Senior Consultant Resume Profile
2.00/5 (Submit Your Rating)
Background
- Overall experience of 8 years and 2 months in Information Security
- Exhaustive experience in performing application web, thick client and mobile security assessments. Have performed over 100 application security assessments
- Exhaustive knowledge on OWASP Top 10 and OWASP Top 10 Mobile risks. Have assisted in authoring the Web Based Application Security FAQs for OWASP.org
- Well versed with network including wireless penetration testing and vulnerability assessments
- Experienced in Cyber Threat Intelligence diagnostic
- Led projects on Mobile Device Management MDM , Data Leakage Prevention DLP , Security Information and Event Management SIEM and Role Based Access Control RBAC
- Experienced in application development, customization, etc. with RSA Archer eGRC
- Good experience in performing vendor security risk assessments. Have performed 38 vendor risk assessments
- Experienced on standards like Payment Card Industry-Data Security Standard PCI DSS and ISO 27001
- Involved in various Pen Test, Code Review, App Sec related pre-sales activities
Experience
Confidential
- Information Security Architect
- Project manager for Mobile Device Management project
- Responsible for establishing information security best practices and controls throughout the organization
- Leading the PCI DSS compliance team, and part of ISO 27001 readiness team.
Confidential
Senior Consultant
Engaged in performing thick and thin client application security assessments Responsible for conducting manual and automated security assessments on a variety of applications off the shelf, web based, thick client, mobile apps for a big Australian organization Engaged in cyber threat assessments Involved in external and internal Cyber Threat Intelligence CTI diagnostics
Confidential
- Practice Consultant
- RSA Archer eGRC Application Development and Customization
- Vendor Security Risk Assessment
- PCI DSS, HIPAA compliance
- SIEM RSA enVision and HP Arcsight
- Pre-sales activities related to VA and PT engagements
- Practice development related activities
Confidential
- Senior Information Security Risk Analyst
- Web Application Security testing
- Network vulnerability assessment and penetration testing
- HSBC Group wide Data Leakage Prevention DLP and Role Based Access Control RBAC projects
- Secure Coding and Information Security Awareness trainings
- Training security resources in HSBC Guangzhou, China