Application Penetration Tester
Current* Conducted Google Partner Security Assessments, both retesting current partners and perspective Google partners.* Performed Application Penetration Tests on many high-profile web applications. Found numerous critical, high and medium vulnerabilities.* Proficient in understanding application level vulnerabilities like XSS, SQL Injection, CSRF, authentication bypass, cryptographic attacks, authentication flaws etc.* Created professional vulnerability reports to be delivered to Google and sites within the Alexa top 500* Security testing of APIs utilizing protocols such as SOAP, JSON, REST and XML. This includes popular frameworks such as Django, Ruby, Flask, * ASP.NET, jQuery, Angular, Bootstrap and many other custom or commercial frameworks.* Extremely proficient with Burp Suite Pro, proficient in various tools/frameworks, and creating custom tools.* Frequently utilized reporting platforms such as Dradis. Used and modified custom macro’s for report writing* Conducted onsite network penetration tests from an insider/outsider threat perspective.* Utilized tools such as Cobalt Strike, Bloodhound and responder to pull NTLM hashes, crack or “pass the hash” to other specified targets. CS beacons would be deployed once a foothold was obtained.* Recognized by for 6 zero Day findings (two combined into CVE-2016-9091), including a severe RCEs, stored XSS and CSRF. CVE’s CVE 2019-9507, 2019-9508, 2019-9509 and CVE-2016-9091 were assigned for said findings* Recognized for rooting both FireEye and BlueCoat appliances (referenced in 2016-9091)