Senior Security Consultant / Research Team Lead
Boston, Massachusetts, Us
Primary Technologies: burp, nessus, nmap, kali, metasploit, powershell, golang, python, android, ios• Led and participated in dozens of engagements for a variety of clients in the financial, media, medical and telecommunications sectors, among others. Engagements included: network, mobile and application penetration testing, code review, reverse engineering and social engineering.• Performed manual penetration testing leveraging tools such as Nessus and Burp Proxy with an emphasis on understanding customer business rules and manually exploiting them. Very little of the testing process was automated. Additionally, testing occasionally presented constraints such as only having access to what was installed on a customer's workstation; cases like these led to using unconventional tools like Powershell as an important part of certain assessments.• Wrote custom tools in a variety of languages such as Python and Go as part of penetration testing assessments in order to adapt to unique targets and environments. Sample tools included a custom CnC server/client embedded in a customer's environment to avoid IDS detection or antivirus scans and an implementation of a customer-written protocol to exploit weaknesses in its design. • Ongoing research projects on industry-relevant information security topics, including: smart locks and mobile in-app purchases.