Späť na profesionálov

Automation Tester

Prehľad


Krátke zhrnutie

Kandidát je seniorný penetračný tester, ktorý pôsobí na tejto pozícii už viac ako 7 rokov v komerčnej praxi. Má skúsenosti s penetračným testovaním mobilných, cloudových a webových aplikácií. Pracoval tiež v modrých aj červených tímoch. Čo sa týka certifikátov, je držiteľom dvoch, a to eLearnSecuirty - Certified Web Application Penetration Tester Extreme a Certified Professional Penetration Tester Extreme. Z komerčných nástrojov BurpSuite a Metasploit pracuje a používa ich na dennej báze. Bez problémov dokáže komunikovať v angličtine. Pri svojej práci aktívne využíva agilné metodiky, najmä Scrum a Kanban. Medzi jeho najčastejšie úlohy patrí identifikácia a definovanie, taxovanie a chýbanie v sieťových a webových systémoch. Počas svojej kariéry niekoľko rokov pracoval aj ako bezpečnostný konzultant pre viaceré medzinárodné projekty.

Pracovné skúsenosti

Offensive Security Researcher (Jul 2022 - Present)

  • Conduct vulnerability assessments, penetration tests, and adversarial operations to evaluate cybersecurity maturity and resiliency against attacks.
  • Perform application penetration tests to identify software security vulnerabilities in products and internal enterprise applications.
  • Collaborate with external third parties and researchers to reproduce and investigate reported issues.
  • Design and execute offensive security engagements, from planning to reporting.
  • Assess environments for security risks and misconfigurations, working with the engineering team to establish security baselines.
  • Validate and document findings, effectively communicating with stakeholders.
  • Maintain, develop, and automate new attack tactics and tools, while monitoring for new threat tactics.

Cyber Security Consultant, Penetration Tester, Technical Advisor & Programmer (Jan 2010 - Present)

  • Conduct penetration testing and vulnerability assessments on various projects.
  • Manage and secure multiple data centers remotely.
  • Perform red teaming and purple teaming assessments.
  • Reverse engineer mainly C# applications.
  • Develop web/mobile applications for clients using various programming languages.
  • Implement continuous integration and continuous development in cloud-native applications.
  • Conduct security research and participate in bug bounty programs.

Linux Security Research Consultant | Research & Development (Dec 2021 - Jun 2022)

  • Conduct research on Linux platform security aspects.
  • Implement and configure different platform security components and features.
  • Apply knowledge of Linux kernel, application, and network security.
  • Review and approve merge requests for security configurations and settings.
  • Research container and Kubernetes-specific threats and generate insights.
  • Collaborate with product and engineering teams to create new security solutions.
  • Develop best practices and security policies based on findings and automate them.

Information Security & Infrastructure Consultant (Oct 2020 - Aug 2021)

  • Implement SIEM solution using open-source tools.
  • Implement continuous monitoring solution for threat hunting using various security tools.
  • Develop and automate vulnerability assessments and penetration testing.
  • Coordinate analysis of security risks and develop action plans.
  • Monitor security incidents and take action against intrusion, fraud, and breaches.
  • Embed information security into the organization's culture.
  • Ensure compliance with security policies and standards.
  • Perform threat analysis, system checks, and security tests to identify weak points.
Author
Automation Tester
63c969b9a51aad00010e9921
Zamestnanec2500  / Mesačne
Role
Automation Tester
Jazyky
English
Zručnosti
GitHubIdentity Management SoftwareIdentity and Access Management (CIAM) SoftwareKernelLinux KernelNon-Functional TestingOneLoginPenetration TestingSecurity TestingTesting Types
Lokality
Brno-městoRemote