We provide IT Staff Augmentation Services!

Senior Project Lead / Penetration Tester Resume

5.00/5 (Submit Your Rating)

SUMMARY:

  • Possesses over eight years of wide - ranging work experience with large financial institutions such as Confidential, Confidential, and Confidential, which helped provide stronger understanding of bank financial systems.
  • Extensive experience evaluating software: creating test plan, test cases, manual and automation testing, risk assessment, developing reports to senior managers.

PROFESSIONAL EXPERIENCE:

Confidential

Senior Project Lead / Penetration tester

Responsibilities:

  • Lead and managed an onshore manual and offshore automated testing teams
  • Penetration testing - manual web security testing using OWASP methodology and tools such as QC, QTP, Paros, Web Scarab, and Burp Suite and functional testing
  • Collaborated with software development to find vulnerabilities in each application version
  • Manual/automated testing and configuration

Confidential

Quality Assurance

Responsibilities:

  • Key liaison for multiple interface applications, 3rd party vendors, IT executives and Project Managers to solve user needs, concerns, and to ensure accurate software use
  • Lead SIT and UAT functional testing for 200 plus software applications, managed project milestones, teams, and work streams
  • Developed and delivered daily status reports to senior stakeholders

Confidential

Security Test Leader and Security assessment.

Responsibilities:

  • Identified need to create security assessment project for existing internal projects
  • Developed team, test plan, risk management through the complete SDLC, and created security test cases
  • Collaborated with programmers in development of IT security principles
  • Applied OWASP for testing vulnerabilities, developed the defect life cycle, discussed and resolved concerns raised by programmers, and produced ad hoc reports for senior management
  • Installed ArcSight ESM Suite, ESM Manager over Linux, ArcSight Console into Windows, and smart connectors for several devices. Managed channels, manipulated lists, created reports and use case
  • Supported functional testing using QTP, QC, LR, and testing AS400 with DB2 Database.
  • Tested application availability using automated tools

Confidential

Quality Assurance

Responsibilities:

  • Functional testing of data migration between AS400 DB2 to Oracle
  • Generated reports, test cases, deliverables to client; worked with Toad and Quality Center
  • Linux programming and cluster development using C/C++

Confidential

Test Leader - Automation Team

Responsibilities:

  • Managed and developed an automation testing team
  • Developed formal testing procedures using SAP, TAO, QTP, and QC.
  • Created framework for vulnerability testing
  • Arranged meeting with stakeholders, produced key daily reports to stakeholders, daily automation testing, KPIs, and managed issues/risks/dependencies

Confidential

IT Security Auditor and Cyber Security SME

Responsibilities:

  • Audited compliance with ISO 27001 and privacy law
  • Analyzed network mapping and vulnerabilities using Wireshark, Nmap, and Nessus. Established mappings of entire system, analyzed code and gateways, ports, and servers for adherence to regulatory standards
  • Provided comprehensive audit report on overall system integrity
  • Suggested specific technical recommendations to remediate problem areas and distributed findings to senior stakeholders and system owners

Confidential

Cyber Security Tester

Responsibilities:

  • Responsible for deliverables on three separate projects: Automation Data Warehouse Testing (“DWH”), Performance Testing, and Cyber Security Testing
  • Developed test strategy for DWH and executed specific testing segments, developed full performance testing life cycle as lead performance tester, and conducted IT system risk assessment
  • Penetration testing using OWASP methodology manually and automated using PMD, Yasca, Paros, Web Scarab, Burp Suite Pro, and App Spider
  • Generated reports for stakeholders, conducted full vulnerability assessment, led defect triage calls with programmers, prepared test data, scheduled automated test execution, and tested on ORACLE, QC, QTP, TAO, LR, Wireshark, NMAP
  • Reviewed process and security compliance for multiple GE Corporate projects
  • Perl Programmer

We'd love your feedback!