Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Timeline
Generic

Abhinav Mishra

Cyber Security
Ballia

Summary

Cyber Security professional with 3.5 Years of experience in Information Security. Have hands-on experience in application security, vulnerability assessments and penetration testing of Web Application, Mobile Application, Thick Client and Infrastructure.

Overview

3
3
years of professional experience
8
8
years of post-secondary education
1
1
Certification

Work History

Consultant

KPMG India
Bangalore
04.2023 - Current


● Performed Penetration testing on various Web Application, API, Network, Android and Thick client Application.

● Led a security assessment project for one of the leading IT management tools and was able to find high level vulnerabilities.

● Performed Penetration testing for world's leading investment banking firm application's and uncovered many critical and high vulnerabilities related privilege, injection, and business logic.

● Performed Penetration testing for Airport application's and was able to found vulnerabilities related to Injection, authentication and account take over.

● Performed Penetration testing for Middle East based EdTech organization applications and found many high and critical vulnerabilities related injection and business logic.

● Performed Penetration testing for India's leading IT company and uncovered may high vulnerabilities related to business logic, sessions and injection.

● Performed source code review using automated tools to find the flaws overlooked in the initial phases of development.

● Hands - on experience in reviewing and defining requirements for information security solutions and mitigation techniques. Performed vulnerability assessment, Patch management and penetration testing using various tools like Metasploit, Burp Suite, DirBuster, OWASP ZAP proxy, NMAP, Nessus, SQL Map, Nets sparker, Kali Linux, Wire shark, fiddler.

● Conducted manual and automated security testing for web, mobile, api, thick client and network applications based on OWASP and CWE/SANS standards.

● Working Knowledge in Windows and Linux (Kali Linux) operating system configuration and utilities.

● Performed both internal and external Network penetration testing based on the client's specifications.

● Done analysis of the results from penetration test to identify the risks that need to be taken care of immediately.

Associate Consultant

KPMG India
Bangalore
04.2022 - 03.2023

● Performed Penetration testing on various Web Application, API, Network, Android and Thick client Application.

● Led a security assessment project for one of the leading IT management tools and was able to find high level vulnerabilities.

● Performed Penetration testing for world's leading investment banking firm application's and uncovered many critical and high vulnerabilities related privilege, injection, and business logic.

● Performed Penetration testing for Airport application's and was able to found vulnerabilities related to Injection, authentication and account take over.

● Performed Penetration testing for Middle East based EdTech organization applications and found many high and critical vulnerabilities related injection and business logic.

● Performed Penetration testing for India's leading IT company and uncovered may high vulnerabilities related to business logic, sessions and injection.

● Performed source code review using automated tools to find the flaws overlooked in the initial phases of development.

● Hands - on experience in reviewing and defining requirements for information security solutions and mitigation techniques. Performed vulnerability assessment, Patch management and penetration testing using various tools like Metasploit, Burp Suite, DirBuster, OWASP ZAP proxy, NMAP, Nessus, SQL Map, Nets sparker, Kali Linux, Wire shark, fiddler.

● Conducted manual and automated security testing for web, mobile, api, thick client and network applications based on OWASP and CWE/SANS standards.

● Working Knowledge in Windows and Linux (Kali Linux) operating system configuration and utilities.

● Performed both internal and external Network penetration testing based on the client's specifications.

● Done analysis of the results from penetration test to identify the risks that need to be taken care of immediately.

Analyst

KPMG India
Bangalore
04.2021 - 03.2022

● Performed Penetration testing on various Web Application, API, Network, Android and Thick client Application

● Lead a Security assessment project for one of the leading IT management tool product and was able to find high vulnerabilities.

● Performed Penetration testing for world's leading investment banking firm application's and uncovered many critical and high vulnerabilities related privilege, injection, and business logic

● Performed Penetration testing for Airport application's and was able to found vulnerabilities related to Injection, authentication and account take over

● Performed Penetration testing for Middle East based EdTech organization applications and found many high and critical vulnerabilities related injection and business logic

● Performed Penetration testing for India's leading IT company and uncovered may high vulnerabilities related to business logic, sessions and injection

● Performed source code review using automated tools to find the flaws overlooked in the initial phases of development

● Hands - on experience in reviewing and defining requirements for information security solutions and mitigation techniques

● Performed vulnerability assessment, Patch management and penetration testing using various tools like Metasploit, Burp

● Suite, DirBuster, OWASP ZAP proxy, NMAP, Nessus, SQL Map, Nets sparker, Kali Linux, Wire shark, fiddler

● Conducted manual and automated security testing for web, mobile, api, thick client and network applications based on

● OWASP and CWE/SANS standards

● Working Knowledge in Windows and Linux (Kali Linux) operating system configuration and utilities

● Performed both internal and external Network penetration testing based on the client's specifications

● Done analysis of the results from penetration test to identify the risks that need to be taken care of immediately

● Generated and presented reports on Security Vulnerabilities to external customers.

Trainee Security Analays

BreachLock Inc
Noida
02.2020 - 04.2021


● Performed manual Penetration Testing on critical client Web Application, Android Application , Thick Client application, API and Network , found many high vulnerabilities related to privilege escalation, session management authentication, authorization, injection and business logic.

● Uncovered high vulnerabilities at the infrastructure level for internet facing websites.

● Update with the new hacking and latest vulnerabilities to ensure no such loopholes are present in the existing system by performing Vulnerability assessment and pen testing for our clients

● Performed source code review using automated tools to find the flaws overlooked in the initial phases of development

● Experience in using Kali Linux to Penetration testing

● Used Network scanning using tools like Acunetix and Nessus

● Providing details of the issues identified and the remediation plan to the stake holders

● Communicating and coordinating day-to- day project activities within the project team and assure that priorities are developed and known

● Create Vulnerability Assessment report detailing exposures that were identified, rate the severity of the system, and suggestions to mitigate any exposures and testing known vulnerabilities.

Education

Bachelor In Technology - Computer Science And Engineering

ABES IT/AKTU
Ghaziabad
08.2015 - 12.2020

Intermediate - PCM

Gandhi Inter College Chilkhar Ballia
Ballia
04.2014 - 05.2015

High School -

St. Xavier's School Ballia
Ballia
04.2011 - 05.2012

Skills

●Web Application Penetration Testing Tools - Burp Suite, SqlMap, Metasploit, Nmap

undefined

Certification

EC-Council Certified Security Analyst(ECSA) EC Council

Accomplishments

● Super Team Award in KPMG

● Accolades for finding Critical vulnerability in KPMG projects.

Timeline

Consultant

KPMG India
04.2023 - Current

Associate Consultant

KPMG India
04.2022 - 03.2023

Analyst

KPMG India
04.2021 - 03.2022

EC-Council Certified Security Analyst(ECSA) EC Council

01-2021

Trainee Security Analays

BreachLock Inc
02.2020 - 04.2021

Bachelor In Technology - Computer Science And Engineering

ABES IT/AKTU
08.2015 - 12.2020

Intermediate - PCM

Gandhi Inter College Chilkhar Ballia
04.2014 - 05.2015

High School -

St. Xavier's School Ballia
04.2011 - 05.2012
Abhinav MishraCyber Security