Strong technical background covering industry standards and frameworks like ISO/IEC 27001, and MITRE ATT&CK; dynamic and results-driven application security analyst. Competent in carrying out security reviews throughout the software development lifecycle, guaranteeing unwavering adherence to rules and guidelines. Seasoned in overseeing and arranging penetration tests, secure code reviews, and vulnerability assessments for a range of applications, including cloud-based, mobile, and web-based ones. Skilled at simplifying procedures and strengthening early security control gates while incorporating security controls into development pipelines.
Industry Standards/ Frameworks: ISO/IEC 27001, PCI, SOC1 & SOC2, PCI SSC, ITIL, MITRE ATT&CK, OSI, NIST CSF, OWASP, SSDLC
Operating Systems: Windows, Linux, Mac OS
Database Engines: PostgreSQL, MySQL, SQL Server
Query Languages: KQL, SQL, Cypher
Programming Languages: HTML, CSS, Javascript, Python, VHDL
Internet Protocols: TCP/IP, WANs, LANs, SMTP, HTTP/HTTPS, FTP, POP, LDAP, SSH, SSH
SIEM Tools: Splunk, LogRhythm, Lumberjack, Microsoft Azure Sentinel
Scripting Languages: Bash, PowerShell
IAM Tools: CyberArk, Auth0, Okta