Summary
Overview
Work History
Skills
Certification
References
Timeline
Generic

Nikos Salamanopoulos

North Las Vegas,NV

Summary

Penetration Tester with 6 years total experience in testing web applications, API's, and Android APK's. Completed several in-season CTF challenges for HTB, THM, and In-Person events such as SparkCon and DefCon. Assisted in creating an online community centered around penetration testing, as well as participate in weekly "Hack-a-long" events. Helped mentor junior level penetration testers. Actively aspiring to learn as many new skill sets as possible, as well as refine current skill set. Have skills in SQL, XML, JavaScript, Linux/Windows Systems, GraphQL, Python, Objection/Frieda, Jadx, along with many others. Familiarity with hardware such as diagnosing and repairing servers and computers. Freshly learned source code review and AWS cloud review, looking to improve the skill set.

Overview

6
6
years of professional experience
1
1
Certification

Work History

Senior End to End Solutions Penetration Tester

Walmart
05.2022 - 08.2024
  • Conducted multiple comprehensive vulnerability assessments and penetration tests on entire solutions to identify and remediate security issues
  • Developed and executed detailed penetration testing plans in alignment with industry best practices and standards
  • Performed penetration tests on web applications, APIs, mobile applications, and internal and external infrastructure for business-critical solutions, as well as solutions that fell under prospective mergers and acquisitions
  • Worked with multiple information security disciplines to provide penetration testing across Walmart's entire organization
  • Found and assisted with remediation on several critical level vulnerabilities within production environments

Junior Application Security Analyst

CCLabs, LLC
08.2020 - 05.2022
  • Conducted comprehensive penetration testing services for diverse ranges of clients
  • Efficiently produced comprehensive findings reports within established deadlines
  • Assisted clients in assessing and mitigating vulnerability risks
  • Communicated with clients to define clear scope and remained within client expectations

Application Security Analyst

Sokin Security, LLC
02.2019 - 08.2020
  • Conducted vulnerability assessments and penetration testing for multiple clients
  • Worked closely with clients to develop and define clear scope, and executing accurate penetration testing that meets client expectation and standards
  • Stayed up-to-date on latest cybersecurity threats, best practices, and regulatory requirements to ensure comprehensive coverage
  • Created and peer reviewed multiple thorough, comprehensive and detailed reports

Repair Tech

Best Buy / Geek Squad
08.2018 - 02.2019
  • Met with customers to help diagnose issues and create efficient remediation plan
  • Developed exemplary customer service skills
  • Worked with physical devices and developed secure data handling skills
  • Worked efficiently and became highest performing repair shop across Best Buy for three fiscal quarters

Skills

- Ability to perform Web Application, API, Android APK, LLM, and AWS Cloud penetration testing

-Experience with modern web application penetration testing tools such as Burp Suite, NMAP, SQLMap, Dirbuster, Gobuster, SSLScan, wafw00f, Nikto, Wireshark, and many others

-Experience in guiding junior level employees as well as guiding indivduals newer to the information security ecosystem

-Some Experience performing external network penetration testing

-Some Experience performing source code review

-Work efficiently within a team in order to complete projects before expected deadlines

Certification

eWPT eLearnSecurity July 2022

Web Application Penetration Testing Certification -

proof of web application penetration testing ability on modern frameworks against OWASP top 10 as well as more complex vulnerabilities. High level report with detailed writeups on vulnerabilities required to complete course


GPEN SANS February 2024

General Penetration Testing Course -

Multiple Choice SANS certification that proves understanding of modern attack vectors and understanding of modern frameworks


Practical Secure Code Review Absolute AppSec October 2024

Secure Coding course -

Secure coding class hosted by Ken Johnson & Seth Law that goes over source code review methodology along with leveraging modern tooling to optimize process


Mobile Application hacking The Cyber Mentor July 2023

Android APK hacking -

Course covering dynamic and static analysis of Android APK applications, along with covering proper operation of Android Emulations and Certification handling to optimize testing process


Pentester Labs Badges PentesterLabs December 2022

Completed Unix, CTF, Yellow, and White badges


CWEE Hack the box

Certified Web Exploitation Expert - W.i.P. - HackTheBox's "most difficult" certification diving deep into advanced web application exploitation


CPTS Hack the Box

Certified Penetration Tester Specialist - WiP - HackTheBox's version of the OSCP, dives deep into network service enumeration and attack methodology.


AWS Cloud Red Team Specialist Cyber Warfare Labs

AWS Penetration Testing Course - W.i.P - Course on penetration testing AWS including bucket exploitation as well as IAM policy auditing.


References

Serena Curtin

Senior Manager, Information Security / Walmart

Serna.Curtin@walmart.com

(719)-205-9935

Gregg Feinstein

Senior Technical Expert, Information Security / Walmart

Gregg.Feinstein0@walmart.com

(702)-339-9667

Lance Pendergrass

Technical Expert team lead, Information Security / Walmart

Lance.pendergrass@walmart.com

(417)-849-7351

Steven Bennett

Director, Information Security / Walmart

Steven.Bennett@walmart.com

(479)-277-5921

Timeline

Senior End to End Solutions Penetration Tester

Walmart
05.2022 - 08.2024

Junior Application Security Analyst

CCLabs, LLC
08.2020 - 05.2022

Application Security Analyst

Sokin Security, LLC
02.2019 - 08.2020

Repair Tech

Best Buy / Geek Squad
08.2018 - 02.2019
Nikos Salamanopoulos