Security Tester Resume Sample
Work Experience
- Development of ‘rules of engagement’ with partners
- Manipulate data in order to conduct sound and accurate analysis regarding output
- Learn and assist in managing DHS-specific Compliance dashboards and applications
- Familiarity with basic IPv4 local area networking concepts like subnets, masking, switches, routers, gateways
- Operator or test experience with McAfee or ForeScout products
- Certification: any one of CompTIA Server+, CompTIA Network+, CompTIA Security+, Microsoft Technology Associate (MTA) IT Infrastructure Track, or equivalent
- Excellent up-to-date technical and hands-on knowledge, experience in current attack methods, penetration testing methods, and hacking tools; especially for web applications, required
- Motivated with a desire to learn and to share knowledge
- Understand, find, verify, and explain security vulnerabilities. Review and ensure the secure configuration of OS and network devices
- Proficiency in one of the following scripting languages: Python, PowerShell, LUA, or Bash
- Perform manual web application security assessments (web-app, mobile, and API) using Capital One’s testing framework and methodology
- Perform automated web application security testing using Capital One tools (HP WebInspect, Fortify, Burp, CheckMarx, NowSecure, etc.)
- Lead and provide guidance to a team of geographical dispersed junior testers
- Act as a central point of contact for AppSec within your line of business
- Develop and maintain a deep understanding of the risks and applications within your line of business
- Provide detailed and thoughtful remediation recommendations
- Have an understanding of Capital One development methodologies, including Agile development
- Work closely with business and engineering teams to promote secure code development throughout the development process
- Promote security awareness by participating in Agile Release Trains
- Review application penetration test findings with the application owner and collaborate in efforts to eliminate or remediate risks associated with those findings
- Analyze code for vulnerabilities, and provide secure code examples
- Teach web application security trainings that cover common vulnerabilities
- Assist with develop and implementation of the penetration testing strategy, processes and procedures
Education
Professional Skills
- Experience with security control validation and DoD information assurance, including DIACAP and RMF processes
- Experience in testing in an agile development environment is strongly desired
- This is a hands-on role, requiring support of technical skills from the hardware to the application layer
- First rate written and oral communications skills
- Beginner Windows and Unix skills
- Beginner written documentation skills
- Preparing testing estimates that incorporate all the activities that are required to effectively test (automated or otherwise) the system
How to write Security Tester Resume
Security Tester role is responsible for security, software, beginner, government, administration, design, architecture, wireless, mac, integration.
To write great resume for security tester job, your resume must include:
- Your contact information
- Work experience
- Education
- Skill listing
Contact Information For Security Tester Resume
The section contact information is important in your security tester resume. The recruiter has to be able to contact you ASAP if they like to offer you the job. This is why you need to provide your:
- First and last name
- Telephone number
Work Experience in Your Security Tester Resume
The section work experience is an essential part of your security tester resume. It’s the one thing the recruiter really cares about and pays the most attention to.
This section, however, is not just a list of your previous security tester responsibilities. It's meant to present you as a wholesome candidate by showcasing your relevant accomplishments and should be tailored specifically to the particular security tester position you're applying to.
The work experience section should be the detailed summary of your latest 3 or 4 positions.
Representative Security Tester resume experience can include:
- Supports the creation of meaningful metrics to demonstrate the effectiveness of security controls and security team operations
- Beginner communication skills
- Beginner web application security & penetration testing experience on web applications and web services through manual testing
- Experience with leveraging exploitation frameworks, including Metasploit and Cobalt Strike to compromise systems
- Experience with red-teaming, including covert computer network exploitation
- Experience working in a team-oriented, collaborative environment with a high level of analytical and problem-solving abilities
Education on a Security Tester Resume
Make sure to make education a priority on your security tester resume. If you’ve been working for a few years and have a few solid positions to show, put your education after your security tester experience. For example, if you have a Ph.D in Neuroscience and a Master's in the same sphere, just list your Ph.D. Besides the doctorate, Master’s degrees go next, followed by Bachelor’s and finally, Associate’s degree.
Additional details to include:
- School you graduated from
- Major/ minor
- Year of graduation
- Location of school
These are the four additional pieces of information you should mention when listing your education on your resume.
Professional Skills in Security Tester Resume
When listing skills on your security tester resume, remember always to be honest about your level of ability. Include the Skills section after experience.
Present the most important skills in your resume, there's a list of typical security tester skills:
- Understanding of network protocols coupled with experience with web proxies, web application firewalls, and vulnerability assessment tools
- Experience with creating systems and applications security test plans and performing hands–on security testing
- Software testing experience with a history performing hands on, web application penetration testing in a variety of diverse environments
- Experience in developing one or more of the following languages - Go, SWIFT, Objective C , JAVA, or .NET
- Experience with leading and developing small high power teams
- Experience with advanced penetration testing, system exploitation, or Cybersecurity engineering
List of Typical Experience For a Security Tester Resume
Experience For Application Security Tester Resume
- Perform the activities necessary to ensure effective delivery of application security services across the enterprise
- Develop and maintain test and Honeywell qualification procedures and processes to produce repeatable and effective test results
- Experience in Information Security and a background in application development (HTML/CSS, HTTPS, Python, Java/Javascript,)
- Experience in Risk Management Framework (RMF) packages
- Generating Gherkin scenarios
- Offensive Security Certified Professional (OSCP) or SANS GIAC Penetration Tester, including GPEN and GXPN Certification
Experience For Cyber Security Tester Resume
- Assume lead role in cyber security product testing and qualifications against Honeywell EPKS and various Advanced Control software.
- Information system engineering
- Supports technical security assessments of applications and infrastructure, security design reviews as well as risk assessments
- Supports project teams, application owners, and general technology teams on relevant security controls and secure SDLC process requirements
- Supports in security architecture reviews and exception approval processes
- Supports security’s role in change management
- Recognize software defects/anomalies/failures and generate test results for later analysis and correction
- Have a good understanding of system administration skills, including hardware, OS, network, software installation, security hardening and system troubleshooting
Experience For Cloud Security Pen Tester Resume
- Develops test scenarios and test scripts
- Traces requirements to test cases to ensure coverage for full system integration test
- Ensures that functional and technical requirements are met through system testing, regression testing, performance testing, system interface testing, and security testing activities
- Develops and maintains the Requirements Traceability Verification Matrix (RTVM) with imbedded Testability Matrix that maps test methods and events, test scripts, scenarios, and test results to the applicable requirement, to include test-related artifact changes
- Plans, prepares, manages and reports progress on the System Development Test (STD) activities and deliverables pertaining to Product Level Test (PLT) and Developer's Integration Test (DIT)
- Beginner Information Security experience
Experience For Security Certification Assessor Tester Resume
- Information Assurance Training (IAT) Level certified - Security+
- Responsible to update status and escalate to management as necessary
- Beginner compliance background (PCI, GLBA, SOX, etc…)
- Expert with common web application penetration testing tools including, but not limited to Burp, Fiddler, OWASP Zap, BeEF, and at least one commercial solution (WebInspect, AppScan, or similar)
- Familiarity with common network vulnerability / penetration testing tools like Metasploit, vulnerability scanners, Kali Linux, and/or Nmap
Experience For Security Assessment Tester Resume
- Fluent in at least 1 programming language
- Thought leadership in the security field, with demonstrable contributions to industry groups
- Beginner leadership qualities
- Test independently
- Manage and perform patch and software distributions, and manage security configuration of the cyber security products offered by Honeywell ICS team
- Liaison with Honeywell DE and HTS to ensure compliance with development and test standards and procedures
Experience For Cyber Security Product Tester Resume
- No certifications required but CISSP or equivalent security related industry certifications desired
- Familiar with DoD 8570 documentation
- Knowledge of PeopleSoft versions 9.1/9.2 HCM
- Willingness to work in a global organization, where
- Program design and implementation
- System certification activities and efforts related to system certification and accreditation
- Research, development, integration, and distribution of IS security tools and associated documentation
- Security procedures for systems and software within area of expertise to ensure consistent security policy implementation
List of Typical Skills For a Security Tester Resume
Skills For Application Security Tester Resume
- Experience in developing test automation frameworks using tools such as HP Quality Center
- Experience with the NIST SP 800 Series and testing the NIST SP 800-53 security control framework
- Experience performing manual application penetration tests
- Experience managing junior testers
- Experience with common web application testing tools: BURP, ZAP, WebInspect, AppScan or Fortify
- Information Security experience supporting the Financial Services sector
Skills For Cyber Security Tester Resume
- Experience with full scope network and infrastructure penetration testing
- Networking experience
- Experience with developing Security Assessment Reports and Security Assessment Plans
- Experience with risk management methodologies, including NIST, DoD, and ICD 503
- Knowledge and experience with Government Risk Compliance (GRC) Suite, and SQL for testing desired
- Experience with each of the following
- Demonstrated ability to analyze test results and suggest mitigations for security problems
- Experience in using Information Assurance test and risk assessment tools
Skills For Cloud Security Pen Tester Resume
- Experience with application vulnerability assessment tools (IBM, HP, or open source)
- What is your experience in web application security?
- What is your experience in Information Security?
- Experience with deploying enterprise security testing solutions
- Experience with performing Cybersecurity analysis of network architectures
- Experience with Web application security testing
Skills For Security Certification Assessor Tester Resume
- Experience with wireless network infrastructure security testing
- Experience with executing Web application, network, and system penetration tests for clients
- Operate security testing projects with little assistance
- Experience in scripting with Python or Ruby
- Experience with Linux, Windows, wireless, and virtual platforms
- Experience with mobile device security
- Experience with Cloud–based infrastructure as a service technology
- Producing and presenting testing-related reports and information, such as requirement-based coverage, testing progress and problem areas
Skills For Security Assessment Tester Resume
- Understanding of UNIX and Windows operating systems and webhosting platforms
- Analyzing the testing (performance, automation, manual, integration and CFIA) testing requirements for Bank applications
- Analyzing the impact of a change from a testing perspective, including time, cost and risk
- Planning for performance testing and creating performance test scripts
- Maintaining and adhering to IT standards and guidelines for all types of testing
Skills For Cyber Security Product Tester Resume
- Leading in the quality assurance (QA) process, adding technical know-how, creativity and a seasoned perspective to initiatives and teams
- Developing and maintaining collaborative relationships with internal and external counterparts to support the Scrum team's objectives
- Verifying and documenting test results, whether performance, automated, manual, integration or CFIA related
- Creating test data creation tools and using them to generate test data
- Identifying gaps in the test automation framework and participating in the work to close those gaps
Skills For IoT Security Tester Resume
- Participating in the defect process, ensuring that defects are documented, tracked and reported to facilitate timely resolution
- Creating robust automated test case suites using a test automation framework
- Understanding of OWASP methodology
- Developing test strategies, test plans, test cases and procedures to uncover bugs and improve the overall quality of the infrastructure and applications
- Ensuring that the automation routines run on demand or on schedule
- Translate an understanding of systems and applications into security test plans and perform hands on security testing
- Performs and/or leads an integrated test team to perform the following activities in support of the testing function
- Participates in other program working groups and IPTs to ensure testing requirements are addressed as needed
Skills For Cyber Security Tester, Mid Resume
- Onsite Gym – get your workout in before work, during your lunch break, or at the end of the day
- Responsible for completing assigned application scans against web applications or web services
- CPTE - Certified Penetration Testing Engineer or CEH - Certified Ethical Hacker GSEC
- Manually testing functionality that cannot be automated
- Broad knowledge of Information Security policies and guidance, as well as the ability to assist in researching, evaluating, and developing relevant security policies and guidance
- Working knowledge of Intelligence Community Information Assurance policies and regulations and how the certification and accreditation (C&A process relates to it
- Ability and skill in using Information Assurance test and risk assessment tools
- Work in a team environment and interact with people. Ability to meet pressured deadlines and time constraints
- DCID 6/3 or ICD 503 and the Government's certification and accreditation process
Skills For Cyber Security Pen Tester Resume
- System methodologies including: clienUserver, web hosting, web content servers, policy servers, directory servers, firewalls, WAN, MAN, LAN, switches, and routers
- Windows, Linux, Unix, and Mac OS X
- Exposure to OWASP
- Certification in the field of Information Security CISSP, CISM, CEH, GIAC CPEN, OSCP, OSWE, CWAPT, GWAPT, or GWEB
- Produce high quality reports and recommendations for clients
Skills For Cloud Security Tester Resume
- Experience with information security policies and guidance and assisting in researching, evaluating, and developing relevant security policies and guidance
- Experience in conducting scans with security risk detection and compliance tools, providing analysis of the results, and suggesting mitigation plans for security problems
- Experience with programming, scripting languages, and exploitation development
- Responsible for implementing, tuning and maintenance of the tested cyber security product solutions
- Cybersecurity or Penetration Testing Certification in Security+, CISSP, or OSCP
- Technical depth in most of the following areas: LAMP stack, Node.js, Scala/Java, iOS, Android OS, Windows Mobile, web services