Experience Education Certifications Languages
Experience Apr 2018 - Present
7 years 5 months
Penetration tests and security assessments: network infrastructure, Active Directory, cloud, Microsoft 365 (e.g. SharePoint), servers, OS (Linux and Windows), web applications (OWASP Top 10, XSS, SQLi), mobile apps
Identification and evaluation of vulnerabilities
Preparation of final reports
Source code analysis: .NET, Java, Kotlin, Swift, JavaScript
Consulting on secure software development
Creation of threat models
Conducted over 150 tests total, each between 3 and 20 PT
30% web penetration tests, following OWASP Testing Guide. Analysis of single-page apps, REST APIs (JSON), authentication, static websites, etc.
50% network/infrastructure: internal and external network analysis, firewall, Active Directory, hardening of servers and workstations
10% cloud: configuration, access control, privilege escalation
10% mobile apps (Android, iOS) and rich clients (Windows): local authentication, secure data storage, API calls