Vartul Goyal

DevOps Manager

India15 yrs 6 mos experience
Most Likely To SwitchHighly Stable

Key Highlights

  • Over 13 years of experience in CyberSecurity.
  • Authored three security books and maintained GitHub profiles.
  • Recognized in Hall of Fame by major tech companies.
Stackforce AI infers this person is a Cybersecurity Expert with extensive experience in Cloud Security and Vulnerability Assessment.

Contact

Skills

Core Skills

Penetration TestingVulnerability AssessmentCybersecuritySecurity Best PracticesDevsecopsWeb Application SecurityCloud SecuritySecurity Governance

Other Skills

AWS SecurityAWS Security ControlsAgile MethodologiesAmazon Web Services (AWS)Application SecurityBlack Box TestingCI/CD AutomationCISClient RelationsCloud ApplicationsCloud ManagementCloud MigrationCloud Security ImplementationCloudflareCollaboration

About

Summary A CyberSecurity Expert and Product Security Innovator (highly praised in performance evaluations ratings for surpassing standards) with over 13+ years of experience as Principal Security Engineer for Financial Products, across diverse organizational domains such as Cloud Migration, Security Compliance, Infrastructure & Networking Security, OmniChannels, Threat Modeller, Micro-Lending Security Architecture, Telecom , Open Banking Solutions, Web3, BlockChain and NFT. CORE COMPETENCIES: Product Security Innovation, Secure Software Lifecycle Development, Shift Left Security, Zero Trust Model, Secure Source Code Reviewer, Agile Practioner, External Pre-Sales Security Advisor, Crypto Exchange Regulation Developer, Cloud Security Posture Management, Penetration Testing Execution Standards, Open Web Application Security Project, Smart Contract Auditor, Web3 Security Aspirant, Centre for Information Security, National Institure of Standards and Technology for Cloud Posture, Amazon Cloud, Microsoft Azure Cloud, Google Cloud, Kubernetes Administration and Security SPECIAL ATTRIBUTES: Exposure to renowned ethical security leaders in nations like the USA, Germany, Dubai and Malaysia to produce effective results in a challenging and multicultural workplace with Zero Trust Model implementation. Knowledge of working with large teams across various time zones and locations using cyber security posture management, product security managers, development teams, stakeholders, and customers from inhouse team. Excellent knowledge of Application Security, Mobile Security, Secure Source Code Analysis, Cloud Security Management Tools, Agility Technology, Sprint Cloud Management Platform, Security DevOps, Amazon Web Services, Microsoft Azure, Cloud, Virtualization, Sprint Velocity Review, Kanban Dashboard Review, and Retrospectives able to implement techniques for project guidelines enforcement and align products with product releases for Global footprint companies Author of three Security Books: Bounty Security Hacks, API Security Hacking and Cyber Security for CISO, CIO, and CTO. Maintainer of GitHub Profiles - API Security Manual, and Cloud Security Encyclopedia. Hall of Fame from Microsoft, Twillio, Intel and Indeed for security research work.

Experience

15 yrs 6 mos
Total Experience
1 yr 11 mos
Average Tenure
5 yrs 6 mos
Current Experience

Confidential

Security Professional

Dec 2020Present · 5 yrs 6 mos · Remote · Remote

  • Conducting Vulnerability Assessments and Penetration Tests
  • My primary role as a Penetration Tester is to conduct vulnerability assessments and penetration tests on computer systems, networks, and applications. I am required to use a range of techniques, tools, and methodologies to identify and exploit vulnerabilities in these systems. I am also document findings and provide recommendations for remediation.
  • Identifying Security Risks and Threats
  • As a Penetration Tester, I am identifying security risks and threats that could impact the organization. I am also required to keep up-to-date with the latest security trends and vulnerabilities to ensure that assessments are comprehensive and effective.
  • Preparing and Delivering Reports
  • After conducting assessments, I prepare detailed reports that summarize findings and provide recommendations for remediation. Reports are generally clear, concise, and actionable, and should be delivered to the appropriate stakeholders in a timely manner.
  • Collaborating with Other Security Professionals
  • Penetration Testers often work in collaboration with other security professionals, including Security Analysts, Network Engineers, and IT Managers. I need to communicate effectively with these stakeholders to ensure that assessments are aligned with the organization's overall security strategy.
  • Keeping Up-to-Date with Emerging Technologies
  • As a Penetration Tester, I would need to keep up-to-date with emerging technologies and trends in the field of cybersecurity. I would always attend conferences, read industry publications, and participate in training sessions to stay current with the latest security techniques and tools.
  • Adhering to Industry Standards and Best Practices
  • Penetration Testers are expected to adhere to industry standards and best practices when conducting assessments. This includes following ethical guidelines and ensuring that assessments are conducted in a safe and controlled manner.
Vulnerability AssessmentsPenetration TestingSecurity Risks IdentificationReport PreparationCollaboration with Security ProfessionalsVulnerability Assessment

Kreditbee

Lead Security Engineer

Oct 2019Nov 2020 · 1 yr 1 mo · Bengaluru, Karnataka, India · On-site

  • Collaborated with development, operations, and security teams to build, deploy, and maintain secure and scalable software systems.
  • Implemented security best practices across the development process, including code review, testing, and deployment.
  • Conducted security assessments and vulnerability scans to identify and mitigate potential security risks in software applications.
  • Developed and maintain security automation scripts and tools to streamline security processes and ensure consistent implementation of security controls.
  • Implemented and managed security monitoring and incident response processes to quickly detect and respond to security incidents.
  • Stay up-to-date with the latest security threats, trends, and technologies and apply this knowledge to improve the security posture of software systems.
  • Developed and maintain documentation and training materials to educate development and operations teams on security best practices and policies.
  • Communicated with stakeholders to report on security status, identify areas for improvement, and provide recommendations for remediation.
  • Participated in the development of security policies and standards to ensure compliance with regulatory requirements and industry best practices.
  • Conducted security awareness training sessions for employees to raise awareness about security risks and promote security best practices.
Security Best PracticesSecurity AssessmentsVulnerability ScansSecurity AutomationIncident ResponseCybersecurity

Wipro

Lead Consultant

Mar 2019Sep 2019 · 6 mos · Bengaluru, Karnataka, India · On-site

  • Deployed and monitor web applications in AWS while maintaining a security-first mindset and using secure development, coding, and engineering practices.
  • Worked collaboratively in a team environment, communicating effectively with peers and clients.
  • Automated end-to-end CI/CD pipelines, from code commits to production, using Infrastructure as Code (IaC) and infrastructure testing strategies.
  • Developed, document, and implement CI/CD strategies for managing the IaC baseline, ensuring the reliability, load balancing, monitoring, and logging of systems.
  • Installed, configured, and troubleshoot the UNIX/Linux-based environments.
  • Continuously evaluated and improved the organization's DevOps processes, tools, and methodologies.
  • As DevSecOps Engineer, responsible for managing the development and deployment of web applications in AWS while maintaining a security-first mindset, worked collaboratively in a team environment and possessed excellent communication skills to effectively communicate with peers and clients, As an Engineer, collaborated with development, security, and operations teams to ensure that security requirements are met throughout the development process and this involves facilitating communication and coordination between teams, providing training and guidance on security best practices, and maintaining positive relationships with stakeholders.
Web Application DeploymentCI/CD AutomationInfrastructure as CodeDevSecOpsCollaborationWeb Application Security

Landmark group

Senior Security Analyst - Manager

Dec 2017Mar 2019 · 1 yr 3 mos · Bengaluru Area, India · On-site

  • Implemented Cloud Advisor, Oracle Functions, Container Registry, Container Engine for Kubernetes, Autoscaling, GPU Shapes, API Gateway, and Anomaly Detection across all OmniChannels.
  • Worked in configuration of secured landing zones.
  • Security Provisioned in regions, service label, advanced configuration, compartment, policies, groups and users(IAM).
  • Integrated of Hashicorp vault(encryption standards) with Oracle Cloud.
  • Implemented cloud security migration from Oracle cloud to AWS Cloud using CloudEndure.
  • Deployed Hub, Spoke Architecture, Inbound SSH CIDR, Outbound HTTPS CIDR, Connect Landing Zone to On-premise Network, Provide Network and Security Administrator Email Address.
  • Audited Cloud Shell, OCI Audit Logs, Cloud Guard, and OCI VCN Flow Logs.
  • Helped the information security team in the implementation of CIS, SOC2 and NIST benchmarking with OCI.
  • Exposure in security configuration with PAAS and IAAS posture.
  • Advisor on Design Reviews, Threat Modeling, Secure SDLC, SAST & DAST Reviews, Security Governance, Information Management, Information Security Strategy, Process and Framework practices.
  • Hold knowledge on working implementation on AWS Configuration, AWS secure CloudEndure migration, and GitLab Cloud in AWS environment.
Cloud Security ImplementationSecurity GovernanceThreat ModelingSecurity Policies DevelopmentCloud MigrationCloud Security

Juniper networks

Level 3 Engineer - Penetration Testing

Jun 2015Dec 2017 · 2 yrs 6 mos · Bengaluru, Karnataka, India · On-site

  • An experienced person of 7 years I had performed Security Testing, Linux Boxes Testing.
  • Session hijacking, Cookie cadger, Image Sniffing, ssl sniffing or ssl stripping, and well versed with phenomenon of VA, AVA and Footprinting.
  • Wireless-pen testing-implementation of standards for IEEE802.11 with all versions, fern wifi crack tool, standards of WEP,WPA and WPA2, RADIUS, using airmon0.
  • Security Implementation: Firewall policies using all ports, IDS/IPS, AIDE, SNORT Implementation and Honey POT.
  • Implemented AWS Cloud security controls(IAM - Provisioning & de-provisioning, AWS Config, Security Hub, Cloudformation Stack, Cloudtrail, Cloudwatch, Lambda Security, DDOS Protection, Hardening, Cloudtrail, GuardDuty, Security Hub, Trusted Advisor, Shield Advanced, AWS Config & Inspector ) & CloudFlare with SIEM activities.
  • Tech Stack: Gitlab Pipelines, SAST: Sonatype, Contrast and Snyk, DAST: Rapid7, BurpSuite, Acunetix, Container Scan: Clair, TwistLock, Falco, Cloud: and AWS and GCP(Basics).
  • Implemented SAST controls Sonatype, Contrast, Fortify and Snyk.
  • Implemented WAF controls for Imperva and Cloudflare.
  • Hall of Fame from Microsoft (4 times), UpWork, Intel, Samsung, Indeed, Netflix, Seagate, Paypal, and Jet Airways.
Security TestingAWS Security ControlsPenetration TestingFirewall PoliciesSecurity ImplementationCloud Security

Ericsson india global services private limited

Senior Solutions Integrator

Apr 2013May 2015 · 2 yrs 1 mo · Gurgaon, India

  • Source code reviews for Java based applications.
  • Performed VAPT for mediation web devices and other postpaid web generated user interface (application user interface, this is specifically used by customers for their activity)
  • Audit FTP, SMTP, AUTH log analysis for user activity and malware activities related to all CDR web logs.
  • Perform ethical cracks ("hacks") to assess the vulnerabilities of test, Internet, and/or Intranet connected systems, networks, and applications including Windows, Linux, AIX, Solaris, Linux, HP-UX.
  • Done the fraud analysis from customer end through analyzing of ftp logs and tracking user activity according to android and iOS application id.
  • Analyzing latest hacks and upgrading servers with help of ec-ops team.
  • Produced advisory reports regarding 0-day exploits, CVE vulnerabilities, current network.
  • Performed host, network, and web application penetration tests.
  • Performed network security analysis and risk management for designated systems.
  • Proposed remediation strategies for re-mediating system vulnerabilities.
  • Developed Security Assessment Plan, Security Assessment Report, Security
  • Assessment Questionnaire, Rules of Engagement, kick off Brief, and Exit Brief templates.
Source Code ReviewsVAPTNetwork Security AnalysisSecurity Assessment ReportsRemediation StrategiesCybersecurity+1

Sapient corporation

Penetration Testing Engineer

Nov 2012Mar 2013 · 4 mos · Gurgaon, India · On-site

  • Performed penetration testing at manual and automated level through burp suite and other automated tools.
  • Audited log analysis for user activity and malware activities related to all Unilever Channel Concepts.
  • Performed ethical cracks ("hacks") to assess the vulnerabilities of test, Internet, and/or Intranet connected systems, networks, and applications including Windows, Linux, AIX, Solaris, Linux, HP-UX.
  • Generated and presented reports on security vulnerabilities to both internal and external customers.
  • Produced advisory reports regarding 0-day exploits, CVE vulnerabilities, current network.
  • Integrated of Hashicorp vault(encryption standards) with Oracle Cloud.
  • Experience in cloud security migration from Oracle cloud to AWS Cloud using CloudEndure.
  • Experience in Deploy Hub, Spoke Architecture, Inbound SSH CIDR, Outbound HTTPS CIDR, Connect Landing Zone to On-premise Network, Provide Network and Security Administrator Email Address.
  • Experience in Cloud Shell, OCI Audit Logs, Cloud Guard, and OCI VCN Flow Logs.
  • Experience in implementation of CIS, SOC2 and NIST benchmarking with OCI.
  • Implemented Design Reviews, Threat Modeling, Secure SDLC, SAST & DAST Reviews, Security Governance, Information Management, Information Security Strategy, Process and Framework practices.
Penetration TestingLog AnalysisEthical HackingSecurity Vulnerability ReportingCybersecurity

Svm infotech

QA Penetration

Aug 2010Nov 2012 · 2 yrs 3 mos · Noida

  • Conducted Vulnerability Assessment and Penetration Testing (VAPT) using a combination of manual and automated methods, including Nessus and other automated tools.
  • Conducted ethical hacking to identify vulnerabilities in connected systems, networks, and applications (such as Windows, Linux, AIX, Solaris, and HP-UX) both on the Internet and Intranet.
  • Generated comprehensive reports on identified security vulnerabilities for both internal and external customers.
  • Proficiently used various security tools including netcat, curl, burp suite extensions (co2, xxser), commix, sqlmap, haviz, wpscan, ssl-dos, xml bomb scanner, urlsnarf, driftnet, tasksel (server installation), poodle scanner, tcpdump, heartbleed scanner, http forensic tool, nmap, dmitry,netdiscover, wireshark, traceroute, host, angryipscanner, dnsdict6, nikto, and Nessus.
  • Possess a strong understanding of the NIST and ISO27001, SOC2 standards' requirements and implementation frameworks.
Vulnerability AssessmentEthical HackingSecurity Tools ProficiencyNIST StandardsCybersecurity

Education

COER, ROORKEE

Bachelor of Technology (BTech) — Computer Science

Jan 2005Jan 2009

Stackforce found 100+ more professionals with Penetration Testing & Vulnerability Assessment

Explore similar profiles based on matching skills and experience