Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 44 guests and 1 member online
 
Advertisement

You are here: Home arrow Resourcesarrow Career Centralarrow Looking For Workarrow Experienced Consultant looking for side work
EH-Net
May 20, 2013, 01:01:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Experienced Consultant looking for side work  (Read 9051 times)
0 Members and 1 Guest are viewing this topic.
pseud0
Recruiters
Full Member
*
Offline Offline

Posts: 208



View Profile
« on: November 17, 2007, 08:49:49 PM »

Hello EHN community,
   I am an experienced penetration tester and computer forensics examiner looking for hourly or contract work.  I am physically located in the Midwest region of the US, but I can work remotely for any global region or time zone.  In addition to my technical skill set I have extensive experience producing professional formal reports, managing large scale engagements, and I regularly present to C level executives.  Currently I am a consultant for one of the Big-4 advisory firms where I manage their penetration testing and vulnerability assessment teams.  My full resume is available upon request.
EDUCATION:
-Bachelor's & Master's in Computer Science
-CISSP, CISM
TECHNICAL:
-BackTrack Suite, Metasploit, Paros, AppScan, Nessus, etc.
-EnCase, Helix, Autopsy, FTK
-C, C++, Ada, LISP, HTML/XML, Java, JavaScript
EXPERIENCE:
-(Present) Security Consultant
   --Multiple Fortune 100, State/Federal Government customers
        --Several international customers
-Manager of DoD SOC
-Air Intelligence Agency
-Air Force Office of Special Investigations
   --Computer Crimes Investigations
Logged

CISSP, CISM, CISA, GCIH, GREM, CEH, HMFIC, KTHXBIROFLCOPTER
andreacross
Recruiters
Newbie
*
Offline Offline

Posts: 5


View Profile WWW
« Reply #1 on: May 15, 2008, 06:12:52 PM »

hi there,

i am a technical recruiter looking specifically for security specialists. if you are still looking for opportunities, please feel free to contact me at ac[at]systegration[dot]com or 847-375-8700 x240.

thank you!

andrea cross
Logged

Senior Technical/Security Recruiter
LSOChris
Guest
« Reply #2 on: May 15, 2008, 10:53:09 PM »

will you be at chicagocon?
Logged
ideareboot
Recruiters
Newbie
*
Offline Offline

Posts: 6


View Profile
« Reply #3 on: November 05, 2009, 08:48:33 AM »

Hi ,

I am not sure about your availability for a new job.
Please let me know if you are available and interested in this position.
 
I can get you an interview latest by tomorrow morning.

Functional Security Testing
Remote with 20% travel
6+ months contract
•   Input validation bypass – Client side validation routines and bounds-checking restrictions are removed to ensure controls are implemented on all application parameters sent to the server.
•   SQL injection – Specially crafted SQL commands are submitted in input fields to validate input controls are in place to properly protect database data.
•   Cross-site scripting – Active content is submitted to the application in an attempt to cause a user's web browser to execute unauthorized and unfiltered code. This test is meant to validate user input controls.
•   Parameter tampering - Query strings, POST parameters, and hidden fields are modified in an attempt to gain unauthorized access to user data or application functionality.
•   Cookie poisoning – Data sent in cookies is modified in order to test application response to receiving unexpected cookie values.
•   Session hijacking – Client attempts to take over a session established by another user to assume the privileges of that user.
•   User privilege escalation – Client attempts to gain unauthorized access to administrator or other users’ privileges.
•   Credential manipulation – Client modifies identification and authorization credentials in an attempt to gain unauthorized access to other users’ data and application functionality.
•   Forceful browsing – Client enumerates files located on a web server in an attempt to access files and user data not explicitly shown to the user within the application interface.  
•   Backdoors and debug options – Many applications contain code left by developers for debugging purposes. Debugging code typically runs with a higher level of access, making it a target for potential exploitation. Application developers may leave backdoors in their code.  Client Business will identify these options that could potentially allow an intruder to gain additional levels of access.
•   Configuration subversion – Improperly configured web servers and application servers are common attack vectors.  Client assesses the software features, as well as the application and server configuration for poor configurations.
Tools
•   HP Software (Formally SPI Dynamics) WebInspect
•   Nessus (Infrastructure Testing)
•   Tamper Data
•   BurpSuite Pro



Regards,
________________________________________
Vikas Kanoongo
Recruitment | Sales

IdeaReboot
9055 SW 73rd CT, Unit 1409
Miami, Florida 33156 United States

vkanoongo@ideareboot.com | Work: 315.683.3001 | Fax: 305.397.2534

Join My Linkedin Network http://www.linkedin.com/in/vikaskanoongo
Follow our latest available jobs on Twitter http://twitter.com/ideareboot
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.065 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.