Sr. CYBER SECURITY ENGINEER Summary Skilled Cyber Security professional with 10+ years of domain experience. A dedicated security researcher well-versed in Application Security, Network Penetration Testing, Threat Intelligence, Incident Management, DevSecOps, Email Security, and Vulnerability Assessments. Possesses a rapid proficiency in acquiring new concepts and technologies, consistently demonstrating a proven track record of collaborative teamwork and a willingness to exceed expectations. Area of Expertise Application Security Testing Network Penetration Testing Mobile Application Security Testing API Security Testing DevSecOps Cloud Security Vulnerability Assessment Threat Intelligence Technical Skills Expertise in OWASP Top 10, CWE/SANS Top 25, MITRE ATT&CK, and NIST Cybersecurity Framework (CSF). Detailed knowledge of most common web application vulnerabilities and best security practices to prevent them. Strong hands-on knowledge in using most widely used security testing tools (Burp Suite, HCL AppScan, Zed Attack Proxy, Fortify, Tenable Nessus, Metasploit Framework, SQLmap, Nmap, API Fuzzer, Mobile Security Framework (MobSF), Sonar Qube and other Kali Linux tools, etc). Hands on experience in carrying out Threat Intelligence activities using various OSINT tools. Threat Modelling Vulnerability Assessment & Penetration Testing Experienced in conducting Security Risk Assessments and Compliance reviews. Experienced in LogRhythm SIEM administration. Familiar with integrating security practices into the software development lifecycle and carrying out DevSecOps activities.
At Brickendon, as a Senior Security Consultant, I manage all the software development security related activities such as introducing best security practices into SDLC, performing regular code scanning and monitoring, performing security testing on APls, periodic penetration tests, etc.
At Anoud Technologies, as a senior security analyst, I manage and perform several security related operations including Web penetration testing, Network vulnerability assessment, SOC operations and Email Security management.
My job responsibilities include,
• Performing Black box, Grey box and White box security testing using OWASP methodologies.
• Working as a part of development team throughout the SDLC and performing security testing for every release.
• Creating a professional assessment report with a detailed walk-through of the findings (POCs) and remediation plan.
• Preparing and reviewing risk assessment reports with developers and site owners.
• Periodically following up with the developers on the remediation of reported findings and conducting retests to make sure the vulnerabilities are completely fixed.
• Conducting security testing on Android and /OS mobile applications.
• Being a part of Security Operations Control (SOC) and managing SIEM activities using LogRhythm.
• Creating email policies and managing email gateways.
• Engaging Red Team activities and train developers on secure coding practices.
Application Security Testing
Network Penetration Testing
Mobile Application Security Testing
API Security Testing
DevSecOps
Cloud Security
Vulnerability Assessment
Threat Intelligence