Zubair Resume

Download as pdf or txt
Download as pdf or txt
You are on page 1of 5

Zubair Shaikh

Security Consultant,
[email protected],
7045224273

Career Objective

To obtain a responsible, challenging, and awarding position in the Information Security field where my skills,
knowledge and technical abilities can be utilized to the maximum of my potential.

Profile Summary

• 7 years of experience working on multiple projects in application security testing, mobile application
security testing, thick client application testing, API testing, VAPT activities for clients across multiple
industries and verticals.
• Experience in working with clients following PCI-DSS standard to maintain a High level of Security
Posture.
• Experience includes working with teams and multiple clients across the globe.
• Onsite experience of performing multiple testing activities for clients in the Middle east and Africa.
• Successfully audited 100+ business Web-Applications, thick client applications, mobile applications, API
testing and VAPT assignments using automated tools and manual testing techniques.
• Hands on Experience in tools like Acunetix, Burp Suite Professional, MoBSF, Sql map, Metasploit,HP
Fortify, Nessus, Qualys and multiple industry standard tools.
• Integration of Azure Devops with vulnerability tracking tools like Acunetix 360 to have a high-level
overview of the vulnerability count and current issues.
• Good knowledge of the healthcare domain and the standards used within like HIPAA.
• Well versed with Security Assessment methodologies like OWASP and CVSS etc.
• An effective communicator with excellent relationship building & interpersonal skills, Strong analytical
and problem-solving abilities.

Academic Qualifications

• Bachelor of Engineering in Electronics and Telecommunication,2017, Mumbai University

Achievements

• Received award for best cyber threat team for a leading BFSI client.
• Received Recognition as best VAPT team and contributor.
• Reported issues on online hacking portals like Hackeone and Bugcrowd and received thanks. Work
Experience

Duration Organization Role

September 2022 - Current Aujas Cybersecurity Senior Security Consultant II


May 2021- August 2022 Citiustech Healthcare Technology Senior Security Consultant
Pvt Ltd

Jan 2019 – April 2021 ControlCase LLC Associate Consultant

September 2017 - X-biz Techventures Pvt Ltd Information Security Analyst


December 2018

Key Projects

Project Name Vulnerability Assessment & Penetration Testing- Web Application

Clients Multiple Companies (Public and Private) across the Globe

 Walkthrough of the application with developer, understanding functionality and


Responsibilities business flow for plotting test cases.

 Prepare threat profile for the application based on the functionalities and
technologies.
 Perform application security assessment.
 Prepare detailed report of the Assessment.
 Discuss the vulnerabilities and their possible solutions with developers,
solution architect and product managers.

Project Name CI/CD Implementation of Azure Devops with Acunetix

Clients Multiple Companies (Public and Private) across the Globe

 To integrate acunetix 360 vulnerability scanner with Azure Devops to have an


Responsibilities integrated flow for vulnerability tracking and remediation

 Integration of Acunetix and issue tracking system to have a high-level


understanding of the security posture.
 To initiate automated scans using the CI/CD functionality, scans to be triggered
on every code change and code pushed by the developer.
 Discuss the vulnerabilities and its possible solution with developers, solution
architect and product managers.

Project Name Security Assessment of Web Services

Clients Multiple Companies (Public and Private) across the Globe


 Understand the application, frameworks and technologies  Perform Manual
web service review using SOAP UI for WSDL.
 Test REST based Webservices.
Responsibilities  Testing API Calls using Postman.
 Prepare detailed report for the observations made.
 Discuss the vulnerabilities and its possible solution with application
stakeholders.

Project Name Mobile Application Security testing

Clients Multiple Companies (Public and Private) across the Globe

 Perform application security tests in line with OWASP TOP 10 


Provide recommendations to fix the issues.
Responsibilities  Revalidation testing to validate the closure of vulnerabilities.
 Generate detail closure report.
 Performed testing using Fiddler, Burp Suite, Android SDK

Project Name Thick Client Application Testing

Clients Multiple Companies (Public and Private) across the Globe

 Perform application security tests in line with OWASP TOP 10


 Provide recommendations to fix the issues
Responsibilities  Report issues in Proper format
 Revalidation testing to validate the closure of vulnerabilities  Generate
detail closure report

Project Name Vulnerability Assessment and Penetration Testing

Clients Multiple Companies (Public and Private) across the Globe


 Perform vulnerability assessment and Penetration Testing in line with multiple
Responsibilities client Networks and infrastructure.
 Scan using Automated tools like Nessus, Nexpose and Qualys
 Manual test results and check for false positives
 Report vulnerabilities according to CVSS methodology
 Assist Network teams with remediation and patches for vulnerabilities.
 Ensure issues are fixed within stringent timelines and the scans are done on a
regular basis to identify zero day and latest issues.

Project Name SAST using HP Fortify

Clients Multiple Companies (Public and Private) across the Globe

 Walkthrough of the application with developer, understanding specific


Responsibilities functionalities and code related changes

 Ensuring proper codebase is aligned for the assessment.


 Run scanning engine and analyze specific sections of codebase.
 Understand the results and remove false positives whereas highlight and verify
the conclusive issues.
 Prepare detailed report containing all information about the result.
 Discuss the vulnerabilities and its possible solution with developers, solution
architect and product managers.
 Ensure issues are fixed within stringent timelines and code quality is
maintained
Personal Details

Date of Birth : 26/11/1994

Languages Known : English, Hindi, and Marathi.

Hobbies : Trekking, Playing Sports, bug bounty etc

I hereby declare that the information given above is true to the best of my knowledge.

You might also like