Penetration Tester with a strong background in software engineering. Over 10+ years experienced in Mobile Apps (Android/iOS) and Web Vulnerability Assessments / Penetration Tests.Expertise include the following:-Vulnerability assessment and penetration testing (VAPT) of mobile applications (Android/iOS)-> White/black box, automated/manual methods, static/dynamic analysis, source code analysis, Malware analysis, OWASP Top 10-> Tools: Burpsuite, Objection, Frida, Genymotion, QARK, MobSF, Drozer, RMS, idb, cycript, Cydia Impactor, Passion Fruit, IDA Pro-> Practice platforms: INE security, DIVA, Insecure bank, kgb messenger, portswigger.net/web-security academy-> Concepts: JavaScript, XML, SOAP, REST, etc.-> Methods: Bypass SSL Pinning, Jailbreak detection, root detection and Emulator detection-> More than 500 apps tested including both android & iOSVulnerability assessment and penetration testing (VAPT) of web applications-> White/black box, automated/manual methods, source code analysis, OWASP-> Tools: Acunetix, HP-Fortify, OWASP-Zap, Nikto, BeEF, Burp-Suite, SQLMAP-> Practice platforms: INE security, hackthebox, vulnhub, , tryhackme, pentester lab, portswigger.net/web-security academy, exploitdb-> concepts: JavaScript, XML, SOAP, REST, AJAX, etc.-> more than 50 websites testedISO Internal Auditor and Risk Analyst-> Prepare and execute ISO/IEC 27001:2013 internal audits for business units.-> Create ISO/IEC 27001 internal audit reports in accordance with ISO/IEC 27001 requirements& internal processes.-> Monitors, analyses and remediates IT security risks and vulnerabilities by adhering todefined operating procedures.-> Reviewing to identify outliers, inefficiencies and non-standard actions.-> Prepare and conduct Security Risk & Threat Assessment for business units with occasionalsupport to vendor assessment team with the vendor selection process, ensuring complianceto vendor contracts.-> Create Risk Assessment Report, identifying improvement opportunities & providingfeedback to team members and management.-> Supports the implementation of security governance by leading the process of governanceadministration and maintenance. Also ensuring compliance with information securitypolicies, standards, procedures and best practices.-> Built relationship and partnership with key stakeholders, aligning business needs withprocesses and practices while monitoring progress and results.-> Recognized & capitalized on improvement opportunities while adapting to competingdemands, organizational changes and new responsibilities.
Listed skills include Java, Javascript, C#, Mysql, and 14 others.