We provide IT Staff Augmentation Services!

Information Security Consultant, Penetration Tester. Resume

2.00/5 (Submit Your Rating)

NJ

SUMMARY

  • TEMPHas 5.7 years of IT experience wif expertise in teh area of Application security wif proficiency in security assessments and vulnerability management blended wif application development and business risk knowledge.
  • Hands on professional experience in discovery of security vulnerabilities and threats through penetration testing, static secure code analysis & free open source software (FOSS) security audit. Have performed IT risk assessments and analyzed risks based on policies, control standards, procedures and guidelines.
  • Deep knowledge on OWASP’s Top 10, SANS top 25 issues, testing methodologies and remediation guidelines.
  • Comprehensive understanding on Enterprise application architecture, SOA and OSI model.
  • Good awareness of IT security standards such as NIST, FFIEC, ISO 27002, PCI - DSS, COBIT.
  • Hands on Penetration testing experience on variety of web applications developed using J2EE, .Net, PHP and other leading programming languages
  • Rich working experience on leading security assessment tools such as Burp Suite, Fortify, CheckMarx,Web-Inspect, AppScan, Acunetix, Nessus.
  • Good understanding on Mobile App security assessment.
  • Have experience working wif Waterfall and Agile SDLC model development teams.
  • Adequate Knowledge on Identity and Access management systems.
  • Good understanding on Network security and threat modelling concepts.
  • Active participation in OWASP Chapters and security user groups.Vulnerability Management
  • Experience in managing and tracking vulnerabilities found during assessments across teh organization through vulnerability management framework.
  • Developed security risk metrics to measure security weakness and help in prioritizing vulnerabilities remediation based on MITRE’s CWSS standards.
  • Experience in vulnerability research using NVD, OSVBD and other leading vulnerability databases.
  • Provided technical support and assistance in teh event of security incidents.
  • Liaised between development and security team for seamless security assessments and in remediation of security defects.
  • Have showcased good communication, co-ordination and problem solving skills.IT Risk Assessment
  • Experience in identifying IT risks through risk frameworks and was instrumental in setting up process, procedures to remediate risks.
  • Management of IT Risk through eGRC platform such as RSA Archer, Brinqa.

TECHNICAL SKILLS

Programming Languages: Java, PHP, C

Security Tools: HP Fortify Suite, HP Web-Inspect, IBM AppScan, Acunetix WVS, CheckMarx, Nessus, Burp-Suite, WireShark, Paras proxy, SOAP-UI, OWASP tools.

Dev Tools: Eclipse IDE, Junit, Find-Bugs, PMD

J2EE Technologies: Struts 2.0, Spring, JSP, SOAP Web-Services

ORM Framework: Hibernate, JDBC.

Database Servers: Oracle 10g, MS-SQL, MySQL.

Servers: Apache Tomcat, JBoss

Scripts: JavaScript, VBScript

Documentation: MS-Office, MS-Visio.

OS: Windows, Linux

PROFESSIONAL EXPERIENCE

Confidential, NJ

Information Security Consultant, Penetration Tester.

Responsibilities:

  • To perform information gathering on teh application through review of business functionality, architecture, criticality, security controls, key facts through meetings and discussions wif teh Stakeholders.
  • Conduct periodic penetration testing, static secure code analysis, and open source software security audit on DTCC business applications along their SDLC.
  • Prepare test plan, test strategy & execution of security test cases.
  • To perform security controls and requirements mapping to teh implemented security solution during teh security risk assessment.
  • Identify security vulnerabilities on teh target systems through automation and manual penetration testing,
  • To document teh issues identified and report them to teh application stakeholders.
  • To provide consultation and guidelines for teh vulnerability remediation to teh developers.
  • Validation of teh security fixes and to ensure teh adequacy of teh implemented security solution.
  • To lead and co-ordinate project activities wifin teh team to deliver teh project assignments on schedule.
  • To provide support and remediation guidance in teh event of security incidents.
  • Maintenance of vulnerability management dashboard for managing teh security risks and metrics of DTCC applications and to analyze their trend.
  • Periodical reporting of teh security posture of teh applications wif their statistics, KPI and trends to teh Information Security top management, Project managers and Product leads.
  • Installation, maintenance and configuration of security tools like Fortify software security center, Web-Inspect, AppScan, Acunetix and other tools used by teh security team.
  • To update teh security knowledge base and testing methodologies based on latest and zero-day vulnerabilities in teh IT world.
  • To provide seminars on best security practices to teh development teams.
  • Texas Instruments (TI), India Jan 2011 - Dec 2011

Java Developer

Confidential

Responsibilities:

  • To work on sequence and use case diagrams during design phase.
  • To develop J2EE business modules for web-components according to spring - Hibernate based MVC pattern.
  • Develop dynamic web pages for product portfolios according to design requirements.
  • To perform Junit testing.
  • To perform version management, build and deployment of code to teh server.
  • Fix bugs during development and QA phases.
  • Take ownership for delivering important web modules on project schedule.

We'd love your feedback!