Automation Tester & IT Security Consultant
Prehľad
Krátke zhrnutie
Kandidát je penetračný tester, ktorý na tejto pozícii pôsobí už takmer dva a pol roka v komerčnej praxi. Medzi jeho hlavné úlohy patrilo testovanie webových aplikácií, internej infraštruktúry prostredníctvom Active directory, testovanie mobilných aplikácií, ale nie je tam úplne doma, vytvára testy zraniteľnosti a hardvérové testy u klientov. Často cestoval za klientmi, takže s tým má skúsenosti. V oblasti IT bezpečnosti pracuje od roku 2015 (predtým bol programátorom. ale to už nechce robiť), kde zastával pozície bezpečnostného analytika a bezpečnostného inžiniera Devops. Pri svojej práci aktívne využíva agilné metodiky, najmä Scrum a Kanban. Bez problémov komunikuje v angličtine a pracoval v medzinárodných tímoch.
Pracovné skúsenosti
Penetration Tester (November 2020 - present): Conducted penetration testing on web applications, internal and external infrastructure, and client stations. Also performed server hardening and audits of mobile applications. Identified and reported vulnerabilities in web applications through bug bounty programs.
DevOps Security Engineer (March 2019 - February 2020): Maintained a Security Incident Response Platform, including CI/CD deployment on a Kubernetes cluster. Integrated with existing logging, monitoring, and vulnerability scanning solutions. Developed internal services using Python and Bash. Conducted penetration testing of web services.
Security Analyst (July 2018 - February 2019): Analyzed platforms for vulnerabilities in Red Hat Enterprise Linux. Documented vulnerabilities and verified fixes. Communicated with upstream and contributed to open-source software. Conducted security source code audits.
Security Analyst (July 2018 - February 2019): Analyzed platforms for vulnerabilities in Red Hat Enterprise Linux. Documented vulnerabilities and verified fixes. Communicated with upstream and contributed to open-source software. Conducted security source code audits.
Security Response Specialist (July 2015 - June 2018): Monitored various resources for security-related information. Performed initial analysis of security issues and conducted security source code audits. Developed internal tooling using Python.
Software Developer (October 2014 - April 2015): Programmed computer forensic tools, including filesystem analysis software in Java and preprocessing modules in Python. Scripted remote system information extraction software in Bash.
Programmer (internship) (July 2013): Developed a client-server application for secure accounting, including client application in Java, server application in PHP, and user application for Android.
Master's Degree in Information Technology Security (2012 - 2016): Specialized in network intrusion detection based on statistical protocol identification. Completed Erasmus study at the University of Vienna, specializing in Business Informatics.
Bachelor's Degree in Computer Systems and Data Processing (2009 - 2012): Specialized in cryptographic pairing schemes.
Certifications & Trainings: Offensive Security Certified Professional (OSCP), NotSoSecure Advanced Infrastructure Hacking, Mastering BurpSuite Pro, Malware Development in Windows, Red Hat Certified Engineer (expired), Red Hat Certified System Administrator (expired), Red Hat Certified Specialist in Ansible Automation (expired).
Personal Skills: Fluent in Slovak. Proficient in English (B2 level) and basic knowledge of German (A2 level). Advanced knowledge in application security, infrastructure security, Active Directory, Linux and Windows security, and AV.
| Zamestnanec | 3500 € / Mesačne |
| Kontraktor | 275 € / Denne |
| Úroveň | MEDIOR |