Application Security Consultant
CurrentPerform DAST using Burp Suite pro and OWASP ZAP. Implemented Cloud Threat Modeling in Azure. Identify Vulnerabilities through test, system design review or code analysis. Provide the root cause for identified vulnerabilities and generate report. Work on creating strong documentation for identified and repeatable tasks. Perform manual web application penetration tests on both internal and external systems to identify vulnerabilitiessuch as those listed in the Open Web Application Project (OWASP) top 10. Participate in Project meetings and provide specifications deliverables in coordination with Omron team Architectsand Management teams. Implemented Azure Cloud Governance for Azure Resources and Azure Active Directory components. Generated executive summary reports showing the security assessments results, recommendations and riskmitigation plans and presented them to the respective business sponsors and senior management. Worked with DevOps teams to automate security scanning into the build process. Reviewed Android and iOS mobile source code manually and recommended code fixes. Participated in the Proof ofConcept (POC) in implementing Arxan application protection software for Mobile apps. Analyzed security incidents originated from various network/application monitoring devices (e.g., Symantec VontuDLP) and coordinated with Engineering teams for tracking and problem escalation, including remediation. Performed the penetration testing of mobile (Android and iOS) applications, specifically, APK reverse engineering,traffic analysis and manipulation, dynamic runtime analysis.