I have Knowledge of Information Security that includes web application, API, and mobile penetration-based Security and Auditing. My experience includes Web, Mobile, API security assessment for Educational websites Ecommerce websites
Overview
1
1
Certification
Work History
Role: Played a vital role as team member and delivered multiple application and network security assessments, Mobile based applications and thick client for leading server and platform
Conducted systematic web application security assessments and penetration tests
The assessments involve manual testing and analysis as well as the use of automated web application vulnerability scanning/testing tools
Application Security Assessment for wide range of business applications: web applications domain against standards such as OWASP Top 10
Proficient in understanding and executing application-level vulnerability attacks like - XSS (Cross Site Scripting), SQL injection, CSRF (Cross Site Request Forgery), Response Splitting, Session Hijacking, Variable Manipulation, Privilege escalation, Authorization Bypass, Authentication flaws etc
Creating Proof of Concept (PoC) for the vulnerability findings and creating formal reports
Recommend corrective measures and ensure the adequacy of existing information security controls
Develop risk remediation plans and security procedures
Conducted External / Internal vulnerability assessment using Nessus
Static analysis and dynamic testing of mobile application
Preparing Dashboard and presents written and oral reports and other technical information in appropriate, concise, and accurate manner for distribution to various responsible or accountable department
Conducting operational, compliance and investigative audits, as assigned
Education
Diploma - Computer Engineering
Maharashtra State Board of Technical Education
06.2018
Bachelor of Science - Information Technology
University of Mumbai
06.2021
Master of Science - Information Technology
University of Mumbai
07.2023
Key Skill Sets
Application Security Testing (Web, Mobile and API)
Good Knowledge in Security Concepts.
Information Security Audits, Policy and Procedure Review