
Senior Application Security Consultant
Greater Chicago Area

Senior Application Security Consultant
Greater Chicago Area
Application Security leader providing security based source code analysis, application security training, and penetration assessments of applications and networks for major financial, government and fortune 500 corporations worldwide.
OWASP Enthusiast and leader of OWASP AppSensor Project
Application Security, security based source code review, penetration testing, compliance services, application security training, OWASP
(Privately Held; 11-50 employees; Computer & Network Security industry)
January 2008 — Present (1 year 11 months)
Senior Application Security Consultant providing application security code reviews and penetration assessments to identify high risk vulnerabilities in mission critical applications. Extensive experience reviewing Java and .NET applications. In addition, lead training seminars to educate developers and management on secure coding techniques, identification of vulnerabilities and simulated attacks to demonstrate exploitation of application vulnerabilities.
(Public Company; 10,001 or more employees; MOT; Telecommunications industry)
November 2006 — January 2008 (1 year 3 months)
* Technical lead for global security services to telecom and enterprise customers
* Managed penetration assessments, application security testing, and regulatory compliance services
* Researched security vulnerabilities for WiMAX technology and develop security services
* Directed and supervised research initiatives of three technical contractors
* Experienced in international business engagements (Spain, Austria, Vietnam, Israel)
* Developed internal software (PHP/MSSQL) to enhance services and reporting capabilities
* Performed DIACAP Information Assurance services for US government
Motorola Security Services provides a variety of security services to telecommunication, government and enterprise customers worldwide. These services include attack and penetration, network security analysis, application penetration, secure network design, compliance services and more.
(Public Company; 10,001 or more employees; MOT; Telecommunications industry)
January 2006 — December 2006 (1 year )
* Lead security consultant of 4 member Level 3 security response team and provided training and procedures to entire SOC (20 person team)
* Provided level 3 security response to attacks on Motorola worldwide network
* Acquired expertise in corporate NIDS/HIDS deployment, log correlation via Security Integration Manager, and interpretation of attack data
* Utilized hacking tools to recreate suspicious attacks for investigation. Experience with numerous tools including NMAP, Metasploit, netcat, Nessus, Foundscan
* Created executive summary and detailed technical reports for upper management and IT responders detailing malicious activity, impact to the organization and required remediation
(Privately Held; 1001-5000 employees; Computer & Network Security industry)
2004 — 2006 (2 years )
* Managed and performed 50+ network security assessment for clients in the financial industry
* Client services:
Penetration Assessments
Secure Network Design
Architecture Design
System hardening
Firewall and Router Secure Configuration Review
Policies and Procedure Reviews
DRP review
(Public Company; 10,001 or more employees; MOT; Telecommunications industry)
2003 — 2004 (1 year )
Windows administration of 200+ user location.
Experience with backup solutions, patch management, and scripting to automate system management tasks.
(Educational Institution; 10,001 or more employees; Education Management industry)
January 2002 — June 2003 (1 year 6 months)
Software Development using Visual Basic
Program designed for Professor David Budescu's Psychology research on Human judgement and decision making under uncertainty
MS , Computer, Information and Network Security , 2007 — 2009
Focus: Self-Sustaining Systems & Application Intrusion Detection
Portuguese culture and language 2002 — 2002
BS , Computer Science
OWASP, SANS, IAESTE
OWASP AppSensor Project Lead
OWASP Global Membership Committee
CompTIA - Security+
SANS - GIAC Certified Forensics Analyst (GCFA)
SANS Google Hacking and Defense
SANS Securing Critical Web Applications and Web Services
DIACAP In-Depth Training