[go: up one dir, main page]

0% found this document useful (0 votes)
52 views1 page

ShivanshSrivastava Resume

Research paper

Uploaded by

ayushkumar95710
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
52 views1 page

ShivanshSrivastava Resume

Research paper

Uploaded by

ayushkumar95710
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 1

Shivansh Srivastava

+91 9026963314 · shivansh.srivastava1912@gmail.com


Lucknow, Uttar Pradesh
https://www.linkedin.com/in/shivansh-srivastava19/

CYBERSECURITY CONSULTANT

Cyber Security and Risk Management Consultant with expertise in application security testing (mobile &
web), SAST/DAST, Grey box and Black box testing, source code review, API security testing, vulnerability
assessments, penetration testing, and data forensics readiness assessments. Proven ability to identify,
analyze, and report security vulnerabilities across various platforms and applications. Skilled in utilizing
industry-standard tools and methodologies to ensure a robust security posture. Currently, at PwC, working
closely on multiple large-scale applications to assess and recommend impactful risk mitigations as per the
client IS policy and regulatory compliance. I have identified and reported vulnerabilities for multiple BFSI
sector clients.

KEY COMPETENCIES
Application Security Testing (Mobile & Web - Burp Suite Community and Professional, Mobsf, Frida, Metasploit, Nmap,
Dirb)
Source Code Review (Fortify Audit Workbench, Mobsf)
API Security Testing (Postman, SoapUI, Burp Suite)
Vulnerability Assessment (Nessus, Nmap, Dirb)
Penetration Testing (Kali Linux, Burp Suite, Nmap, Sqlmap, Dirb, Metasploit, Wireshark)
Data Forensics Readiness Assessment
Process Review (Operational, Procedural, Administrative Security)
Secure Network Architecture and Firewall Access Rules (FAR) Review for 2-tier and 3-tier applications

PROFESSIONAL EXPERIENCE
PricewaterhouseCoopers Services LLP (PwC India) Feb 2023 - Present
Cybersecurity Consultant
Performed application security testing, SAST/DAST, source code reviews, VAPT, digital forensics readiness,
and process reviews for multiple projects for leading scheduled commercial bank in the BFSI sector.
Thorough risk assessments I performed for multiple clients involved hands-on with testing tools like Kali
Linux, Burp Suite, Postman, Nmap, Dirb, Mobsf, Frida, etc. I have performed 40+ application security testing
(grey box and black box) for multiple clients for internal and internet applications, covering OWASP 10 and
SANS 25 listed vulnerabilities. Furthermore, I have performed Process Reviews covering up enterprise-level
security compliance as per the information security policies of the client and regulatory compliances for
multiple applications and departments.

DataClog (CloFra Cloud Pvt Ltd) Jun 2022 - September 2022


Software Engineer
Built client-side interface for the enterprise-level application using Reactjs + Typescript to integrate the
services and functionality with Java backend and multiple API(s) integrations. Utilized external UI libraries and
packages to achieve application flexibility, and interactiveness and maintain scalability.

EDUCATION & CERTIFICATIONS CERTIFICATIONS

Chandigarh University Certified Ethical Hacker (CEH) by EC-Council


Master of Computer Applications (2022 - 2024) Feb 2024 - Feb 2027
University Of Lucknow ISO 27001 LI
Bachelor of Computer Applications (2018 - 2021)

You might also like