Vulnerability Assessment skills : Thorough and practical knowledge of OWASP, Hands on experience with popular security tools – Nessus, Burpsuite, Netsparker, Metasploit, Nexpose, KALI Linux. Working knowledge of manual testing of web applications. Good knowledge of modifying and compiling exploit code. Hands on experience of working on Windows and Linux Platforms.
Penetration Testing Skills: configuration review for network, web application, mobile application and thick-client application, PT of web and mobile applications, cloud penetration testing, Network Penetration Testing etc. Keep oneself updated on the latest IT Security news, exploits, hacks. Prepare Threat Intelligence reports for newly discovered threat agents, exploits, attacks etc.
Infra & Network Security Skills : Technical knowledge of Firewall, AD, VPN, Duo, CDN, DDOS, APT, NAC, IPS/IDS, PIM/PAM, Cloud & Container configuration etc. Driving Security at all Perimeter level, Rules & Configuration review of Network elements i.e.
Other Desired technical skills:
Working knowledge of CIS Security benchmarks Good understanding and knowledge of codes & Programming languages Has practical experience in auditing various OS, DB, Network and Security technologiesDesired Certifications
Offensive Security Certified Expert (OSCE) Offensive Security Web expert (OSWE) Offensive Security Wireless Professional (OSWP) Offensive Security Exploitation Expert (OSEE) Certified Information Security Manager(CISM) Certified Information Systems Security Professional(CISSP)