Summary
Overview
Work History
Education
Certification
Skills
Software
Work Availability
Interests
Quote
Timeline
Publications
Generic
Rami Reddy Allam

Rami Reddy Allam

Cyber Security Engineer
Nandyal,Andhra Pradesh

Summary

A seasoned cybersecurity professional with expertise in penetration testing and security analysis across diverse domains. With a track record of over 250 projects, specialize in web and mobile application security, network infrastructure VAPT, API security testing, payment gateway assessments, thick client penetration testing, and red team assignments.


Guided by industry standards like OWASP, NIST, and MITRE frameworks, employ a meticulous approach to identify and mitigate vulnerabilities effectively. My work has bolstered security postures for organizations in healthcare, e-commerce, banking, government initiatives, and more.


Dedicated to upholding compliance standards such as PCI DSS, PA-DSS, and GDPR, prioritize data security and regulatory adherence. Excel in collaborative teamwork, addressing security concerns, and implementing proactive solutions efficiently and effectively.

Overview

3
3
years of professional experience
6
6
years of post-secondary education
4
4
Languages
5
5
Certificates

Work History

Senior Security Analyst

Andhra Pradesh Technology Services
04.2021 - 03.2024
  • Experienced in conducting thorough penetration testing on over 100 web applications across diverse sectors including healthcare, e-commerce, banking, and government initiatives.
  • Identified and mitigated various vulnerabilities including SQL Injection, Cross-Site Scripting (XSS), XML External Entity (XXE) injection, Account Takeover, Local File Inclusion (LFI), Insecure File Upload, Broken Access Controls, Business/Application Logic Bypass, Remote Code Execution (RCE), Insecure Direct Object References (IDOR), Privilege Escalations, Insecure Deserialization, Server-Side Request Forgery (SSRF), Server-Side Template Injection (SSTI), and Insecure Designs.
  • Applied industry standards such as OWASP, NIST, and MITRE frameworks to ensure comprehensive coverage and adherence to best practices in web application security.
  • Experienced in conducting penetration testing on over 60 mobile applications spanning various categories, utilizing technologies like React Native, Flutter, Xamarin, and Progressive Web Apps.
  • Identified vulnerabilities such as SQL injection, business/application logic bypass, reflected file download, flaws in S3 buckets, insecure storage, insecure logging of data, hardcoded sensitive information, root detection bypass, jailbreaking detection bypass, SSL pinning bypass, account takeover, and authentication/authorization issues.
  • Executed over 25 Vulnerability Assessment and Penetration Testing (VA/PT) assessments on network infrastructure across a wide range of sectors including Defense, Electricity, OT/SCADA, Police department, Emergency services, Financial services, Industrial development, and IT sector.
  • Identified vulnerabilities such as device and framework-centric CVEs, weak credentials exploitation, Windows-centric vulnerabilities related to SMB, RDP, exploitation of unauthorized services(LDAP, TNS Listener etc..), and exploitation of default services and Credentials( snmp, sql, postgresql).
  • Conducted penetration testing on REST and SOAP APIs across various domains, identifying vulnerabilities such as broken object and functional issues, injection attacks, authentication issues, rate limiting, mass assignment, open/unvalidated redirection, insecure file uploads, misconfigurations, business logic flaws, excessive data exposure, and Cross-Site Request Forgery (CSRF).
  • Performed penetration testing and compliance assessments on diverse domains within payment gateways , encompassing aspects such as offers, discounts, prices, discount eligibility, products, and maximum discounts.
  • Performed rigorous penetration testing activities including injection attacks and checksum verification to identify vulnerabilities and ensure robust security measures. Adhered to compliance standards such as PCI DSS, PA-DSS, and GDPR, conducting comprehensive assessments to ensure regulatory adherence and data security.
  • Conducted penetration testing on thick client applications , identifying issues such as DLL hijacking, insecure validation and injections, insecure storage of sensitive data, buffer overflow, authentication bypass, privilege escalations, command injections, and hardcoded sensitive data.
  • Executed Red Team assignments including social engineering, targeted phishing, Google dorking, credential spraying, DoS attacks, sub-domain takeover, DNS attacks, RCE, and mail server takeovers.
  • Collaborated with cross-functional teams to mitigate reported issues and suggested best solutions to resolve issues without affecting users.
  • Served as single point of contact for working closely with CERT-In, testing government microservices AUA/KUA, NSDL, and health services.
  • Developed internal website to streamline th vulnerability management process, including project entry, adding proof of concepts (POCs), generating single PDF reports consolidating findings, issuing safe hosting certifications, and automatic generation of CERT-In datasheets.

    Achievements:
  • Successfully mitigated vulnerabilities across various sectors, ensuring enhanced security posture and compliance with industry standards.
  • Developed and implemented streamlined processes for vulnerability management, resulting in improved efficiency and effectiveness in addressing security issues.
  • Recognized for outstanding contributions in security testing and collaboration with cross-functional teams.

Education

Master of Technology - Cyber Security

KL University
Vijayawada, India
08.2019 - 12.2021

Bachelor of Technology - Computer Science

Kalasalingam University
Madurai, India
05.2015 - 04.2019

Certification

Certified Ethical Hacker Certification (CEH)

Skills

    Application Security

undefined

Software

Burp Suite

Acunetix

Nessus io

HCL Appscan

Metasploit

OWASP ZAP

IDS/IPS

Qualys

OWASP ZAP

Open Source tools : Nmap, Hash/password salt Cracking, Nikto, Sub and Directory tools, etc

Work Availability

monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Interests

Cloud Security

Research on opensource technology

Sports

Gaming

Movies/OTT

Quote

Don’t fear failure. Not failure, but low aim, is the crime. In great attempts it is glorious even to fail.
Bruce Lee

Timeline

Senior Security Analyst

Andhra Pradesh Technology Services
04.2021 - 03.2024

Master of Technology - Cyber Security

KL University
08.2019 - 12.2021

Bachelor of Technology - Computer Science

Kalasalingam University
05.2015 - 04.2019

Certified Ethical Hacker Certification (CEH)

Mar 2024

ORACLE CLOUD INFRASTRUCTURE FOUNDATIONS 2020 CERTIFIED ASSOCIATE

Aug 2021

AWS Knowledge: Cloud Essentials

Feb 2024

SECURING API SERVERS

Feb 2024

MICROSOFT CERTIFIED: AZURE FUNDAMENTALS

Aug 2022

Publications

  • ELLIPTIC CURVE CRYPTOGRAPHY OVER XOR, Allam Rami Reddy, http://thedesignengineering.com5index.php5DE5article5view56731, 08/09/92, This paper proposes a unique hybrid methodology based on Elliptical Curve Cryptography over XOR and Scrambling Techniques for Image encryption and decryption process.


  • VULNERABILITY PROJECT TRACKER APTS, This project is developed for my current organization for adding project details, vulnerabilities and adding POC. Then generating Project report in form of Pdf which contains OWASP Risk Categorization and other details followed by client details and POC with screenshots. It also includes Description, Impact, and Recommendations, Website Developed using P8P Report generator developed using TCPDF plugin.


Rami Reddy AllamCyber Security Engineer