Summary
Overview
Work History
Education
Skills
Hobbies and Interests
Training
Certification
Accomplishments
SOSdefence - Dependency Tracker
Web Application Firewall
Timeline
Generic
Yash Mishra

Yash Mishra

Gurugram

Summary

With over 5.5 years of experience, I am a cybersecurity professional specializing in application, network, and cloud security. My career is a blend of technical expertise and creative problem-solving, where I craft security frameworks to outsmart evolving threats and fortify digital landscapes. My expertise spans from securing intricate applications and safeguarding complex networks to optimizing cloud security with cutting-edge strategies. Passionate about turning cybersecurity challenges into opportunities for innovation, I thrive on designing solutions that not only protect but also enhance operational efficiency. My proactive approach and strategic mindset ensure that security is seamlessly integrated into every aspect of the digital ecosystem, balancing risk and resilience with agility and foresight.

Overview

6
6
years of professional experience
1
1
Certification

Work History

Security Engineer

Shiprocket
10.2023 - Current
  • Led and mentored a team of 6 cybersecurity professionals, driving performance improvements and ensuring effective execution of security strategies and protocols.
  • Conducted comprehensive vulnerability assessments, identified critical security flaws, and implemented remediation strategies to mitigate risks and enhance system resilience.
  • Partnered with development and engineering teams to facilitate the timely remediation of vulnerabilities, ensuring secure deployments and adherence to best security practices.
  • Working closely with other security teams, IT staff, and sometimes external partners to address and resolve security issues.

Associate Consultant

KPMG
07.2021 - 10.2023
  • Developed and implemented a Software Bill of Materials (SBOM) analysis tool to improve transparency and management of software components
  • Deployed and managed an attack surface monitoring solution to continuously assess and reduce potential exposure points in the system
  • Conducted workshops to share cybersecurity knowledge and best practices, enhancing team skills and awareness across the organization
  • Oversaw and monitored the operation of Palo Alto Prisma and Cortex solutions to ensure security posture and compliance.

SOC Analyst

CRAW Security
01.2020 - 07.2021
  • Identifying vulnerabilities and weaknesses in web applications through various testing methods
  • Simulating attacks to find potential entry points for malicious actors
  • Using automated tools to detect common security issues
  • Examining source code to find security flaws
  • Documenting findings and providing recommendations for remediation
  • Keeping abreast of the latest security trends, threats, and best practices.

Security Analyst Level 1

Safe Security
01.2019 - 12.2019
  • Conducting tests on networks and applications
  • Performing physical security assessments
  • Conducting security audits
  • Analyzing security policies
  • Documenting security incidents, actions taken, and the outcomes.

Education

B.Tech in Cloud Technology and Information Security -

Invertis University
Bareilly, India
09.2020

Skills

  • Project Management
  • Network Security
  • Penetration Testing
  • Application Security
  • Cloud Security
  • OSINT
  • Kali Linux
  • Windows
  • Mac
  • Automation
  • Offensive Approaching
  • JIRA and Confluence
  • Microsoft Office
  • Scripting
  • Reverse Engineering
  • Conducting vulnerability assessments
  • Red team scenarios
  • Code review
  • Incident response
  • Threat analysis
  • Reporting and documentation
  • Threat intelligence
  • Collaboration
  • Physical security assessments

Hobbies and Interests

  • Reverse Engineering
  • CTF Solving
  • Video Games
  • YouTube Content Creating
  • Rubix Cube Solving
  • Travelling

Training

  • Robotics and Embedded System Workshop
  • Amazon Web Services Workshop
  • Machine Learning Workshop

Certification

  • PEN-200: Penetration Testing with Kali Linux OSCP Certification, Offensive Security, 2016, 90 Points
  • Penetration Testing Certification by CompTIA, CompTIA, March 2020
  • Lucideus Cyber Security Professional, Lucideus, 2020, 100%
  • AWS Certified Solutions Architect Associate, Amazon Web Services, 2020

Accomplishments

  • CVE-2023-36266 - Keeper Security desktop 16.10.2 & Browser Extension 16.5.4 - Password Dumping
  • CVE-2023-52252 - Unified Remote 3.13.0 - Remote Code Execution (RCE)
  • CWE-434 - WordPress Plugin Simple File List 4.2.2 - Arbitrary File Upload

SOSdefence - Dependency Tracker

Security Solution for OWASP A8: Software and Data Integrity Failures:

SOSdefence is a security solution designed to address OWASP A8: Software and Data Integrity Failures. It helps organizations identify and mitigate risks related to software and data integrity, ensuring the security and reliability of their applications and data.

SBOM Analysis Tool, SOSdefence is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. SOSdefence takes a unique and highly beneficial approach by leveraging the capabilities of Software Bill of Materials (SBOM). This approach provides capabilities that traditional Software Composition Analysis (SCA) solutions cannot achieve. 

SOSdefence monitors component usage across all versions of every application in its portfolio in order to proactively identify risk across an organization. The platform has an API-first design and is ideal for use in CI/CD environments., 

Web Application Firewall

Web Application Firewall, A WAF or Web Application Firewall helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet. It typically protects web applications from attacks such as cross-site forgery, cross-site-scripting (XSS), file inclusion, and SQL injection but is not designed to defend against all types of attacks.

Documentation: https://bit.ly/2QRpxfI

Whitepaper: https://bit.ly/31SfpJZ

Timeline

Security Engineer

Shiprocket
10.2023 - Current

Associate Consultant

KPMG
07.2021 - 10.2023

SOC Analyst

CRAW Security
01.2020 - 07.2021

Security Analyst Level 1

Safe Security
01.2019 - 12.2019

B.Tech in Cloud Technology and Information Security -

Invertis University
Yash Mishra