Post Job Free
Sign in

Project Security

Location:
Hyderabad, India
Posted:
October 03, 2011

Contact this candidate

Resume:

Jay Kiran Kotha

H.N.-**-**-****, Saroja Nilayam, Boudha Nagar, Warasiguda, Secunderabad- 500061

E-mail: ********@*****.***

Mobile No: - +91-986******* / 929*******

OBJECTIVE

I intend to establish myself as Security Professional with an integrated business solution provider through a long time commitment, contributing to the company's growth and in turn ensuring personal growth with in the organization.

SUMMARY

Overall 4.11 years of industry experience as a Software Professional in development of both web based and network related applications.

Hands on experience in vulnerability assessment and scanning tools (Nessus, Nmap, OpenVAS, OWASP methodology, PCI DSS).

Web application security testing and physical security audits.

Developed NASL scripts for the PCI DSS v1.2 compliance and Microsoft Hotfixes.

Web Application Firewall project Installed / configured ModSecurity (with Breach rule set) as a part of PCI Compliance Project.

Identified Vulnerability Advisories on Cross-site-scripting, CSRF, Local/Remote file execution vulnerabilities

Proficient in Linux operating system configuration, utilities and programming

Security review and assessment (penetration testing, architectural analysis, code review)

Good Knowledge on Regular Expression

Experience in developing and testing snort Signatures for still secure-intrusion detection/prevention systems for protection against OWASP Top10 vulnerabilities, virus, worms and trojans, dos and ddos Vulnerabilities existing in various applications like microsoft,adobe, hp etc..,

Deep Packet level Inspection and Analysis through the aid of Wire shark.

Hands on experience on still secure-protect point security operations Center(SOC).

Strong VMWare server administration.

Excellent working knowledge of JSP, Servlets, JDBC Technologies.

Excellent working knowledge in JSF framework.

Excellent working knowledge in Jboss4.0 and Tomcat5.0 Servers.

Worked in a Team and Individually on Projects successfully.

Ability to quickly master new software and apply its full range of capabilities.

EDUCATION

M.C.A (Mater of Computer Applications) from Osmania University in the year 2006

B.C.A (Bachelor of Computer Applications) from Osmania University with 2003

TECHNICAL PROFICIENCIES

Languages : C, Java

Database : MS SqlServer 2005, MySql

Operating Systems : Windows Family, Linux (RedHat, Ubuntu, SuSe), Mac

Vulnerability Scanners : Nessus, VAM, OpenVas, Inprotect, NMap, Nikto,

CSRFTester, Paros, Brupsuit, WebInspect

Packet Sniffers : Wireshark

Servers : Apache, Wamp, Jboss 4.0, Tomcat 5.5, IIS

Technologies : JSP, Servlets and JDBC

Framework : JSF

IDE’S : Eclipse 5.5, Wing and Edit Plus

Project Management : CVS, Visual Source Safe 5.0, SVN

Scripting Languages : Nessus attack scripting language, JavaScript, Shell script

Networking concepts : TCP/IP, Firewall, VPN, Iptables

PROFESSIONAL EXPERIENCE

Working as Sr. Security Engineer for SynfoSys Business Solutions Ltd., Hyderabad from November 2006 to till date.

CERTIFICATIONS

Certified Ethical Hacker – V7 from EC-Council in Aug 2011.

PROJECT PROFILE

# Vulnerability Assessment and Management (VAM)

Client : StillSecure, USA

Environment : Windows & Linux family, Nessus, NASL

Team Size : 9

Description:

StillSecure VAM is a vulnerability management platform that includes discovery, vulnerability scanning and identification, remediation workflow and reporting tools. The platform features both scheduled and on-demand vulnerability scanning capabilities, based on known vulnerability information from the vendor that can be updated by the customer on demand and/or automatically up to once an hour.

Some of the major attacks patterns launched by exploiting the vulnerability in each application during the project:

Cross Site Scripting

SQL Injection

Denial of Service.

Cross site request forgery

Remote/Local file inclusion

Responsibilities:

Monitoring sources of security alerts, notifications, and advisories for emerging threats

In-house rule development

PCI DSS Compliance Program Implementation

Regular log analysis and finding the exploitation attempts

Quality assurance/quality control (QA/QC) for both VAM-developed rules and open-source GPL rules

Vulnerability Assessment and Penetration Testing

Auditing controls related to IT in ISO 27001 and SOX

Releasing new and updated plugins

Interacting with the client and making the changes to the product as suggested.

Miscellaneous duties as assigned

# Web Application Firewall (WAF)

Organization : SynfoSys Business Solutions Ltd. Hyderabad

Client : StillSecure

Environment : Linux, Apache server

Team size : 7

Project Details :

WAF (ModSecurity) is a web application firewall engine that provides very little protection on its own. In order to become useful, ModSecurity must be configured with rules. In order to enable users to take full advantage of ModSecurity out of the box, Breach Security, Inc. is providing a free certified rule set for ModSecurity 2.x. Unlike intrusion detection and prevention systems, which rely on signatures specific to known vulnerabilities, the Core Rules provide generic protection from unknown vulnerabilities often found in web applications, which are in most cases custom coded. The Core Rules are heavily commented to allow it to be used as a step-by-step deployment guide for ModSecurity.

Responsibilities:

Information Gathering from various security Advisories.

Developing custom and generic rules for Zero Day Vulnerabilities.

Testing them in varied environments in order to avoid any FP's and FN's

# Strata Guard – Intrusion Detection/Prevention System

Client : StillSecure, USA

Environment : Linux,SNORT,MYSQL, SNORT BASE.

Tools : Wireshark

Team Size : 3

Strata Guard is a high-speed intrusion detection/prevention system (IDS/IPS) gives you a real-time, zero-day protection from network attacks and malicious traffic,

preventing:

Malware, spyware, port scans, viruses, and DoS and DDoS from compromising hosts

Device and network outages

Data leakage

High-risk protocols, such as BitTorrent and TelNet, from running on your network

Unauthorized access to sensitive data

Strata Guard takes the powerful, open-source Snort IDS engine and makes it practical for protecting corporate-scale networks.

Responsibilities:

Information gathering from various publicly posted security advisories. Primarily focus on zero day attacks and vulnerabilities reported in commercially acclaimed products(Microsoft,Adobe,HP etc..

Testing for the existence of vulnerability(s) in an application.

Deep Packet level analysis for identifying unique signature patterns in a malicious application.

Reporting the Impact Analysis(Confidentiality,Integrity and Availability) for a vulnerable application.

Developing SNORT rules for vulnerabilities in an application per day basis.

Testing SNORT rules against the vulnerable application and also in various other non vulnerable scenarios whether the rule developed is a true positive signature and not generating False positives and False negatives.

Deploying rules into a Strata guard Production environment on twice a week basis.

Posting SNORT rules to Emerging Threats.

Reporting Rule update information to the customers.

Daily perform rule reviews over the Strata Guard- build files and tune accordingly.

# Protect Point – Security Operations Center(SOC)

Client : StillSecure-Protect Point, USA

Environment : SOC

Team Size : 3

Security Operations Center (SOC) is a secure, and feasible environment staffed by IT

Security Analysts. The analysts monitor the health, status, and availability of security

devices. They respond to anomalistic events, manage crisis/incident response, and maintain the

infrastructure that supports that role. SOC Analysts will coordinate, respond and track

mitigation of known threats while documenting new threats as they are encountered.

They will have input into process improvements assisting to identify opportunities for

Positive change, improving SOC's overall detection and response capabilities.

Responsibilities:

Assigned the role of a soc analyst to monitor the rule set existing in SOC environment. For each rule monitored create a test environment, deploy the rule and test for validity of the rule.

Determine whether a SNORT signature developed is a True Positive signature or would be generating False Positives/Negatives over a Network.

Active/inactive snort signatures monitored in the SOC Manager and reload them onto the lab

Developing, testing and deploying rules to SOC Manager on need basis.

# Financial Management System (FMS)

Client : Long Term Care Group (LTCG), USA

Environment : Java 2, Servlets, EJB2.0, XML, JSP, HTML, MS SQL Server 2000,

Jboss Server, Eclipse 3.0.

Team Size : 10

Description:

Financial Management System (FMS) is a large web based module, which eases the calculations involved in Billings and Collections of LTCG Insurance Project. FMS gets Events from LTCAS (Long Term Care Administrative Services) and prepares Billings and Collections (Receivables, Receipts and Refunds). LTCAS events (New issue, Termination of Application etc) periodically processed by FMS; appropriate files or Reports are generated and intimated to respective Policy Holders.

Responsibilities:

The system is developed using J2EE technologies based on MVC architecture.

For every module involved in the project we developed High Level Designs, Test Cases and finally the code.

Tracking the issues, and monitoring tasks.

Developing Servlets, JSP, EJB, JDBC and JavaScript.

Maintaining version-controlling system.

Customer communications through Telecom and mails.

Involved in Integration & handled all Integration related bugs and reviews.

I also had the responsibility of verifying the code according to pre defined coding standards and delivering the same to the client, which gave me a further insight into the process involved in delivery of the code.



Contact this candidate