Lakshmi Gopalakrishnan
Vulnerability Assessment Analyst Application Security & Penetration Testing U.S. Citizen 518-***-**** ********.******@*****.***
Professional Summary
Security Analyst with 10+ years of Information Technology experience, including 9+ years specializing in web application security testing, API and AI security testing and vulnerability assessment. Deep working knowledge of the OWASP Web, API, and AI Top 10, and NIST 800-series frameworks. Proven track record implementing testing methodologies, integrating security into the development lifecycle, and delivering actionable remediation guidance to development and system-owner teams across federal and commercial environments.
Core Skills
Testing Methodologies: Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), network penetration testing, vulnerability scan interpretation, open source component/dependency analysis
Tools: Burp Suite, IBM AppScan, OWASP Zed Attack Proxy (ZAP), Nmap, Netsparker, SQLMap, HP Fortify, Scuba, Postman, ReadyAPI, SOAP UI, OWASP Dependency-Check, Nessus, Metasploit
Standards & Frameworks: OWASP Top 10, OWASP API Security Top 10, OWASP AI Security Top 10, NIST SP 800-53, NIST 800-series frameworks, CIS Benchmarks
Security Program Support: POA&M development, Security Impact Analysis, tabletop exercise input, continuous monitoring/ATO vulnerability management, JIRA-based defect tracking and process frameworks
Collaboration: Cross-functional coordination with development and system-owner teams, remediation guidance, secure SDLC integration, sprint-cycle security review
Work History
Vulnerability Assessment Analyst
Visual Connections Client: Department of Veterans Affairs Sep 2025 – Present
Conducted web application and API security testing using Burp Suite, OWASP ZAP, and IBM AppScan to identify OWASP Top 10 vulnerabilities, including CSRF, XSS, Clickjacking, insufficient server-side validation, Broken Authentication, and Broken Session Management.
Performed web services security testing using SOAP UI, ReadyAPI, and Postman to assess REST/SOAP API endpoints for authentication, authorization, and input validation weaknesses.
Executed infrastructure and network vulnerability scanning using Nessus and Nmap to identify exposed services, misconfigurations, and known CVEs.
Performed end-to-end DAST: identified vulnerabilities, validated findings against live application behavior, assessed business and technical risk, and delivered actionable remediation recommendations.
Partnered directly with application and system owners to drive remediation, track finding status, and verify fixes through retesting.
Served as a core member of the application security team supporting DAST and penetration testing initiatives across multiple concurrent application portfolios.
Defined, maintained, and enforced application security best practices and testing standards.
Researched emerging threats and attack vectors to maintain current knowledge of the web application security landscape.
Cyber Engineer Principal
SAIC Client: Department of Veterans Affairs Dec 2023 – Sep 2025
Served as Assistant Team Lead / WASA Tester on the VA-NSOC team, conducting web application and API assessments across VA-wide applications.
Participated in client calls with team leads to resolve application issues, address client queries, and provide ongoing support.
Partnered with the team lead to develop solutions for analyzing incoming web and API requests.
Supported team members in troubleshooting application issues and addressing testing/findings questions.
Conducted web application and API security testing using Burp Suite, ZAP, and IBM AppScan to identify OWASP Top 10 vulnerabilities, including CSRF, XSS, Clickjacking, insufficient server-side validation, Broken Authentication, and Broken Session Management.
Performed web services security testing using SOAP UI, ReadyAPI, and Postman.
Performed DAST, validated findings, assessed risk, and provided remediation recommendations in partnership with application/system owners.
Acted as a core member of the application security team supporting DAST and penetration testing efforts.
Defined, maintained, and enforced application security best practices.
Researched threats and attack vectors affecting web applications and infrastructure to stay current on the evolving threat landscape.
Evaluated and recommended additional application security tools to enhance testing capabilities.
Vulnerability Assessment Analyst
Higher Echelon Client: Department of Veterans Affairs – CSOC Jan 2023 – Nov 2023
Served as Assistant Team Lead / WASA Tester on the VA-NSOC team, conducting web application assessments across VA-wide applications.
Participated in client calls with team leads to resolve application issues and provide client support.
Partnered with the team lead to develop solutions for analyzing incoming web/API requests.
Supported team members in troubleshooting application issues and testing questions.
Conducted web application and API security testing using Burp Suite, ZAP, and IBM AppScan to identify OWASP Top 10 vulnerabilities.
Performed web services security testing using SOAP UI, ReadyAPI, and Postman.
Performed DAST, validated findings, assessed risk, and delivered remediation recommendations.
Defined, maintained, and enforced application security best practices.
Researched threats and attack vectors, and evaluated additional tools to strengthen security testing capabilities.
Operations Security Engineer
ASM Research Fairfax, VA Client: Department of Veterans Affairs – CSOC Oct 2019 – Oct 2022
Served as a contractor on the VA-NSOC team conducting web application assessments across VA-wide applications.
Conducted web application and API security testing using Burp Suite, ZAP, and IBM AppScan to identify OWASP Top 10 vulnerabilities.
Performed web services security testing using SOAP UI, ReadyAPI, and Postman.
Performed DAST, validated findings, assessed risk, and delivered remediation recommendations.
Defined, maintained, and enforced application security best practices.
Researched threats and attack vectors, and evaluated additional tools to strengthen security capabilities.
Web Application Security Analyst
CGI Federal Fairfax, VA Jan 2017 – Sep 2019
Performed application penetration testing for a range of federal and commercial clients.
Conducted manual DAST web application testing using Burp Suite, ZAP, and IBM AppScan to identify OWASP Top 10 vulnerabilities.
Conducted SAST using HP Fortify along with manual code walkthroughs and reviews.
Prepared final security assessment reports with detailed findings and remediation guidance as client deliverables.
Performed web services security testing using SOAP UI, ReadyAPI, and Postman.
Conducted vulnerability scanning using Nessus and open source component analysis using OWASP Dependency-Check.
Performed mobile security testing for Android and iOS applications.
Applied additional tools including Nmap, Scuba, and SQLMap as needed.
Supported vulnerability management, reporting, and continuous monitoring for ATO processes.
Conducted penetration testing of AWS-hosted applications and evaluated configurations against CIS Benchmark controls.
Provided security best-practice guidance to development teams and participated in sprint cycles to review new functionality and provide early security feedback.
Logged and managed defects using JIRA; assessed and developed JIRA customization frameworks across applications.
Researched threats, attack vectors, and security control implementation affecting web applications and infrastructure.
Quality Analyst
Accenture India Oct 2004 – Dec 2005
Conducted process-related SQA audits for applications, including tollgate reviews.
Conducted SOX audits tailored to client requirements and ensured process adherence.
Reported project-level quality metrics to the Quality Organization.
Quality Analyst
Ivesia Solutions India May 2002 – Sep 2004
Participated in CMM IPA assessments supporting the organization's SEI CMM Level 3 certification.
Interacted with project teams across all phases as SQA representative and conducted reviews of project artifacts.
Identified process deviations, proposed solutions, contributed to process tailoring, and conducted periodic project audits.
Education
M.B.A. (2000–2002)
B.S., Mathematics (1996–1999)
Certifications
Certified Ethical Hacker (CEH) — Dec 2023
Project Management Professional (PMP) — June 2018
Citizenship
U.S. Citizen