Automation Tester
Přehled
Krátké shrnutí
Kandidát je seniorní penetrační tester, který tuto pozici zastává již více než 7 let v komerční praxi. Má zkušenosti s penetračním testováním mobilních, cloudových a webových aplikací. Pracoval také v modrých i červených týmech. Co se týče certifikací, je držitelem dvou, a to eLearnSecuirty - Certified Web Application Penetration Tester Extreme a Certified Professional Penetration Tester Extreme. Z komerčních nástrojů pracuje a denně používá BurpSuite a Metasploit. Bez problémů se domluví anglicky. Při své práci aktivně využívá agilní metodiky, zejména Scrum a Kanban. Mezi jeho nejčastější úkoly patří identifikace a definice, taxace a chybějící v síťových a webových systémech. Během své kariéry pracoval několik let také jako bezpečnostní konzultant pro několik mezinárodních projektů.
Pracovní zkušenosti
Offensive Security Researcher (Jul 2022 - Present)
- Conduct vulnerability assessments, penetration tests, and adversarial operations to evaluate cybersecurity maturity and resiliency against attacks.
- Perform application penetration tests to identify software security vulnerabilities in products and internal enterprise applications.
- Collaborate with external third parties and researchers to reproduce and investigate reported issues.
- Design and execute offensive security engagements, from planning to reporting.
- Assess environments for security risks and misconfigurations, working with the engineering team to establish security baselines.
- Validate and document findings, effectively communicating with stakeholders.
- Maintain, develop, and automate new attack tactics and tools, while monitoring for new threat tactics.
Cyber Security Consultant, Penetration Tester, Technical Advisor & Programmer (Jan 2010 - Present)
- Conduct penetration testing and vulnerability assessments on various projects.
- Manage and secure multiple data centers remotely.
- Perform red teaming and purple teaming assessments.
- Reverse engineer mainly C# applications.
- Develop web/mobile applications for clients using various programming languages.
- Implement continuous integration and continuous development in cloud-native applications.
- Conduct security research and participate in bug bounty programs.
Linux Security Research Consultant | Research & Development (Dec 2021 - Jun 2022)
- Conduct research on Linux platform security aspects.
- Implement and configure different platform security components and features.
- Apply knowledge of Linux kernel, application, and network security.
- Review and approve merge requests for security configurations and settings.
- Research container and Kubernetes-specific threats and generate insights.
- Collaborate with product and engineering teams to create new security solutions.
- Develop best practices and security policies based on findings and automate them.
Information Security & Infrastructure Consultant (Oct 2020 - Aug 2021)
- Implement SIEM solution using open-source tools.
- Implement continuous monitoring solution for threat hunting using various security tools.
- Develop and automate vulnerability assessments and penetration testing.
- Coordinate analysis of security risks and develop action plans.
- Monitor security incidents and take action against intrusion, fraud, and breaches.
- Embed information security into the organization's culture.
- Ensure compliance with security policies and standards.
- Perform threat analysis, system checks, and security tests to identify weak points.
| Zaměstnanec | 60850 Kč / Měsíčně |