Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Languages
Work Availability
Timeline
Hi, I’m

Neela Sindhuja Yasarapu

Somerville,NJ
Everyone you will ever meet knows something you don’t.
Bill Nye, the Science Guy
Neela Sindhuja Yasarapu

Summary

Information Security Professional with 7+ years of experience mainly focused on web applications, web services, mobile security, Thick Client , threat modelling and DevSecOps.

Overview

8
years of professional experience
2
Certificate

Work History

Concentrix

Security Consultant
12.2021 - 05.2023

Job overview

  • Implemented DevSecOps process in Organization. Reviewed and conducted POCs for several security tools. Integrated them in CI/CD pipeline for all Critical Applications.
  • Integrated DAST, SAST, SCA, Cloud Security tools like BlackDuck, Alert (by Synopsys), Webinspect, SonarQube, Coverity, Fortify SSC, Burp Suite Enterprise in CI/CD pipeline. JIRA integration is also worked upon. Researching on automating Pentest Scenarios also using Nuclei Tool.
  • Cybersecurity sessions on SecureSDLC was provided to all developers across organization. Prepared Run books and play books on using Security tool plugins like Coverity, BlackDuck, Sonarlint in IDEs like Eclipse, Visual Studio, IntelliJ, Visual Studio Code etc.
  • Hosted and installed all security tools as saas, on prem , Docker and maintained Servers like upgrading softwares, updating certificates, adding new plugins and acted as Subject Matter Expert (SME) for all security Tools. Performed Root Cause Analysis (RCA) for failures in CI/CD pipeline and provided immediate resolutions.
  • Coordinated with Development, DevOps team for successful onboarding of all applications in CI/CD pipeline. Categorizing applications, understanding their DevOps (Gitlab, Jenkins), Build Pipelines, Source Code Repositories (Gitlab, Bitbucket)and preparing plan/ Checklist to integrate them in pipeline.
  • Performed Manual Penetration testing for Web Applications, API, Thick Client Applications, Mobile Applications and identified Critical, Major and High vulnerabilities using Burpsuite Professional, ZAP proxy, SQL Map, NMAP, Wire Shark, Echo Mirage, Postman, Swagger, MobSF.
  • Conducted Vulnerability assessments for Web applications and APIs using DAST automated tools and performed False Positive Analysis. Source code was assessed by Building code and automated Scan using SAST tools. Performed Security, license and Operational risk analysis using Software Composition Analysis (SCA) Tools like Snyk, BlackDuck, Dependency Checker.
  • Performed False positive analysis for identified Vulnerabilities. Prepared Excel Dashboards and reports of findings with Proof of Concept like screenshots, payloads and steps on reproducing vulnerability identified, cost effective recommendations for remediation's.
  • Prepared Application Security guidelines for developers (both checklist and documents), Source Code Repository Management tools (Bitbucket, Gitlab) Hardening Guidelines.
  • Performed Threatmodelling for critical applications using STRIDE methodology. With Microsoft Threatmodelling tool (Microsoft TMT) created Data Flow Diagrams, Prepared attack trees, Risk matrix and identified potential risks and discussed with application architects and business owners of respective application team.
  • Provided Presentations on MITRE Attack Framework and PASTA model of threatmodelling. Provided many Knowledge sharing sessions on Dashboard Walkthrough of security tools to internal teams.

Carrier

Senior Security Analyst
10.2021 - 12.2021

Job overview

  • Responsible for conducting dynamic security testing of applications, Static Application security testing, Software composition Analysis, Penetration Testing, identifying and assessing vulnerabilities, and generating comprehensive reports with actionable recommendations for remediation.
  • Collaborate with development teams, validate and assist in vulnerability remediation efforts, and stay updated with latest security trends and best practices in field of SAST, Pentest and dynamic application security testing.
  • Research and Continuous Learning: -Stay updated with latest security vulnerabilities, attack techniques, and industry best practices related to dynamic application security testing.
  • Conduct research and experiments to enhance effectiveness and efficiency of DAST processes and methodologies. Share knowledge and insights with broader security community through blog posts, whitepapers, or conference presentations.
  • Collaborate with development teams, security engineers, and other stakeholders to foster strong security culture. Provide guidance and training to development teams on secure coding practices and importance of security testing. Communicate effectively with both technical and non-technical stakeholders, ensuring clear and concise reporting and sharing of information

Accenture

Security Analyst
03.2020 - 10.2021

Job overview

  • Collaborate with development teams and security stakeholders to define scope and objectives of dynamic security testing.
  • Develop detailed test plans and strategies, including target applications, test scenarios, and expected outcomes.
  • Execute dynamic security tests against web applications, APIs, mobile applications, and other relevant software systems.
  • Vulnerability Identification and Assessment: -Identify and assess security vulnerabilities, such as injection flaws, cross-site scripting (XSS), Cross site request forgery (CSRF), authentication and authorization issues, and insecure configurations.
  • Analyze scan results, interpret findings, and validate vulnerabilities to eliminate false positives.
  • Prioritize identified vulnerabilities based on severity, impact, and exploitability.

ShipByNight IT Solutions

Security Analyst
03.2018 - 03.2020

Job overview

  • Conduct thorough vulnerability assessments to identify security weaknesses in systems, networks and applications. - Utilize automated scanning tools and manual techniques to identify known vulnerabilities, misconfigurations, and weaknesses in security controls.
  • Analyse scan results, prioritize vulnerabilities based on severity, and provide recommendations for remediation.
  • Penetration Testing: Perform penetration testing to simulate real-world attacks and attempt to exploit identified vulnerabilities.
  • Conduct both external and internal penetration tests to assess security posture from an attacker's perspective.
  • Use various tools and methodologies to exploit vulnerabilities and gain unauthorized access, while avoiding damage to systems or data.
  • Document findings, including methods used, vulnerabilities exploited, and recommendations for mitigation.

Bug Bounty Platforms

Security Researcher
04.2017 - 03.2018

Job overview

Perform penetration testing for various applications listed in Bug Bounty Platforms using different Security tools like WireShark, Kali Linux, Burp Suite, SQLmap, Nmap, ZAP Proxy, Metasploit.


Identified many Business logic vulnerabilities like Improper Access control , Authorization Bypass, IDOR, Privelage escalation, File upload, Denial of Service Vulnerabilities.

Tata Consultancy Solutions

Systems Engineer
06.2012 - 08.2014

Job overview

  • Responsible for managing and performing VA/PT, risk assessment and threat modelling primarily for banking and finance industries.
  • Analysing and evaluating security posture of applications
  • Understanding of application workflows and identifying possible attack vectors
  • Exploitation of vulnerabilities found.
  • Co-ordinate team to design and execute test cases based upon requirements.
  • Assist development teams during vulnerability remediation phase.

Education

Andhra University College of Engineering
Visakhapatnam, India

Master of Technology
12.2016

ANITS
Visakhapatnam, India

Bachelor of Technology
06.2012

Skills

  • DAST
  • SAST
  • SCA
  • BlackDuck
  • Penetration Testing
  • DevSecOps
  • OWASP Top 10
  • Threat Modelling
  • Web Application Testing
  • Thick Client Testing
  • API Testing
  • Mobile Testing
  • Employee Security Training
  • Coverity
  • Fortify
  • WebInspect
  • Acunetix
  • AppScan
  • BurpSuite
  • Postman
  • EchoMirage
  • SonarQube

Accomplishments

    ● Received various awards (Rockstar, Best OPS team player, Most Valuable player) and kudos from Concentrix, 2022 & 2023

    ● Received client appreciation for designing and creating internal vulnerability metrics dashboard in Accenture in 2020

    ● Participated in various “OWASP”, “Women Who Code” meets, 2018 & 2019

    ● Awarded TCS On-Spot awards in 2013,2014.

    ● Won various awards during national technical symposiums.

    ● Published article on ScienceDirect during graduation, 2016

Certification

  • eWPT-eLearnSecurity Web Application Penetration Tester - eLearnSecurity
  • AZ-900 - Microsoft

Languages

English
Full Professional
Hindi
Limited Working
Telugu
Native or Bilingual
Tamil
Limited Working
Availability
See my work availability
Not Available
Available
monday
tuesday
wednesday
thursday
friday
saturday
sunday
morning
afternoon
evening
swipe to browse

Timeline

Security Consultant

Concentrix
12.2021 - 05.2023

Senior Security Analyst

Carrier
10.2021 - 12.2021

Security Analyst

Accenture
03.2020 - 10.2021

Security Analyst

ShipByNight IT Solutions
03.2018 - 03.2020

Security Researcher

Bug Bounty Platforms
04.2017 - 03.2018

Systems Engineer

Tata Consultancy Solutions
06.2012 - 08.2014

Andhra University College of Engineering

Master of Technology

ANITS

Bachelor of Technology
Neela Sindhuja Yasarapu