls (WAF), IDS/IPS, Data Loss Prevention (DLP), O/S (Windows and Linux), Oracle/MS SQL database servers.
- Researched, initiated and drove the evaluation of tools/technologies/processes to maintain and enhance the security of infrastructure and applications.
- Designed implemented, documented, and managed Penetration Tests & Audits of Applications & Databases for Security & Compliance and explained security risks in common terms to assist system owners in prioritizing system enhancements.
- Prepared technical documentation which included release notes, change requests, vulnerability reports, checklists and user guides.
- Reviewed and evaluated 3rd party vendor security assessments (SSAE 16).
- Coached the junior team members on testing related activities.
- Experience in Documentation in MS Excel MS Word- Preparing Work Instructions, Test Plan, Test Cases. Had extensively worked on MS Excel.
- Planning of testing activities and delivering of test reports as per the software deadlines.
- Successfully handled customer's escalations.
Confidential
Software Developer
Roles and Responsibilities:
- Worked on converting various tax filing mechanisms such as XML, Paper & Electronic mode, making Confidential, agency Compliant. This avoided potential Fines and manual filings. The estimated cost saving to the customer is more than $1 Million.
- Developing or writing new complex COBOL programs using DB2 database. Analyzing and modifying existing complex code and generating appropriate test plans and user guides.
- Writing SQL queries using with COBOL/DB2 programming. Development of the new batch and online programs using z/OS, COBOL, JCL and CICS.
- Involved in writing the Test Estimates, Test Planning and Test Strategy planning of Test Preparation and Execution.
- Preparing QTP plans for testing the work requests after delivering from the developers.
- Performed Unit testing, Integration testing, Regression Testing and System testing of the software.
- Implemented Regression and Smoke tests execution as separate step of deployment process.
- Developed tool for easy code check-in and deployment by using COBOL Coding.
- Created documents related to System Development Life Cycle (SDLC) deliverables.
- Assisted in business process design and documentation as needed for new technology solution implementations
