ANVESH GUMMADILLI
331 Lord byron lane, Cockeysville, MD, 21030
+1 (614) 364 4290
WORK EXPERIENCE
CYBER SECURITY TESTER, SENIOR
10/2016 – PRESENT
Boston, MA
- Development of ‘rules of engagement’ with partners
- Manipulate data in order to conduct sound and accurate analysis regarding output
- Learn and assist in managing DHS-specific Compliance dashboards and applications
- Familiarity with basic IPv4 local area networking concepts like subnets, masking, switches, routers, gateways
- Operator or test experience with McAfee or ForeScout products
- Certification: any one of CompTIA Server+, CompTIA Network+, CompTIA Security+, Microsoft Technology Associate (MTA) IT Infrastructure Track, or equivalent
- Excellent up-to-date technical and hands-on knowledge, experience in current attack methods, penetration testing methods, and hacking tools; especially for web applications, required
- Motivated with a desire to learn and to share knowledge
APPLICATION SECURITY TESTER
09/2009 – 04/2016
Dallas, TX
- Understand, find, verify, and explain security vulnerabilities. Review and ensure the secure configuration of OS and network devices
- Proficiency in one of the following scripting languages: Python, PowerShell, LUA, or Bash
- Perform manual web application security assessments (web-app, mobile, and API) using Capital One’s testing framework and methodology
- Perform automated web application security testing using Capital One tools (HP WebInspect, Fortify, Burp, CheckMarx, NowSecure, etc.)
- Lead and provide guidance to a team of geographical dispersed junior testers
- Act as a central point of contact for AppSec within your line of business
- Develop and maintain a deep understanding of the risks and applications within your line of business
- Provide detailed and thoughtful remediation recommendations
CYBER SECURITY TESTER
11/2003 – 06/2009
Dallas, TX
- Have an understanding of Capital One development methodologies, including Agile development
- Work closely with business and engineering teams to promote secure code development throughout the development process
- Promote security awareness by participating in Agile Release Trains
- Review application penetration test findings with the application owner and collaborate in efforts to eliminate or remediate risks associated with those findings
- Analyze code for vulnerabilities, and provide secure code examples
- Teach web application security trainings that cover common vulnerabilities
- Assist with develop and implementation of the penetration testing strategy, processes and procedures
EDUCATION
KENT STATE UNIVERSITY – STARK CAMPUS
1999 – 2003
Engineer’s Degree in Computer Science
PROFESSIONAL SKILLS
- Experience with security control validation and DoD information assurance, including DIACAP and RMF processes
- Experience in testing in an agile development environment is strongly desired
- This is a hands-on role, requiring support of technical skills from the hardware to the application layer
- First rate written and oral communications skills
- Beginner Windows and Unix skills
- Beginner written documentation skills
- Preparing testing estimates that incorporate all the activities that are required to effectively test (automated or otherwise) the system