Avishek Sarkar

  • Hyderabad Telengana

System Engineer,CEH -Web Application Security

Summary

Insightful, results-driven IT professional with excellent oral and written skills, outstanding attention to detail and passion to provide outstanding service. Experience in leading the Web Application Security and Vulnerability Management projects  ensuring  security planning, testing, verification and risk analysis.Well-versed in direct and remote analysis with strong critical thinking communication and people skills. Able to thrive in fast-paced and challenging environments where accuracy and efficiency matter.

Expertise

  • In-depth knowledge of application security vulnerabilities, testing techniques, and the OWASP framework.
  • In depth understanding of secure web application development, Java, Java development frameworks.
  • Experience of web application and Agile development methodologies.
  • Comprehensive knowledge of IT and information security subject matter.
  • Knowledge of security policies and standards and such as PCI-DSS and ISO 17799, 27001.
  • Knowledge of technical security architectural principles.
  • Able to prioritise workload and drive work to set deadlines.
  • Exposure to methods of promoting security awareness.
  • Strong communication (verbal/written) and influencing skills, with an ability to manage internal and external relationships up to senior levels of management.
  • Anticipates problems and identifies long-term implications of decisions and actions.
  • Ability to work alone and build relationships across the organisation.

Technical Purview

Operating Systems :

 BackTrack 5 R3, Kali 2.0, Windows XP/Vista/7/8

Network Scanners and analysis :

 Nmap, Zenmap,Wireshark

Web Application Vulnerability :

Nessus,Accunetix, Paros,SQLMap, Burp Suite, Zap, IBM AppScan, Nikto,W3AF ,XSSer

Penetration Testing Framework :

Metasploit

 

Work Experience

Work History
Jan 2014 - Present

System Engineer

Tata Consultancy Services
  • Identify application security risks and requirements for new projects and system developments.
  • Sign-off on application security prior to live implementation.
  • Work with the architecture and development teams to review code for security vulnerabilities and embed/improve security threat modelling and secure coding in the development life cycle.
  • Develop security testing plans and integrate into the software development life cycle.
  • Perform/oversee security testing and manage remediation of identified vulnerabilities.
  • Monitor and proactively report on current threats and vulnerabilities to application security.
  • Designed training manuals to increase security awareness throughout company.
  • Prepare and monitor operational security metrics and trends.

Certifications

Certifications
Feb 2016 - 2019

Certified Ethical Hacker

EC-Council


Education

Education
2009 - 2013

B.Tech

Academy Of Technology

Passed with DGPA of 8.10(out of 10) with specialization in Information Technology. 

2008 - 2009

12th AISSCE

K.V NO.1 Kanchrapara

Passed with an aggregate of 81% 

2006 - 2007

10th AISSE

K.V NO.1 Kanchrapara

Passed with an aggregate of 84%