Summary
Overview
Work History
Education
Skills
Certification
Accomplishments
Languages
Timeline
AdministrativeAssistant

Rahul Yadav

Faridabad,HR

Summary

Highly skilled Cyber Security professional specializing in Penetration Testing and Configuration Reviews. Proficient in conducting thorough assessments in diverse domains, including Web Application, Network, Mobile Application, Thick Client, Cloud, Kubernetes, and Containers.

Demonstrated expertise in implementing security tools within CI/CD pipelines for various stages, encompassing SCA, SAST, DAST, IaC, CaC, and Vulnerability Management. Holds multiple certifications, including Certified Ethical Hacker v11, Certified DevSecOps Professional, and Microsoft Azure’s Security Engineer Associate. Well-versed in utilizing a wide range of professional and open-source tools to enhance security measures effectively.

Overview

3
3
years of professional experience
1
1
Certification

Work History

Security Consultant

E&Y LLP
09.2023 - Current
  • Led the creation and evaluation of risk assessments for the entire organization, meticulously analyzing and mitigating risks across diverse departments, resulting in a 15% reduction in overall identified risks
  • Developed and implemented comprehensive security documentation outlining Standard Configuration Directives (SCD) for servers, endpoints, and network devices
  • Generated regular reports summarizing the status of server, endpoint, and network device configurations, highlighting achievements, areas for improvement, and recommendations for enhancing overall security posture
  • Led the Vulnerability Management program, overseeing the identification, assessment, and remediation of security vulnerabilities across multi-platform environments, resulting in a 30% decrease in high-severity vulnerabilities
  • Defined key performance indicators (KPIs) related to configuration management effectiveness, such as compliance rates, incident response times, and resolution efficiency

Security Analyst

Mobikwik
Gurgaon, Haryana
05.2023 - 08.2023

• Led vulnerability management program to ensure the tracking and remediation of the critical vulnerabilities in organisations infrastructure.
• Performed source code review of the various internal applications and identified several high-severity issues.

Associate Consultant

KPMG
08.2021 - 05.2023
  • Conducted meticulous penetration testing for Schneider Electric's Global Security Lab on both Mobile and Thick Client applications to ensure their security and resilience against potential cyber threats
  • Spearheaded Red Teaming exercises to fortify the internal infrastructure, proactively identifying and addressing critical misconfigurations and vulnerabilities that could compromise the organization's security posture.
  • Demonstrated expert command in performing Container and Cloud Penetration Testing, enabling meticulous evaluation and fortification of cloud-based infrastructure and containerized environments, thereby bolstering the organization's overall security posture
  • Demonstrated leadership and organizational skills by managing and orchestrating Capture the Flag (CTF) competitions for college students, aligning the event's objectives with the recruitment process to identify exceptional talents for potential hiring opportunities.

Security Analyst

CyberCube Services (P) Ltd
01.2021 - 07.2021
  • Conducted comprehensive penetration testing on web applications, meticulously analyzing their security posture and successfully identifying several critical vulnerabilities that could potentially expose the organization to substantial business risks.
  • Demonstrated expertise in performing thorough Vulnerability Assessment and Penetration Testing (VAPT) on the organization's internal network across diverse domains, aiming to fortify its security infrastructure and safeguard sensitive information from potential threats.

Education

Bachelor of Technology - Computer Science, Cyber Security

Lingaya's University
Faridabad, India
04.2021

AISSCE -

Army Public School
Mathura, India
04.2016

Skills

  • Web Application Penetration Testing
  • Mobile Application Penetration Testing
  • Thick Client Penetration Testing
  • API Penetration Testing
  • Configuration Reviews
  • Docker and Kubernetes
  • Source Code Review
  • Vulnerability Management
  • DevSecOps
  • Red Teaming

Certification

  • CRTP, Altered Security - 2024
  • ISO 27001 Lead Auditor, BSI - 2024
  • Azure Security Engineer Associate, Microsoft - 2022
  • Hacking and Securing Cloud Infrastructure, NotSoSecure - 2022
  • Certified DevSecOps Professional, Practical DevSecOps - 2022
  • Certified Ethical Hacker (CEH) Practical, EC Council - 2021
  • AWS Security Fundamentals, AWS - 2021
  • Azure Fundamentals, Microsoft - 2021

Accomplishments

  • Bug Bounty - Man Matters
  • Super Team Award, KPMG - 2023
  • Kudos, KPMG - 2023


Languages

English
Bilingual or Proficient (C2)
Hindi
Bilingual or Proficient (C2)

Timeline

Security Consultant

E&Y LLP
09.2023 - Current

Security Analyst

Mobikwik
05.2023 - 08.2023

Associate Consultant

KPMG
08.2021 - 05.2023

Security Analyst

CyberCube Services (P) Ltd
01.2021 - 07.2021

Bachelor of Technology - Computer Science, Cyber Security

Lingaya's University

AISSCE -

Army Public School
Rahul Yadav