We provide IT Staff Augmentation Services!

Senior Application Security Engineer Resume

2.00/5 (Submit Your Rating)

San Antonio, TX

PROFESSIONAL SUMMARY:

  • An (ISC)2 certified Application Security Engineer with around 10 years of experience in IT industry. Expertise in Application Security / Mobile apps security testing and .Net development.
  • 7+ years of experience in Web application and mobile app security assessments.
  • Around 3 years of experience in .net development.
  • Proficiency in testing OWASP TOP 10 and SANS TOP 25 guidelines for enterprise applications using both automated tools and Manual assessments.
  • Proficient in Security Assessment Activities (Secure Design Review, Source Code Review & Security Testing).
  • Performed security requirements and technical design reviews of portal applications, ensuring strong security measures and standards meeting business requirements.
  • Strong domain knowledge in Application Security, Threat Modeling, Processes and Standards.
  • Providing Security Consulting to various teams (design, development) on measures to be incorporated in the requirements, design, development phases and the best practices to be followed for a secure application development.
  • Performing the vulnerability assessment and penetration testing on their internet facing, mobile applications, SOAP and REST services.

TECHNICAL SKILLS:

AppScan, WebInspect, Accunetix (VA and Pentest tools for web applications), Wire shark (Network sniffing tool), Burp Suite, Webscarab, Paros, Havij, Zed attack proxy, SoapUI, SoapUI Pro, Android SDK, fiddler, Nessus, SqlProfiler and HP Fortify

WORK HISTORY:

Senior Application Security Engineer

Confidential, San Antonio, TX

Responsibilities:

  • Communicating with the client teams to understand the application security requirements, application flow, functionality, architecture and the technology on which the application is built.
  • Meeting the application development teams to understand their application architecture and understand their application data classification.
  • Performing the vulnerability assessment and penetration tests on their internet facing and mobile applications.
  • Reporting the assessment findings to the respective teams and suggesting and helping them to close the gaps as well as to improve the application level security.
  • Performing the checks on critical data as per the data classification.
  • Testing for business logic flaws.
  • CR (Change Request) Analysis and Estimation.
  • Testing the SSO implementation with the vendors for security vulnerabilities.
  • Following the process life cycle using IBM RTC.
  • Using tools such as IBM AppScan, Burp Suite, HP Fortify and iFunbox.
  • Updating the status to client daily.

Application Security Engineer

Confidential, Columbus, IN

Responsibilities:

  • Understanding the application functionality/architecture, data classification and it’s security requirements.
  • Communicating with the offshore team to make them understand the client requirements and helping them in application security assessments.
  • Performing the vulnerability assessment and penetration tests on their internet and intranet - facing web applications.
  • Performing Data sensitivity test and analyze the Risk.
  • Reporting the assessment findings to the respective teams and suggesting them to close the gaps as well as to improve the application level security.
  • Using tools such as IBM AppScan and Burp Suite.
  • Updating the status to client on a weekly basis.
  • Performing the checks on critical data as per the data classification.

Application Security Engineer

Confidential

Responsibilities:

  • Assessed 150+ critical applications for vulnerabilities as an IT Application Security Officer.
  • Communicated with the application teams to understand the application flow, functionality, architecture and the technology on which the application was built.
  • Performed vulnerability assessments and penetration tests on the internet-facing and most critical applications.
  • Studied various tools to assess the web/web services and android applications.
  • Reported the assessment findings to the respective teams and suggesting them to close the gaps as well as to improve the application level security.
  • Updated the Emirates Group security checklist standard.
  • Reported the status of the application assessment to senior management by preparing trend analysis.
  • Participated in IT security road shows for security awareness to the group employees.
  • Reviewed the architectural/code changes in application level.
  • Followed up with the application teams on the reported vulnerabilities to make sure that they fix the issues.
  • Change management reviews, security exceptions and approvals.
  • Performing the checks on critical data as per the data classification.

Systems Engineer

Confidential

Responsibilities:

  • Performed web application vulnerability assessments with AppScan and Intercepting tools.
  • Analyzed the VA reports and coordinated with application teams on vulnerabilities.
  • Performed vulnerability Assessments on 60+ Critical Applications.
  • Analyzed the technology on which the application is built, studying the flow of the application, trying to gather the information regarding the web server, database server etc.
  • Followed the OWASP frame work for the list of top 10 security risks in a web application.
  • Conducted the Vulnerability Assessments using both automated and manual approaches on a periodic basis.
  • Analyzed the results and prepared detailed reports with executive summaries, risk ratings, steps to exploit, and recommendations.
  • Worked closely with application teams to resolve the issues found in the Vulnerability Assessments.
  • Conducted periodic applications Vulnerability assessments during audits.
  • Performing the checks on critical data as per the data classification.
  • Documented and updated the Application Security Checklist.
  • Developed two web applications to upload and view the Vulnerability reports generated from Nessus and GFI Languard and to change the status of the Vulnerabilities, User Management, and Graph Analysis.
  • Developed a web application using Dot net and SQL server 2005 for employee and exit process.

We'd love your feedback!