Information Security Consultant, Penetration Tester. Resume
2.00/5 (Submit Your Rating)
NJ
SUMMARY
- TEMPHas 5.7 years of IT experience wif expertise in teh area of Application security wif proficiency in security assessments and vulnerability management blended wif application development and business risk knowledge.
- Hands on professional experience in discovery of security vulnerabilities and threats through penetration testing, static secure code analysis & free open source software (FOSS) security audit. Have performed IT risk assessments and analyzed risks based on policies, control standards, procedures and guidelines.
- Deep knowledge on OWASP’s Top 10, SANS top 25 issues, testing methodologies and remediation guidelines.
- Comprehensive understanding on Enterprise application architecture, SOA and OSI model.
- Good awareness of IT security standards such as NIST, FFIEC, ISO 27002, PCI - DSS, COBIT.
- Hands on Penetration testing experience on variety of web applications developed using J2EE, .Net, PHP and other leading programming languages
- Rich working experience on leading security assessment tools such as Burp Suite, Fortify, CheckMarx,Web-Inspect, AppScan, Acunetix, Nessus.
- Good understanding on Mobile App security assessment.
- Have experience working wif Waterfall and Agile SDLC model development teams.
- Adequate Knowledge on Identity and Access management systems.
- Good understanding on Network security and threat modelling concepts.
- Active participation in OWASP Chapters and security user groups.Vulnerability Management
- Experience in managing and tracking vulnerabilities found during assessments across teh organization through vulnerability management framework.
- Developed security risk metrics to measure security weakness and help in prioritizing vulnerabilities remediation based on MITRE’s CWSS standards.
- Experience in vulnerability research using NVD, OSVBD and other leading vulnerability databases.
- Provided technical support and assistance in teh event of security incidents.
- Liaised between development and security team for seamless security assessments and in remediation of security defects.
- Have showcased good communication, co-ordination and problem solving skills.IT Risk Assessment
- Experience in identifying IT risks through risk frameworks and was instrumental in setting up process, procedures to remediate risks.
- Management of IT Risk through eGRC platform such as RSA Archer, Brinqa.
TECHNICAL SKILLS
Programming Languages: Java, PHP, C
Security Tools: HP Fortify Suite, HP Web-Inspect, IBM AppScan, Acunetix WVS, CheckMarx, Nessus, Burp-Suite, WireShark, Paras proxy, SOAP-UI, OWASP tools.
Dev Tools: Eclipse IDE, Junit, Find-Bugs, PMD
J2EE Technologies: Struts 2.0, Spring, JSP, SOAP Web-Services
ORM Framework: Hibernate, JDBC.
Database Servers: Oracle 10g, MS-SQL, MySQL.
Servers: Apache Tomcat, JBoss
Scripts: JavaScript, VBScript
Documentation: MS-Office, MS-Visio.
OS: Windows, Linux
PROFESSIONAL EXPERIENCE
Confidential, NJ
Information Security Consultant, Penetration Tester.
Responsibilities:
- To perform information gathering on teh application through review of business functionality, architecture, criticality, security controls, key facts through meetings and discussions wif teh Stakeholders.
- Conduct periodic penetration testing, static secure code analysis, and open source software security audit on DTCC business applications along their SDLC.
- Prepare test plan, test strategy & execution of security test cases.
- To perform security controls and requirements mapping to teh implemented security solution during teh security risk assessment.
- Identify security vulnerabilities on teh target systems through automation and manual penetration testing,
- To document teh issues identified and report them to teh application stakeholders.
- To provide consultation and guidelines for teh vulnerability remediation to teh developers.
- Validation of teh security fixes and to ensure teh adequacy of teh implemented security solution.
- To lead and co-ordinate project activities wifin teh team to deliver teh project assignments on schedule.
- To provide support and remediation guidance in teh event of security incidents.
- Maintenance of vulnerability management dashboard for managing teh security risks and metrics of DTCC applications and to analyze their trend.
- Periodical reporting of teh security posture of teh applications wif their statistics, KPI and trends to teh Information Security top management, Project managers and Product leads.
- Installation, maintenance and configuration of security tools like Fortify software security center, Web-Inspect, AppScan, Acunetix and other tools used by teh security team.
- To update teh security knowledge base and testing methodologies based on latest and zero-day vulnerabilities in teh IT world.
- To provide seminars on best security practices to teh development teams.
- Texas Instruments (TI), India Jan 2011 - Dec 2011
Java Developer
Confidential
Responsibilities:
- To work on sequence and use case diagrams during design phase.
- To develop J2EE business modules for web-components according to spring - Hibernate based MVC pattern.
- Develop dynamic web pages for product portfolios according to design requirements.
- To perform Junit testing.
- To perform version management, build and deployment of code to teh server.
- Fix bugs during development and QA phases.
- Take ownership for delivering important web modules on project schedule.
