Senior Application Security Consultant Resume
SUMMARY:
Seeking remote software penetration tester contract position with emphasis on black box Confidential
AREAS OF EXPERTISE:
- Mastery of software security principles, vulnerability detection, remediation, and mitigation
- Hands - on DAST and SAST expertise using various attack tools and penetration testing techniques
- Deep understanding of development methodologies throughout SSDLC
- Background in software engineering and project management
- Experience in delivering security awareness training
SKILLS & TECHNOLOGIES:
Infosec: Software penetration testing, code reviews, software Security principles, compensating controls, denial & deception, Defense-in-Depth, Mitigation techniques, OWASP and SANS testing guides, SSDLC
Tools: kali, Burp, Fortify, WebInspect, Appscan
OS: Windows, Linux, iOS, Android, Mac OS
Languages: .Net Framework, C#, T-SQL, Java, Visual Basic, C
Web: XML, HTML, CSS, JavaScript frameworks, VBScript, ASP.Net, Web Services
DBMS: SQL Server, Oracle, Sybase, DB2
Other: Exposure to Reverse Engineering, Disassembling, and Debugging
PROFESSIONAL EXPERIENCE:
Confidential
Senior Application Security consultant
Responsibilities:
- Participated in designing and implementing a comprehensive software security program
- Played a key role in developing enterprise-wide application security standards and procedures
- Conducted on-going research of testing tools and techniques
- Performed white box and black box software security assessments
- Tested commercial enterprise application such as WMS, MS exchange, JDA TMS, and IAM
- Trained developers in application security principles, remediation, and mitigation techniques
- Conducted hands-on DAST and SAST with adherence to OWASP and SANS standards
- Delivered detailed assessment reports, including exploitation POC
- Interacted with vendors, developers, and QA teams world-wide
Senior Application Security Assessment Engineer
Confidential
Responsibilities:
- Responsible for event detection, risk assessment, mitigation and resolution of cyber security threats
- Perform manual Web applications penetration testing
- Use automated scanner and analyze results to eliminate false positives
- Generate reports and communicate assessment results to business entities and management
- Conduct source code analysis of closed/OS source code
- Work with partners and third-party vendors globally
- Evaluate security products
Software Security analyst and Intellectual Property Auditor
Confidential
Responsibilities:
- Provided open source security analysis services and intellectual property audits with emphasis on mergers & acquisitions and corporate IT shops
- Utilized proprietary technology in conjunction with Open Source tools to systematically identify and document Application Security concerns and Intellectual Property (IP) violations
- Complied and communicated reports to non-technical stakeholders
- Led a small team as well as participated in several Confidential 500 IP/IT audits, including MySql, Sun Microsystems, Microsoft, and Yahoo
Project Manager/Team Lead
Confidential
Responsibilities:
- Developed quality assurance procedures at Confidential .
- Guided development team to meet business objectives
- Led a team to enhance the functionality of ATM systems at Confidential .
- Developed code components to communicate with Web Services.
- Designed and implemented a multi-threaded medical information archiving system for Confidential, Inc.
- Developed modules to transfer data and serialize it to DVD.
- Led development team and coordinated with marketing, training, and support.
Software Architect
Confidential
Responsibilities:
- Worked with domestic and near-shore development teams to define requirements.
- Developed standards and methodologies to meet project's goals.
- Performed risk assessments and software development audits.
Senior Developer
Confidential
Responsibilities:
- Designed and implemented Confidential fulfillment system for e-commerce site
- Designed and developed wireless messaging application at Confidential
- Designed and developed e-commerce website.
- Implemented high level security modules to deflect SpamBots, optimize search engine hits, and track usage patterns