Cybersecurity Penetration Tester Senior
CurrentConsulted as a member of the computer forensics team during incident response requests and provide clients with detailed forensic analysis of aggregated network logs, Windows and Linux event logs, cloud-based applications and email collection. Assisted CLA's financial forensics team by providing technical services when needed (email capture, hard drive acquisition, transferring data to eDiscovery platforms). Processed and stored case data in a forensically sound manner such as adhering to chain of custody and creating working copies of forensic data. Became the technical lead on computer forensic matters in Summer 2023. Consult and perform internal and external penetration tests against a variety of clients from banks and credit unions, to higher education and local municipalities across the United States. Performed customized simulated email phishing attacks and customized simulated phone phishing (vishing) attacks against clients. Assess cloud infrastructure such as Microsoft 365, Google Suite, and AWS against CIS recommendations and provide prioritized findings for our clients. Compose detailed findings reports for our clients and be able to discuss technical insecurities with IT and management. Utilize and customize a variety of in-house tools written in bash, Python, and Node.js alongside with industry standard tools such as Tenable Nessus for assessing a client's vulnerabilities. Utilize a Unix terminal daily to perform assessments and penetration tests. Maintain custom web domains and administrate Unix and web servers within the cloud for assessments. Sought out and utilized custom data analytic frameworks to assist in providing clients with concise details for vulnerabilities discovered.Maintain a custom assessment software written in Python. Assist fellow penetration testing associates within our technical team for success and seamless integrations with our clients.