Sherwyn Moodley
Ontario, Canada 226-***-**** *******@**************.***
Penetration Testing and Security Consulting
Summary
Over 10 years of experience in IT, starting as a Network Engineer and currently a Penetration Tester. IT Security and Assessment Professional with excellent written and oral communication skills. Thorough understanding of Networking Information Assurance and Cybersecurity disciplines to include open- source information gathering threat and vulnerability assessments penetration testing and techniques and network defence.
Core Competencies
●External Penetration Tests
●Web Application Testing
●AWS and GCP Security
●WAF/IPS/FW Testing
●CIS Cloud Controls
●Attack Surface Assessments and OSINT
●Cloudtrail, Cloudfront
●Sumologic, SIEM
●Rapid7 and Tenable Vulnerability Management
●EDR Deployments
●Architect, Implement and Support security monitoring services
●Security Integration Deployment
●ISO 27001, SOC2, compliance testing
●Linux - Ubuntu, Arch, Debian, Gentoo, Mint
●Process Documentation
Professional Experience
2019 - Current Independent CyberSecurity Consultant
(Due to Non Disclosure Agreements, clients are described and not named)
Social Media and Photography platform with 30M users
●Web Application Penetration Test
●Mobile Penetration Test
●Reverse Engineering apk using Ghidra
●Using Burp Suite and Frida to bypass SSL Pinning
●Web API testing using Postman
●Report and Presentation
Blockchain as a service provider
●Web Application Penetration Test
●API Testing
●GCP Assessment
Marketing Platform inserting machine learning into chatbots
●Web Application Penetration Test
●Web Services and API Testing
●Report and Presentation
●OSSINT Assessment
●Github and Cloud Service Assessment
Nationwide US Online Catering Platform
●SIEM and AWS services Integration
Github
Cloudtrail
Cloudfront
Security Hub
Inspector
Crowdstrike
●OSSINT Assessment
●AWS Assessment
Collaboration Video Editing and Sharing Platform
●CyberSecurity Awareness Policy and Procedure Documents
●Phishing Campaigns using Knowbe4
●CIS Top 20 Control Assessment
Online Marketplace for pet care and services (nationwide US and Canada)
●OSSINT and Cloud Assessment
●CIS Top 20 Control Assessment
Internal Security Program
●Unified IAM
●Phishing Prevention
●DLP
●Security Centre and Investigations
●OpenVPN SSO
2015 - 2019 Penetration Testing and Security Consultant
Exocet Security
●Penetration Testing
Large South African Job Board website
Client in the Education sector
South African HR as a service client
●Web Application Testing
Large South African Job Board Web Application
City of Johannesburg Education System
Banking Application to share client data between large banks
●Vulnerability Management
Rapid7 - InsightVM, Metasploit, AppSec, Nexpose, AppSpider
South African Government entity with over 30 000 devices
Botswana Telecommunications Company
Enterprise Education Client
●Penetration Testing and Vulnerability Management policy documentation
●OSINT and Surface Attack Assessments
●SOC2 technical assessments
●CIS Control assessments
Botswana Government entity in Financial Oversight
Online HR company
Auto Retailer
Online Education Provider
●AWS Security - Cloudtrail, Cloudfront, SecurityHub
●GCP Security Assessments
●Architecture Documentation
●Process Documentation
2012 - 2014 Senior Network Engineer/Sales Engineer
StorTech/Nexio
●Work with a sales team to identify, gather requirements for solutions
●Provide pre-sales support
●Design solutions and plan implementations
●Translate business needs into technology specifications
●Configure hardware and software
●LAN Assessments
●Information Gathering
●Network Solutions
●Network Design
●Penetration Testing
●Security Assessments
●VOIP readiness assessments Documentation
2011 - 2012 Network Engineer
Dimension Data
●WAN Optimization
●Network Troubleshooting
●Cisco Switches(3760, Nexus, 2960, 3560)
●PBA and Hardening deployment project
●Configs and Lab Testing on Cisco Switches
●Configs and Lab Testing on Cisco Router
●Deployment, piloting and troubleshooting
●Lead team of junior network engineers
●Design Document
BugBounty Profiles
https://hackerone.com/bagheeraaltered
https://bugcrowd.com/BagheeraAltered
Education
2019 Prisma Certifications, Sumologic Certifications
2017 Rapid7 Certifications,AppSec InsightVM Metasploit IDR
2015 Certified Ethical Hacker
2012 Cisco CCDA
2008 Cisco CCNA
2006 Associates Degree Information Technology, CTi Bedfordview