Summary
Overview
Work History
Education
Skills
Certification
Languages
Employment History Additional
References
Additional Information
Timeline
Generic

Jayesh Patel

Ottawa

Summary

Analytical Penetration Tester with over 18+ years of hands-on experience in various domains such as security testing and penetration testing. Strong knowledge of network architectures, operating systems and cybersecurity tools. Confident and communicative professional proficient in scripting paired with familiarity of Unix and Windows. Collaborative team player committed to working with businesses and organizations to identify and resolve security vulnerabilities and weaknesses affecting digital assets and computer networks. Good hand and experience on CSPM, SCA, SAST.

Overview

12
12
years of professional experience
1
1
Certification

Work History

Network Security Engineer

Prakshal Technologies Pvt
  • Linux and Windows Server development and maintenance
  • Network Security hardware configuration and troubleshooting (Cyberoam, Cisco, Palo alto, Checkpoint, Sophos, huwai)
  • Routing (OSPF, EIGRP)
  • Border gateway protocol (BGP) configuration
  • Switching Technology (STP, VTP, VLAN)
  • Enterprise network security implementation
  • Programming Skill (Python and Shell Script)
  • Automation Tools (PowerShell, Jenkins and Puppet).

Sr. Security Configuration Assessment Engineer

Sophos
09.2011 - 10.2015
  • Experience in Antivirus, IPS /IDS Signature Development
  • Exploit reproduced and security alert monitoring
  • Experience in Security testing tools (Metasploits / Nessus / Nikto / Kali /Wireshark)
  • Experience in Vulnerability Scanning and OS Hardening (Nessus, OpenVAS, Metasploit, nmap)
  • Experience in Layer2 and Lyer3 Switching Technology(OSCP/VLAN/VTP/STP)
  • Experience in Penetration Testing, OWASP Top Vulnerabilities
  • Experience in WAF (web application firewall)
  • Experience in Python and Shell script
  • Experience in Automation Tools (PowerShell, Jenkins and Puppet)
  • Experience in Routing Protocol (RIP/BGP/OSPF/ISIS/EIGRP)
  • Automated network security tools.


Sr. Information Security Specialist

Versa-Networks Inc
01.2015 - 03.2017
  • Leading and mentoring team within Threat Research and Signature Development domain thereby achieved nearly 95% detection rate for malicious traffic in major certification tests
  • Also, as an active member of vulnerability assessment team, testing and reporting vulnerability for Versa products and advising OS Hardening solutions
  • SDWAN Applications Security testing (Network applications, Cloud Application)
  • Experience in Vulnerability Scanning and OS Hardening (Nessus, OpenVAS, Metasploit, Nmap, OpenScap)
  • Experience in Pen Testing Tools (Metasploits, Nessus, Nikto, Kali, Wireshark, Burp Suit Pro, ZAP Proxy)
  • Experience Network Virtualization (OpenStack, VMware ESXi, Hypervisor)
  • Experience Programming Skill (Python and Shell Script)
  • Experience in Mitre Attack research and detection
  • Automated network security tools
  • Open Source Vulnerabilities Scanning Tool developed
  • Experience in Continuous Integration and Continuous Delivery concepts (DevOps) Process
  • Application Security Scanning (Vera code and other in-house tool developed by me)
  • Linus Security (SELinux, IPTables).
  • Good hand in security automation tool development in python and shell scripting.
  • Good experience in Kubernetes security hardening validation.
  • As part of CSPM, have experience of security testing for different cloud platform (AWS, Azure, GCP), Terraform.
  • Developed and Designed some security tools for SCA, CSPM, SAST.

Sr. Information Security Specialist

Trend Micro Canada
03.2017 - 03.2021
  • Leading and mentoring team within Threat Research and Signature Development domain thereby achieved nearly 95% detection rate for malicious traffic in major certification tests
  • Enhanced network security by implementing robust firewall configurations and intrusion detection systems.
  • Streamlined vulnerability management process to effectively identify and remediate potential threats.
  • Also, as an active member of vulnerability assessment team, testing and reporting vulnerability for Versa products and advising OS Hardening solutions
  • Experience in Vulnerability Scanning and OS Hardening (Nessus, OpenVAS, Metasploit, Nmap, OpenScap)
  • Experience in Pen Testing Tools (Metasploits, Nessus, Nikto, Kali, Wireshark, Burp Suit Pro, ZAP Proxy)
  • Experience Network Virtualization (OpenStack, VMware ESXi, Hypervisor)
  • Experience Programming Skill (Python and Shell Script)
  • Experience in Mitre Attack research and detection
  • Automated network security tools
  • Open Source Vulnerabilities Scanning Tool developed
  • Experience in Continuous Integration and Continuous Delivery concepts (DevOps) Process
  • Application Security Scanning (Vera code and other in-house tool developed by me)
  • Linus Security (SELinux, IPTables)
  • Open Source Vulnerability Scanning (Manually and Automatic)
  • Software Bill of Materials.
  • Acts as a expert for security tools Burp, ZAP, OWASP, Kali, SSL Scanner, OpenScan.
  • Developed and Designed some security tools for SCA, CSPM, SAST.
  • As part of CSPM, have experience of security testing for different cloud platform (AWS, Azure, GCP), Terraform.
  • Good experience in Kubernetes security hardening validation.
  • Good hand in security automation tool development in python and shell scripting.

Vulnerability Assessment and Penetration Tester

Manulife
03.2021 - Current
  • Enhanced network security by performing comprehensive vulnerability assessments and penetration tests.
  • Identified critical weaknesses in systems through thorough penetration testing, leading to improved defenses.
  • Designing and implementing cloud security strategies and policies that meet an organisation's specific needs.
  • Ensuring the security of cloud-based data and applications against unauthorized access, theft, and other threats.
  • Staying up-to-date on the latest cloud security technologies, trends, and best practices.
  • Collaborated with Development teams to remediate vulnerabilities discovered during assessments, strengthening overall security posture.
  • Collaborate with Product Managers, Platform Leads, and Information Security teams, to design and implement cloud security solutions
  • Acts as a expert for security tools Burp, ZAP, OWASP, Kali, SSL Scanner, OpenScan, Nessus, Qualys.
  • Developed and Designed the security tools for SCA, CSPM, SAST.
  • As part of CSPM, have experience of security testing for different cloud platform (AWS, Azure, GCP), Terraform.
  • Good experience in Kubernetes security hardening validation.
  • Good hand in security automation tool development in python and shell scripting.
  • Experience in Penetration Testing, OWASP Top Vulnerabilities

Education

OSCP -

Offensive Security
01.2019

Diploma in Information Technology -

Ganapath University
04.2003

Skills

  • Ethical Hacking Principles
  • Vulnerability Scanning Tools
  • Security Information and Event Management
  • Threat Modeling
  • Cloud Security Assessment
  • API Security Testing
  • Risk Assessment Methodologies
  • Network Penetration Testing
  • Operating System Hardening
  • Intrusion Detection Systems
  • Scripting Languages
  • Web Application Testing
  • Malware Analysis
  • Vulnerability Assessment
  • Penetration Testing
  • Source Code Review

Certification

  • CEH (Certified Ethical Hacker), Ottawa, 11/2020, 11/2020
  • AWS Certified Security Specialist, Ottawa, 11/2020, 11/2020
  • RHCE (Red Hat Certified Engineer), 2011, 2011
  • CCNA (Cisco Certified Network Associated), 2011, 2011
  • MCITP (Microsoft Certified), 2012, 2012
  • MCSE (Microsoft Certified), 2012, 2012
  • CCNSP (Cyberoam Certified Network and Security Professional), 2013, 2013

Languages

English
Native or Bilingual
Hindi
Native or Bilingual
Gujarati
Native or Bilingual

Employment History Additional

  • Jays Linux (Linux Distro) Project, 2019, 2019, Developed Own Linux Distro, with compile, install dhcp, lighttp (Web server), telnet, busy box, php, MySQL module from source, and manage whole Distro by web interface., https://code.google.com/p/jayslinux
  • SDN (Software Defined Networking), 2019, 2019, An open SDN platform with centralized software provisioning delivers dramatic improvements in your network agility via programmability and automation, while substantially reducing the cost of your network operations. And using an industry standard data plane abstraction protocol like Open Flow?, you are now free to use any type and brand of data plane devices, since all the underlying network hardware is addressable through a common abstraction protocol., https://code.google.com/p/open-sdn/
  • Malware Analysis Project (Sandbox Controller), 2019, 2019, This Malware Analysis project as a research project written in python which is automatically investigate any file and generate the report with results of file like (Submitted file was Malware or Clean) , we have client/server application for malware analysis. Using client application, you can submit file on server and get back results and report. This project is developed on python. In this project, we used many open source tools and developed some parser for analyses malware file. Here we cover both static analysis and dynamic analysis. In static analysis, we use some parser and open source tools to analyses file. In dynamic analysis, we use virtual operating system to run file and geared memory dump. We analyses memory dump and find some malware activity., https://github.com/umasolution/malware-analysis
  • DoS and DDoS attack project, 2019, 2019, This is Distribute denial of service and denial of service attack documentation., https://github.com/umasolution/DDoS
  • NSS Certification Testing Tool, 2019, 2019, Prepared NSS Testing tools to get NSS NGFW certification. HTTP Evader HTML Evader Javascript/VBScript evasion IP/TCP (With IPv6) Evasion Resiliency Techniques, https://github.com/umasolution/htmlEvader
  • Sysmon Sandbox, 09/2020, 09/2020, Sysmon sandbox and malware analysis sandbox., https://github.com/umasolution/sysmonSandbox
  • OpenSource Vulnerability Scanning Project, 09/2020, 09/2020, This is open source vulnerability scanning project, you can scan npm, pip, maven, composer language installer library vulnerability, tomcat, apache, Drupal, wordpress and other all 300+ application vulnerability scanning, Platform Vulnerability scanning., https://github.com/umasolution/threatInfoHunters

References

References available upon request

Additional Information

Certifications:


-> RedHat Enterprise Engineer (RHCE)

-> Cisco Network Certification (CCNA)

-> Microsoft 2003 and 2008 Certification (MCSE, MCITP)

-> Offensive Security Certified Professional certification (OSCP)


Timeline

Vulnerability Assessment and Penetration Tester

Manulife
03.2021 - Current

Sr. Information Security Specialist

Trend Micro Canada
03.2017 - 03.2021

Sr. Information Security Specialist

Versa-Networks Inc
01.2015 - 03.2017

Sr. Security Configuration Assessment Engineer

Sophos
09.2011 - 10.2015

Network Security Engineer

Prakshal Technologies Pvt

OSCP -

Offensive Security

Diploma in Information Technology -

Ganapath University
Jayesh Patel