Sasmithabanu

Download as docx, pdf, or txt
Download as docx, pdf, or txt
You are on page 1of 4

Sasmithabanu

Mobile: +6596343558

Senior Security Consultant Email:sasmitha.banu13@gmail.com

Career Objective

 To achieve a benchmark in Information Security, Risk and Compliance with my knowledge, skills, and applying them
in an effective manner which would benefit me and my organization.
 Always open for learning new concepts, working well under pressure, and communicating ideas clearly and
effectively.
 Expertise in handling various security appliances, security threats, consulting services (Application Security,
Penetration Test, Vulnerability Assessment, Technical Audit), Security awareness trainer.
Professional Experience — 6.5 years
Functional Area
 Application Security (Black Box, Grey Box)
 Mobile Application Security(lOS and Android)
 OWASP Top 10
 SANS Top 25
 Network Penetration Testing
 Wireless Penetration Testing
 ISMS Audits
 Security Configuration Audits
 Phishing Campaign
 IT Audits (MAS Compliance)
 Risk Management
 Resource Management within the team

1. Ensign Infosecurity (Formerly known as "Quann Asia pacific Pte Ltd"), Singapore
July 2017 to Present

— Senior Security Consultant and Project Lead


Key Projects:
 Internal and External VAPT for Web applications and Networks.
 Wireless Penetration Testing
 Phishing Campaign
 Hardening Configuration Review for firewall, network devices, OS and
databases.
 Mobile application testing for various platforms like IOS, Android.
 Cyber Security Framework and IT security Policies
 IT Audits
 Kick-off meetings
 Manage projects and coordinate with clients.
Tools Used:
 Nexpose
 Nessus
IBM App scan
 Netsparker
 Burp Suite
 Nmap
 Qualys guard
 Phishme Clients:
 Government sector
Summary
 External network penetration testing and web application penetration testing to assess vulnerabilities as
seen by a layman.
 Mobile application penetration testing for Android and IOS application to assess vulnerabilities.
 Wireless Penetration Testing
 Performed in depth analysis of the firewall rules and configuration.
 Provided a comprehensive report on the identified vulnerabilities and action items to mitigate them.
 Provided a comprehensive report on the identified vulnerabilities and action items to mitigate them. Also
meet with the application owner to explain the vulnerabilities
 Performed threat modeling manually as per OWASP Top 10 & SANS Top 25.
 Reasoning out the appropriate test cases to the threats identified in the application and execute generic
and business logic test cases as per the Threat Profile.
 Conduct Phishing campaign and conduct phishing awareness training and quiz
 Performed in depth analysis Of the existing IT policies and modified according to the TRM requirements.
 Lead projects from kick off meeting to the final delivery of the project.
 Manage a team of 4 consultants

2. SysNet Systems and Solutions, Singapore April 2015 to June 2017

— Senior Network Specialist


Key Projects:
 External Network Penetration Test for various application servers and database servers
 Mobile application testing for various platforms like IOS, Android.
 Firewall Rule base Analysis for various firewalls
 Application Security testing for a Banking application.
 Cyber Security Framework and IT security Policies
 IT Audits
 MAS Compliance to Fl's
 ABS (OSPAR) Audits
 Incident Management framework and cyber security policy
 Assisting an insurance company with the IT audits and handling the day to day security related works
including firewall log and MacAfee log monitoring.
 Symantec DLP Policy creation (Monitoring and detection rules)
Clients:
 Banking and Finance sector
 E-Commerce
Summary
 External network penetration testing to assess vulnerabilities as seen by a layman.
 Mobile application penetration testing for Android and IOS application to assess vulnerabilities.
Provided a comprehensive report on the identified vulnerabilities and action items to mitigate them.
 Performed in depth analysis of the firewall.
 Provided comprehensive report on findings and action items to fix the identified vulnerabilities.
 Understanding the data flow in the application.
 Conducting discussions with the application owners in order to understand the application.
 Reasoning out the appropriate test cases to the threats identified in the application.
 Executing generic and business logic test cases as per the Threat Profile.
 Providing a comprehensive report on the identified vulnerabilities and action items in order to mitigate
them.
 Application security audit of the application.
 Performed in depth analysis Of the existing IT policies and modified according to the TRM requirements.
 Handling day to day security activities and reporting the same to the IT manager (Firewall logs, MacAfee
logs, policy creation and any other breaches)
 Prepared ABS OSPAR document in line with the auditor's guidelines for my current organization.

3. Paladion Networks, Bangalore, India November 2012 to April 2015 — Security Analyst
Key Projects:
 Internal and External Application Security Testing for various sectors (banking, insurance, health, e-
commerce etc.,).
 Mobile Application Testing for banking applications.
 API testing for a banking applications.
 Vulnerability Assessment and Network level Penetration Testing.
 External Network Penetration Test for various application servers and database servers.
 Network Penetration Testing, Vulnerability Assessment Of Critical Servers/Devices and Application Security
Assessment of applications hosted on these servers.
 Firewall Rule base Analysis for various firewalls.
Summary
 Daily Meeting with Onshore leads to discuss on progress/issues.
 Resource management.
 Assigning task to team members.
 Review Test Plan, Assessment Report and provide feedback.
 Identified vulnerabilities, recommend corrective measures and ensure the adequacy of existing
information security controls.
 Educated business unit managers, IT development team, and the user community about risks and security
controls.
 Expertise in open source port scanning tools.
 Performed threat modeling manually as per OWASP Top 10 & SANS Top 25.
 Prepared detail practices and procedures on technical processes.
 Conducted onsite penetration tests from an insider threat perspective.
 Performed host, network, and web application penetration tests.
 Performed Mobile and API (Thick client) application testing.
 Performed network security analysis and risk management for designated systems
 Developed Security Assessment Plan, Security Assessment Report, Security Assessment Questionnaire,
Rules Of engagement, Kick off Brief, and Exit Brief templates
 Perform peer reviews of Security Assessment Reports (SAR)s
 Established security test strategies.
 Daily use of NeXpose, Nessus, Metasploit Pro and Burp Suite Pro.
Clients
 Remote support for US and UK clients from various fields (banks, consumer goods, online market).
 Most of the Middle East financial sectors.
 Onsite support for South East Asia's leading bank.
Education
 B.Tech in Information Technology from SNS College Of Engineering, Coimbatore, TamilNadu (CGPA —8.45)
 2012 12th Standard from Mount Zion Matriculation Higher Sec. School, Pudukkottai, TamilNadu (Score —
78% ) 2008
 10th Standard from Vairams Matriculation Higher Sec. School, Pudukkottai, TamilNadu (Score — 78% ) 2006
Certifications
 Certified Ethical Hacker (C EH) V8
 Pursuing CISSP
Achievements at Workplace
 Received the "Paladion Silver Star" award twice for various contributions in project.
 Provided Knowledge-Transfer sessions to onshore team, new joiners on various functionalities.
 Suggested Process Improvement ideas which helped lot of savings in terms Of cost and time.
Personal Details
Date of birth 13th March 1991
Gender Female
Nationality Indian
Marital Status Single
Contact Address BLk 341, #02-1502, Jurong East Avenue 1, Singapore-600341
Languages Tamil, English.
Extra-Curricular Activities Badminton, Craft works, Listening to music, Travelling,.
I hereby declare that the above-furnished information is true to the best Of my knowledge.

Sasmithabanu M

You might also like