Summary
Overview
Work History
Education
Skills
Certification
Industry Expertise
Experience Highlights
Timeline
Generic
Kirti Kharb

Kirti Kharb

Senior Consultant
Sonipat

Summary

Experienced cybersecurity consultant proficient in deploying effective security solutions, specializing in Onsite-ME projects. Recognized for adeptly identifying vulnerabilities, proposing corrective measures, and elevating overall security posture. A collaborative team member with strong skills in security testing, documentation, research, and suggesting security improvements.

Overview

5
5
years of professional experience
2
2
years of post-secondary education
3
3
Certifications

Work History

Senior Consultant

Protiviti India Member Private Ltd.
05.2022 - 10.2024

Executed diverse assessments including bug bounty hunting, vulnerability assessment and penetration testing (VAPT), application security (AppSec) testing, network architecture and source code reviews, cyber threat intelligence (CTI) assessments, vulnerability analysis & management. As well as audits of application security, cloud security and vendor risk management.

Security Researcher

Bugcrowd
08.2020 - 04.2022

As a security researcher, conducted vulnerability assessments for over 30 organizations, resulting in more than 70 accepted submissions. Recognized for contributions with monetary rewards and points-based incentives.

Information Security Engineer

TAC Security
05.2019 - 08.2020

Engaged in penetration testing across a variety of platforms including web, Android, network, and thick client applications. Innovated new testing methodologies to uncover vulnerabilities effectively. Compiled comprehensive bug reports and incident reports for further action and resolution.

Education

Master of Computer Applications - Computer And Information Systems

DCRUST University
Sonipat
08.2015 - 05.2017

Skills

VAPT (Web, Mobile, API, Network, cloud security, forensics)

Time management

Teamwork mindset

Vendor risk management

Cyber threat intelligence

Source code reviews

Technical Tools

Internal VAPT Audits

VAPT (Web, Mobile, API, Network, cloud security, forensics)

Certification

Certified Ethical Hacker(CEH)

Industry Expertise

  • Banking & Financial services (BFSI)
  • E-Commerce
  • Hospitality
  • Healthcare
  • IT/ITES
  • Social Media

Experience Highlights

Vulnerability Assessment and Penetration Testing (VAPT):

  • Conducted successful SAST and DAST security testing across a diverse range of applications, Provided real-time feedback on security flaws utilizing a comprehensive suite of SAST and DAST tools.
  • Expertise in identifying, analyzing, and prioritizing security vulnerabilities. Proficient in using CVSS to evaluate risk levels and EPSS to forecast exploitability.
  • Tested and remediated code-level vulnerabilities in web, mobile and network, while also simulating real-world attack scenarios.
  • Familiar with tools such as Rapid7, Checkmarx, and Black Duck for managing vulnerabilities across cloud platforms and on-premises environments.

Cyber Threat Intelligence (CTI) Assessment:

  • Conducted CTI assessments across various applications, offering meticulous reporting and documentation.
  • Expertise includes utilizing SIEM and OSINT for threat analysis, understanding cyber attack vectors, and employing incident response protocols.

Cloud Security:

  • Understanding of cloud environments, including AWS and Azure ensuring security best practices for infrastructure, identity management and data storage.
  • Implement and manage security controls for cloud-based applications and services.

Internal Audits:

  • Conducted in-depth analysis to identify vulnerabilities in authentication protocols and sensitive data storage within mobile applications. Ensured adherence to policy compliance standards through rigorous verification processes.
  • Performed thorough reviews encompassing network architecture, firewall rules, and backup policies. Conducted comprehensive technology inventory assessments. Provided recommendations for network architecture improvements and offered mitigation strategies.
  • Conduct security assessments for container configurations and implement security policies to mitigate potential risks. Automated security monitoring and reporting processes using python and java scripts, enhancing the team's efficiency in vulnerability tracking and mitigation.

Timeline

Senior Consultant

Protiviti India Member Private Ltd.
05.2022 - 10.2024

Security Researcher

Bugcrowd
08.2020 - 04.2022

Information Security Engineer

TAC Security
05.2019 - 08.2020

Master of Computer Applications - Computer And Information Systems

DCRUST University
08.2015 - 05.2017
Kirti KharbSenior Consultant