Zpět na profesionály

Automation Tester

Přehled


Krátké shrnutí

Kandidát je seniorní penetrační tester, který tuto pozici zastává již více než 7 let v komerční praxi. Má zkušenosti s penetračním testováním mobilních, cloudových a webových aplikací. Pracoval také v modrých i červených týmech. Co se týče certifikací, je držitelem dvou, a to eLearnSecuirty - Certified Web Application Penetration Tester Extreme a Certified Professional Penetration Tester Extreme. Z komerčních nástrojů pracuje a denně používá BurpSuite a Metasploit. Bez problémů se domluví anglicky. Při své práci aktivně využívá agilní metodiky, zejména Scrum a Kanban. Mezi jeho nejčastější úkoly patří identifikace a definice, taxace a chybějící v síťových a webových systémech. Během své kariéry pracoval několik let také jako bezpečnostní konzultant pro několik mezinárodních projektů.

Pracovní zkušenosti

Offensive Security Researcher (Jul 2022 - Present)

  • Conduct vulnerability assessments, penetration tests, and adversarial operations to evaluate cybersecurity maturity and resiliency against attacks.
  • Perform application penetration tests to identify software security vulnerabilities in products and internal enterprise applications.
  • Collaborate with external third parties and researchers to reproduce and investigate reported issues.
  • Design and execute offensive security engagements, from planning to reporting.
  • Assess environments for security risks and misconfigurations, working with the engineering team to establish security baselines.
  • Validate and document findings, effectively communicating with stakeholders.
  • Maintain, develop, and automate new attack tactics and tools, while monitoring for new threat tactics.

Cyber Security Consultant, Penetration Tester, Technical Advisor & Programmer (Jan 2010 - Present)

  • Conduct penetration testing and vulnerability assessments on various projects.
  • Manage and secure multiple data centers remotely.
  • Perform red teaming and purple teaming assessments.
  • Reverse engineer mainly C# applications.
  • Develop web/mobile applications for clients using various programming languages.
  • Implement continuous integration and continuous development in cloud-native applications.
  • Conduct security research and participate in bug bounty programs.

Linux Security Research Consultant | Research & Development (Dec 2021 - Jun 2022)

  • Conduct research on Linux platform security aspects.
  • Implement and configure different platform security components and features.
  • Apply knowledge of Linux kernel, application, and network security.
  • Review and approve merge requests for security configurations and settings.
  • Research container and Kubernetes-specific threats and generate insights.
  • Collaborate with product and engineering teams to create new security solutions.
  • Develop best practices and security policies based on findings and automate them.

Information Security & Infrastructure Consultant (Oct 2020 - Aug 2021)

  • Implement SIEM solution using open-source tools.
  • Implement continuous monitoring solution for threat hunting using various security tools.
  • Develop and automate vulnerability assessments and penetration testing.
  • Coordinate analysis of security risks and develop action plans.
  • Monitor security incidents and take action against intrusion, fraud, and breaches.
  • Embed information security into the organization's culture.
  • Ensure compliance with security policies and standards.
  • Perform threat analysis, system checks, and security tests to identify weak points.
Author
Automation Tester
63c969b9a51aad00010e9921
Zaměstnanec60850  / Měsíčně
Role
Automation Tester
Jazyky
English
Dovednosti
GitHubIdentity Management SoftwareIdentity and Access Management (CIAM) SoftwareKernelLinux KernelNon-Functional TestingOneLoginPenetration TestingSecurity TestingTesting Types
Lokality
Brno-městoRemote