Security Researcher and testing the new Security Technologies
I am an Information Security Consultant over 2 years of experience in the Information Security domain. I specialize in various security technologies, including web and mobile application penetration testing, network penetration testing, vulnerability management, and security configuration reviews. My experience includes working in demanding environments such as public and private sector banks, where I have effectively managed and addressed a wide range of security challenges.
•Conducted penetration testing on a wide range of web and mobile applications.
•Performed penetration testing and vulnerability assessments on various targets,including Windows, UNIX, Linux systems, routers, firewalls, switches, and web applications.
•Conducted security configuration reviews on servers running Windows and Linux.
•Detected, investigated, confirmed, and exploited diverse security
vulnerabilities on both server and client sides.
•Identified web application vulnerabilities using black box and grey box penetration testing approach.
•Assisted in the execution of application security penetration testing activities,including scheduling, resource allocation, tool execution, and reporting.
•Identified potential security vulnerabilities that could threaten customernetworks, assets, or applications in the near future.
•Engaged with clients in both public (government) and private sector banks.
•Experience in automated web application vulnerability scanners and manual assessments using Burp Suite.
•Strong knowledge on OWASP and detailed knowledge of common web application
Vectors such as SQL injection, CSRF, XSS ,Click Jacking etc.
•Strong knowledge in security tools such as Nessus, Qualys Guard, NMAP, Burp Suite,
Kali Linux, Metasploit, MobSF, Postman and Wireshark tools.
•Provide guidance to improve the operations and compliance with security controls
and systems.
Security Researcher and testing the new Security Technologies
Reading Security Blogs and Security Web Articles