Zurück zu den Profis

Automation Tester

Überblick


Kurzer Überblick

Der Kandidat ist ein Senior Penetration Tester, der seit über 7 Jahren in dieser Funktion in der Praxis tätig ist. Er hat Erfahrung mit Penetrationstests von mobilen, Cloud- und Web-Anwendungen. Er hat sowohl in Blue-Teams als auch in Red-Teams gearbeitet. Was die Zertifizierungen betrifft, so hat er zwei: eLearnSecuirty - Certified Web Application Penetration Tester Extreme und Certified Professional Penetration Tester Extreme. Mit den kommerziellen Tools BurpSuite und Metasploit arbeitet er und nutzt sie täglich. Er kann sich ohne Probleme auf Englisch verständigen. Bei seiner Arbeit nutzt er aktiv agile Methoden, insbesondere Scrum und Kanban. Zu seinen häufigsten Aufgaben gehören das Identifizieren und Definieren von Lücken in netz- und webbasierten Systemen sowie deren Besteuerung. Im Laufe seiner Karriere hat er außerdem mehrere Jahre lang als Sicherheitsberater für verschiedene internationale Projekte gearbeitet.

Berufliche Erfahrung

Offensive Security Researcher (Jul 2022 - Present)

  • Conduct vulnerability assessments, penetration tests, and adversarial operations to evaluate cybersecurity maturity and resiliency against attacks.
  • Perform application penetration tests to identify software security vulnerabilities in products and internal enterprise applications.
  • Collaborate with external third parties and researchers to reproduce and investigate reported issues.
  • Design and execute offensive security engagements, from planning to reporting.
  • Assess environments for security risks and misconfigurations, working with the engineering team to establish security baselines.
  • Validate and document findings, effectively communicating with stakeholders.
  • Maintain, develop, and automate new attack tactics and tools, while monitoring for new threat tactics.

Cyber Security Consultant, Penetration Tester, Technical Advisor & Programmer (Jan 2010 - Present)

  • Conduct penetration testing and vulnerability assessments on various projects.
  • Manage and secure multiple data centers remotely.
  • Perform red teaming and purple teaming assessments.
  • Reverse engineer mainly C# applications.
  • Develop web/mobile applications for clients using various programming languages.
  • Implement continuous integration and continuous development in cloud-native applications.
  • Conduct security research and participate in bug bounty programs.

Linux Security Research Consultant | Research & Development (Dec 2021 - Jun 2022)

  • Conduct research on Linux platform security aspects.
  • Implement and configure different platform security components and features.
  • Apply knowledge of Linux kernel, application, and network security.
  • Review and approve merge requests for security configurations and settings.
  • Research container and Kubernetes-specific threats and generate insights.
  • Collaborate with product and engineering teams to create new security solutions.
  • Develop best practices and security policies based on findings and automate them.

Information Security & Infrastructure Consultant (Oct 2020 - Aug 2021)

  • Implement SIEM solution using open-source tools.
  • Implement continuous monitoring solution for threat hunting using various security tools.
  • Develop and automate vulnerability assessments and penetration testing.
  • Coordinate analysis of security risks and develop action plans.
  • Monitor security incidents and take action against intrusion, fraud, and breaches.
  • Embed information security into the organization's culture.
  • Ensure compliance with security policies and standards.
  • Perform threat analysis, system checks, and security tests to identify weak points.
Author
Automation Tester
63c969b9a51aad00010e9921
Angestellter2500  / Pro Monat
Rollen
Automation Tester
Sprachen
English
Fähigkeiten
GitHubIdentity Management SoftwareIdentity and Access Management (CIAM) SoftwareKernelLinux KernelNon-Functional TestingOneLoginPenetration TestingSecurity TestingTesting Types
Lokalitäten
Brno-městoRemote