Back to professionals

Automation Tester

Overview


Short Summary

The candidate is a Senior Penetration Tester who has been in this role for over 7 years in commercial practice. He has experience in penetration testing of mobile, cloud and web applications. He has also worked in both Blue teams and Red teams. As far as certifications are concerned, he holds two namely - eLearnSecuirty - Certified Web Application Penetration Tester Extreme and Certified Professional Penetration Tester Extreme. From the commercial tools BurpSuite and Metasploit, he works and uses them on a daily basis. He can communicate in English without any problems. He actively uses agile methodologies in his work, especially Scrum and Kanban. His most common tasks include identifying and defining, taxing and missing in network and web-based systems. He has also worked as a Security Consultant for several years during his career for several international projects.

Work Experience

Offensive Security Researcher (Jul 2022 - Present)

  • Conduct vulnerability assessments, penetration tests, and adversarial operations to evaluate cybersecurity maturity and resiliency against attacks.
  • Perform application penetration tests to identify software security vulnerabilities in products and internal enterprise applications.
  • Collaborate with external third parties and researchers to reproduce and investigate reported issues.
  • Design and execute offensive security engagements, from planning to reporting.
  • Assess environments for security risks and misconfigurations, working with the engineering team to establish security baselines.
  • Validate and document findings, effectively communicating with stakeholders.
  • Maintain, develop, and automate new attack tactics and tools, while monitoring for new threat tactics.

Cyber Security Consultant, Penetration Tester, Technical Advisor & Programmer (Jan 2010 - Present)

  • Conduct penetration testing and vulnerability assessments on various projects.
  • Manage and secure multiple data centers remotely.
  • Perform red teaming and purple teaming assessments.
  • Reverse engineer mainly C# applications.
  • Develop web/mobile applications for clients using various programming languages.
  • Implement continuous integration and continuous development in cloud-native applications.
  • Conduct security research and participate in bug bounty programs.

Linux Security Research Consultant | Research & Development (Dec 2021 - Jun 2022)

  • Conduct research on Linux platform security aspects.
  • Implement and configure different platform security components and features.
  • Apply knowledge of Linux kernel, application, and network security.
  • Review and approve merge requests for security configurations and settings.
  • Research container and Kubernetes-specific threats and generate insights.
  • Collaborate with product and engineering teams to create new security solutions.
  • Develop best practices and security policies based on findings and automate them.

Information Security & Infrastructure Consultant (Oct 2020 - Aug 2021)

  • Implement SIEM solution using open-source tools.
  • Implement continuous monitoring solution for threat hunting using various security tools.
  • Develop and automate vulnerability assessments and penetration testing.
  • Coordinate analysis of security risks and develop action plans.
  • Monitor security incidents and take action against intrusion, fraud, and breaches.
  • Embed information security into the organization's culture.
  • Ensure compliance with security policies and standards.
  • Perform threat analysis, system checks, and security tests to identify weak points.
Author
Automation Tester
63c969b9a51aad00010e9921
Employee2500  / Per month
Roles
Automation Tester
Languages
English
Skillset
GitHubIdentity Management SoftwareIdentity and Access Management (CIAM) SoftwareKernelLinux KernelNon-Functional TestingOneLoginPenetration TestingSecurity TestingTesting Types
Localities
Brno-městoRemote