Sai Nandan
***********.*@*****.***
Professional Summary:
7+ years of professional experience in the Information Security domain involving responsibilities such as Application and Network Vulnerability Assessment, Penetration Testing, and taking care of end-to-end Security of organization/clients. I have also experience in working as a Security analyst where my responsibilities include security Incident handling, threat detection, analysis of logs from various network devices.
Experience in performing network and web vulnerability Assessment scans scanning using various vulnerability assessment tools.
Experience in performing penetration testing using various Kali Linux tools, web application penetration testing as per OWASP
Experience in Security Incident Handling that includes analysis of various network and host-based security appliance logs (Firewalls, IPS, IDS. EDR, SIEM, etc.) to determine the correct remediation actions and escalation for each incident
Experience in implementing automation through scripting languages like Python
Experience in Cloud Access Security Broker (CASB) and Data Loss Prevention (DLP) solutions.
Experience in troubleshooting Qualys, Tenable Nessus and other security tools when it is not working properly
Configuring CIS benchmark scans/custom benchmark scans and policy scans on Qualys, Tenable.io Nessus to check if hosts(Windows Server/Linux Server/Web Server/Apache) are configured as per the standards
Prioritizing vulnerabilities based on CVSS score, criticality of the issue and following industry standards such as NIST, CIS, CSA etc
Experience in implementing policies for Web Application Firewall (Akamai WAF) to prevent applications from web attacks/bot attacks
Quick learner, Resourceful team player, and capable of delivering tasks within stringent timelines.
Excellent analytical, communication, and presentation skills.
EDUCATION
Bachelor of Technology Jun 2013 - Apr 2017
Rajiv Gandhi University of Knowledge Technologies • India
Specialization in Computer Science and Engineering with CGPA of 8.30
Pre-University Course Sep 2011 - May 2013
Rajiv Gandhi University of Knowledge Technologies • India
Secondary Education (School) Apr 2010 - Mar 2011
S. E. Railway Mixed Higher Secondary School (E.M) • Kharagpur
Professional Credentials:
Offensive Security Certified Professional – OSCP – May 2022
Certified Ethical Hacker – CEH v10
Qualys Certified Specialist – Vulnerability Management
Qualys Certified Specialist – Web Application Scanning
Technical Skills:
Vulnerability Management/Assessment Tools: Qualys, Nessus, ZAP, Kenna Security, Onapsis
Penetration Testing Tools: Burp Suite, nmap, Metasploit, powershell, mimikatz and other Kali Linux tools
Programming Languages: Python, C, CoreJava, shell scripting, powershell
Operating System: Windows, Linux, Mac
Ticketing Tools: ServiceNow, Opsramp, JIRA
Other Security Tools: Netskope, Symantec DLP, Orca, Akamai WAF, KnowBe4, CyberArk, IBM QRadar, Splunk
Reporting Tools: Microsoft Excel, Powerpoint, Access Database, PowerBI, Neo4j
Professional Experience:
Cybersecurity Analyst - Vulnerability Management Dec 2020 - Present
Levi Strauss and Co • Westlake, TX, USA• Remote
Industry: Retail, e-commerce Textile Industry
Roles and Responsibilities:
Performing system network vulnerability scans using tools like Nessus, Qualys. Analyzing the findings and removing the false positives.
Performing penetration testing using various Kali Linux tools, listing out the loopholes, and exploiting the vulnerabilities
Performing web application vulnerability assessment using Qualys, ZAP. Analyzing the findings and removing the false positives.
Reveal information gaps that can help identify potential security threats and recommend security enhancements to mitigate the threats
Performing manual penetration testing on web applications(e-commerce sites) using Burp Suite and other manual tools for identifying deeper vulnerabilities.
Reporting the vulnerabilities generated from the tools with appropriate recommendations in order to mitigate the loopholes
Implementing policies for Web Application Firewall (Akamai WAF) to prevent applications from web attacks/bot attacks
Generating POCs for all the vulnerabilities and listing them out in a prescribed report including impact and eradication/remediation guidelines.
Conducting bug bounty programs and interacting with security researchers regarding the submissions.
Associate Information Security Engineer - II Oct 2019 - Dec 2020
HighRadiusTechnologies • Houston, TX, USA• Remote
Industry: Fintech/Financial Supply Chain Management
Roles and Responsibilities:
Performing system network vulnerability scans using tools like Nessus, Qualys. Analyzing the findings and removing the false positives.
Performing penetration testing using various Kali Linux tools, listing out the loopholes, and exploiting the host
Secure the fintech products such as Integrated Receivables Platform, Cash Application Automation, Collections Management, Deductions Management, and Credit Management used by Clients like Bank of America, Citi Bank, etc
Scheduling CIS benchmark scans for systems like web server, application server, Operating System
Performing web application vulnerability assessment using Qualys. Analyzing the findings and removing the false positives.
Performing manual penetration testing on web applications using Burp Suite and other manual tools to identify the deeper vulnerabilities apart from the low hanging fruits
Reporting the vulnerabilities generated from the tools with appropriate recommendations in order to mitigate the loopholes
Generating POCs and including steps to reproduce for all the vulnerabilities and listing them out in a prescribed report including impact and eradication/remediation guidelines.
Worked on implementing Netskope Cloud Access Security Broker(CASB) tool for shadow IT discovery and writing policies for web protection.
Worked on Symantec DLP for monitoring alerts and creating rules for protecting data like PII, PCI, HIPPA etc.
Been a part of audit meetings conducted by Risk & Compliance Team that includes providing evidences adhering to standards like ISO 27001, PCI-DSS as well as internal audits.
Associate Analyst May 2016 - Oct 2019
NetEnrich Technologies Pvt Ltd • Hyderabad, India
Industry: IT-Security Services/ MSSP
Roles and Responsibilities:
Responding to security incidents that get triggered from various network devices
Analyze network flow data for anomalies and detect malicious network activity
Administration, monitoring of security events on various SIEM platforms and investigating, documentation, reporting on true positive events and on emerging threats.
Assist with the development of processes and procedures to improve incident response times, analysis of incidents, and overall SOC functions
Exploring different threat intelligence platforms like IBM X-force, Alienvault OTX.
Providing detailed reports on contamination and eradication/remediation to clients.
Performing vulnerability assessment and penetration testing for various network devices and web applications.