Summary
Overview
Work History
Education
Skills
Certification
Areas Of Interest
Projects
Timeline
Generic

Aneesh Narain

Bengaluru

Summary

Looking for a challenging position where I can utilize my skills to the extent possible to achieve individual as well as organization goals.

Overview

14
14
years of professional experience
4
4
Certification

Work History

Senior Staff

PaloAlto Networks
Bengaluru
08.2022 - Current
  • Currently working under solution team, where I take care of end to end deployment as well as validation of different features and functionalities.
  • Tested multiple functionalities on PRISMA cloud deployed Paloalto firewalls like CASB, SASE, SAAS Inline, WILDFIRE, IoT, DLP. Policy access browsing(PAB), Zero-trust Network Access (ZTNA), DLP,Advance Threat Prevention (ATP), Vulnerability Management, FEDRAMP.
  • Deployed Paloalto firewall on Azure cloud and validated all L7 functionality.
  • Using Python for Test case Automation.

Member of Technical Staff

Fortinet technologies
Bengaluru
04.2013 - 08.2022

Pentest:

  • Familiar with Web application security issues related to different types of vulnerabilities part of OWASP-Top-10 such as Injections.
  • Validating Pentest tool against FP and FN for vulnerability part of different categories.
  • Creating vulnerable targets for validating the functionality of the Pentest tool.
  • Comparing results of different VAPT tools like Fortipentest, Netsparker, Nessus, Burp.
  • Cloud deployment of FPT tool on Azure.
  • Docker container validation for all different supported modules.

FIPS-CC:

  • Familiar with all different hardening criteria to make our product certified against FIPS-CC.
  • Different cryptographic Algorithm validation.
  • Certificate Validation, PKI/Certificates, encryption/hashing for different scenarios.
  • OPENVPN(SSL), IPsec validation.
  • Focus mainly on hardening the product like cryptography, certificates, privilege escalation, password hardening, external communication encryption and many more.

L2/L3 Testing:

  • Strong Networking Fundamentals and L2/L3 protocols.
  • Tested features such as load balancing, BGP route reflector, Communities, OSPF election process etc
  • Strong knowledge in networking fundamentals like ARP, ICMP, ETHERNET, IP FORWARDING.
  • Developed and executed test cases for functional testing of OSPF, BGP, RIP, VLAN.
  • Hands-own experience in setting up the test topology.
  • Brief knowledge about IPV6, IPSec and Wireless protocols like (802.11 a/g/n ).
  • Security Protocols: SSL, 802.1x.

QA Engineer

Quintom Mentor Systems pvt. Ltd.
06.2010 - 04.2013

L2/L3 and security Protocol testing:

This Project involve testing different protocols related to L2/L3 and some security protocols.

So I need to perform both Manual and Automation.

Protocols tested: SSL, 802.1x, OSPF, BGP, RIP, VLAN, ARP, ICMP, ETHERNET, STP and RSTP, IP FORWARDING, WLAN Controllers.

Education

B.E. -

Pune University
01.2009

12th -

01.2004

10th -

01.2002

Skills

  • SASE/ CASB/ WildFire/ IoT/ SaaS Inline/ FEDRAMP/ Prisma CLoud/ DLP/ Secure access browser/ Proxy
  • SSL/ IPSec
  • Pentest/ Web application security/ OWASP-Top-10/ Injections/ Pentest tool/ VAPT tools/ Fortipentest/ Netsparker/ Nessus/ Burp Suit
  • FIPS-CC/ Hardening criteria/ Cryptographic Algorithm validation/ Certificate Validation/ PKI/Certificates/ Encryption/hashing
  • L2/L3 Testing/ Networking Fundamentals/ L2/L3 protocols
  • ARP/ ICMP/ ETHERNET/ IP FORWARDING/ VLAN/ IPV6
  • OSPF/ BGP/ RIP/ Load balancing/ STP/ RSTP
  • Test cases/ Test topology
  • Cloud deployment/ Azure/ Docker container validation
  • Wireless protocols/ 80211 a/g/n/ Security Protocols/ 8021x
  • Scripting/ Python

Certification

  • CEH V11 (Certified Ethical Hacker Version11)
  • Fortinet: Network Security Associate-1
  • Fortinet: Network Security Associate-2
  • Fortinet: Network Security Associate-3
  • Preparing for OSCP

Areas Of Interest

Information Security Analyst, Networking, L3/L7 Network Security, Ethical Hacking, Security Information and Event Management Vulnerable Assessment & Penetration Testing (VAPT), Hardening, Server, Firewall, TCP/IP.

Projects

PRISMA CLOUD/ Firewall: 

  • Currently working under solution team, where I take care of end to end deployment as well as validation of different features and functionalities., Tested multiple functionalities on PRISMA cloud deployed Paloalto firewalls like CASB, SAAS Inline, WildFire, IoT, FEDRAMP. Deployed Paloalto firewall on Azure cloud and validated all L7 functionality.

FortiPentest:

  • I will perform end to end testing for FortiPentest tool, which detects vulnerabilities on Web Applications. Apart from that I use to validate the deployment infrastructure where we will cover Docker container validation as well as cloud deployment of our tool. So worked on Azure and GCP for cloud deployment. Initially tool was designed to detect vulnerabilities related to OWASP Top 10, but now new coverage has been added and I have to validated different functionalities., So my role is to come up with the test cases and targets for validating functionality of the tool. Then review it with Product Management and Dev team. Fox ex: If I need to validated RCE functionality then we need to created targets and test case to cover all possible scenarios so that tool should not report FP or FN. So I have tested multiple Injections like SSTI, SQLi, NoSQL, LDAP, etc. , XSS, SSRF, CSRF, Security misconfiguration, Using component with known vulnerabilities, broken Authentication, session fixation, recon engine, zero day vulnerabilities, Scanning Networks, Enumeration, Session Hijacking, Buffer Overflow, Cryptography.

FIPS-CC Certification:

  • I have worked on making Fortinet products get certified for FIPS-CC. FIPS 140-2 and Common Criteria are two security-product certification programs run by government. FIPS 140-2 says the cryptographic parts of a product must be done to the government’s satisfaction. Common Criteria details a range of security related topics (like auditing, or software development practices) and what the government requires for different types of products., So my role was to come up with the test cases for all different Fortinet products, so test cases will vary for different products like firewalls, Controllers Access Points. Where we will focus mainly on hardening the product like cryptography, certificates, privilege escalation, password hardening, external communication encryption and many more. So after internal testing we send our product for certification.

L2/L3 and security Protocol testing:

  • This Project involve testing different protocols related to L2/L3 and some security protocols. So I need to perform both Manual and Automation. Protocols tested: SSL, 802.1x, OSPF, BGP, RIP, VLAN, ARP, ICMP, ETHERNET, STP and RSTP, IP FORWARDING, WLAN Controllers. Brief testing of IPV6, IPsec and Wireless protocols like (802.11 a/g/n ), Understanding the feature, requirements and the scope of the feature for testing. Test topology setup Come up with test cases and review it with product management and Dev team. Modification the test scripts by using Python. Manual testing and verification of the expected results. Bug reporting Result documentation. Support on customer issue’s, This Project involved to work with customer requirement, Reproducing issue to our lab environment Raise an internal bug to work with Developers. write Test plan, Test cases related to this issue. Used to automate test cases by using existing framework and Python and integrate it to regression.

Timeline

Senior Staff

PaloAlto Networks
08.2022 - Current

Member of Technical Staff

Fortinet technologies
04.2013 - 08.2022

QA Engineer

Quintom Mentor Systems pvt. Ltd.
06.2010 - 04.2013

B.E. -

Pune University

12th -

10th -

Aneesh Narain