Post Job Free
Sign in

Vulnerability Management, Web AppScanning, Penetration Testing, Python

Location:
Trenton, NJ
Posted:
July 11, 2023

Contact this candidate

Resume:

Sai Nandan

***********.*@*****.***

940-***-****

Professional Summary:

7+ years of professional experience in the Information Security domain involving responsibilities such as Application and Network Vulnerability Assessment, Penetration Testing, and taking care of end-to-end Security of organization/clients. I have also experience in working as a Security analyst where my responsibilities include security Incident handling, threat detection, analysis of logs from various network devices.

Experience in performing network and web vulnerability Assessment scans scanning using various vulnerability assessment tools.

Experience in performing penetration testing using various Kali Linux tools, web application penetration testing as per OWASP

Experience in Security Incident Handling that includes analysis of various network and host-based security appliance logs (Firewalls, IPS, IDS. EDR, SIEM, etc.) to determine the correct remediation actions and escalation for each incident

Experience in implementing automation through scripting languages like Python

Experience in Cloud Access Security Broker (CASB) and Data Loss Prevention (DLP) solutions.

Experience in troubleshooting Qualys, Tenable Nessus and other security tools when it is not working properly

Configuring CIS benchmark scans/custom benchmark scans and policy scans on Qualys, Tenable.io Nessus to check if hosts(Windows Server/Linux Server/Web Server/Apache) are configured as per the standards

Prioritizing vulnerabilities based on CVSS score, criticality of the issue and following industry standards such as NIST, CIS, CSA etc

Experience in implementing policies for Web Application Firewall (Akamai WAF) to prevent applications from web attacks/bot attacks

Quick learner, Resourceful team player, and capable of delivering tasks within stringent timelines.

Excellent analytical, communication, and presentation skills.

EDUCATION

Bachelor of Technology Jun 2013 - Apr 2017

Rajiv Gandhi University of Knowledge Technologies • India

Specialization in Computer Science and Engineering with CGPA of 8.30

Pre-University Course Sep 2011 - May 2013

Rajiv Gandhi University of Knowledge Technologies • India

Secondary Education (School) Apr 2010 - Mar 2011

S. E. Railway Mixed Higher Secondary School (E.M) • Kharagpur

Professional Credentials:

Offensive Security Certified Professional – OSCP – May 2022

Certified Ethical Hacker – CEH v10

Qualys Certified Specialist – Vulnerability Management

Qualys Certified Specialist – Web Application Scanning

Technical Skills:

Vulnerability Management/Assessment Tools: Qualys, Nessus, ZAP, Kenna Security, Onapsis

Penetration Testing Tools: Burp Suite, nmap, Metasploit, powershell, mimikatz and other Kali Linux tools

Programming Languages: Python, C, CoreJava, shell scripting, powershell

Operating System: Windows, Linux, Mac

Ticketing Tools: ServiceNow, Opsramp, JIRA

Other Security Tools: Netskope, Symantec DLP, Orca, Akamai WAF, KnowBe4, CyberArk, IBM QRadar, Splunk

Reporting Tools: Microsoft Excel, Powerpoint, Access Database, PowerBI, Neo4j

Professional Experience:

Cybersecurity Analyst - Vulnerability Management Dec 2020 - Present

Levi Strauss and Co • Westlake, TX, USA• Remote

Industry: Retail, e-commerce Textile Industry

Roles and Responsibilities:

Performing system network vulnerability scans using tools like Nessus, Qualys. Analyzing the findings and removing the false positives.

Performing penetration testing using various Kali Linux tools, listing out the loopholes, and exploiting the vulnerabilities

Performing web application vulnerability assessment using Qualys, ZAP. Analyzing the findings and removing the false positives.

Reveal information gaps that can help identify potential security threats and recommend security enhancements to mitigate the threats

Performing manual penetration testing on web applications(e-commerce sites) using Burp Suite and other manual tools for identifying deeper vulnerabilities.

Reporting the vulnerabilities generated from the tools with appropriate recommendations in order to mitigate the loopholes

Implementing policies for Web Application Firewall (Akamai WAF) to prevent applications from web attacks/bot attacks

Generating POCs for all the vulnerabilities and listing them out in a prescribed report including impact and eradication/remediation guidelines.

Conducting bug bounty programs and interacting with security researchers regarding the submissions.

Associate Information Security Engineer - II Oct 2019 - Dec 2020

HighRadiusTechnologies • Houston, TX, USA• Remote

Industry: Fintech/Financial Supply Chain Management

Roles and Responsibilities:

Performing system network vulnerability scans using tools like Nessus, Qualys. Analyzing the findings and removing the false positives.

Performing penetration testing using various Kali Linux tools, listing out the loopholes, and exploiting the host

Secure the fintech products such as Integrated Receivables Platform, Cash Application Automation, Collections Management, Deductions Management, and Credit Management used by Clients like Bank of America, Citi Bank, etc

Scheduling CIS benchmark scans for systems like web server, application server, Operating System

Performing web application vulnerability assessment using Qualys. Analyzing the findings and removing the false positives.

Performing manual penetration testing on web applications using Burp Suite and other manual tools to identify the deeper vulnerabilities apart from the low hanging fruits

Reporting the vulnerabilities generated from the tools with appropriate recommendations in order to mitigate the loopholes

Generating POCs and including steps to reproduce for all the vulnerabilities and listing them out in a prescribed report including impact and eradication/remediation guidelines.

Worked on implementing Netskope Cloud Access Security Broker(CASB) tool for shadow IT discovery and writing policies for web protection.

Worked on Symantec DLP for monitoring alerts and creating rules for protecting data like PII, PCI, HIPPA etc.

Been a part of audit meetings conducted by Risk & Compliance Team that includes providing evidences adhering to standards like ISO 27001, PCI-DSS as well as internal audits.

Associate Analyst May 2016 - Oct 2019

NetEnrich Technologies Pvt Ltd • Hyderabad, India

Industry: IT-Security Services/ MSSP

Roles and Responsibilities:

Responding to security incidents that get triggered from various network devices

Analyze network flow data for anomalies and detect malicious network activity

Administration, monitoring of security events on various SIEM platforms and investigating, documentation, reporting on true positive events and on emerging threats.

Assist with the development of processes and procedures to improve incident response times, analysis of incidents, and overall SOC functions

Exploring different threat intelligence platforms like IBM X-force, Alienvault OTX.

Providing detailed reports on contamination and eradication/remediation to clients.

Performing vulnerability assessment and penetration testing for various network devices and web applications.



Contact this candidate