عبد الرشيد Baloch, Information Security Consultant/Specialist/Manager

عبد الرشيد Baloch

Information Security Consultant/Specialist/Manager

Evamp & Saanga

البلد
باكستان
التعليم
ماجستير, Information security
الخبرات
15 years, 2 أشهر

مشاركة سيرتي الذاتية

حظر المستخدم


الخبرة العملية

مجموع سنوات الخبرة :15 years, 2 أشهر

Information Security Consultant/Specialist/Manager في Evamp & Saanga
  • باكستان - إسلام أباد
  • أشغل هذه الوظيفة منذ أبريل 2015

As an Information Security Specialist I have been assigned role of technical lead for Information Security, especially application security and security management. My responsibilities include but are not limited to:
 Develop, assess and verify application security requirements and architecture for critical business and financial applications, including but not limited to mobile financial services, telecom customer self-care applications, B2B and B2C portals etc.
 To conduct application security reviews to identify policy non-compliance and security vulnerabilities in change management
 To communicate the solutions for identified vulnerabilities to stakeholders as per defined policies and contractual requirements and support them to ensure that vulnerabilities are fixed in timely manner without affecting project deadlines
 To responsibly disclose application vulnerabilities in 3rd party functionality and provide support and Proof of Concept attacks to fix the vulnerabilities.
 To ensure that security is integrated into System Development Life Cycle (SDLC)
 To design and implement security solutions and controls recommended by compliance audits.
 To develop and maintain information security guidelines, standards, policies and procedures
 Develop and maintain information security trainings and ISO 27001 security standard compliance reporting

Information Security Researcher في National University of Science and Technology
  • باكستان - إسلام أباد
  • سبتمبر 2011 إلى يونيو 2015

Computer Security
Advance Networks and Web Security
Wireless Networks Security
IT Laws and Computer Forensics
Information Security Management
Information Security Evaluation and auditing
Vulnerability Exploitation and Defense
Information Security Project Management
Cryptography

Web Developer في webhive
  • باكستان - إسلام أباد
  • أبريل 2010 إلى سبتمبر 2012

Worked on a number of websites using:
Custom PHP
Content Management Systems e.g. Wordpress
MVC Frameworks such as Codeigniter
Various Shopping Cart Scripts such as Pinnacle Cart, Open Cart and a few Custom Carts
Different modules and routine based tasks.
Plug-in development, template/theme integration
Payment method integration, Ecommerce Sites customization (Frontend and database)
Search Engine Optimization
Testing and vulnerability assessment of web Applications and applying proper controls to fix the vulnerabilities.

Web developer في Gensoft
  • باكستان - حيدر أباد
  • يناير 2008 إلى يناير 2009

Dynamic HTML Web Pages
Cascaded Style Sheets
JavaScript validation in web forms
Website Content Management

الخلفية التعليمية

ماجستير, Information security
  • في National University of Science and Technology
  • يوليو 2015

Information Security Assurance Information Security Evaluation and auditing Vulnerability Research and Exploitation Penetration Testing Risk Management Source Code Auditing Digital Forensics Cryptography Information Security Project Management Wireless Network Security

بكالوريوس, Information Technology
  • في University of Sindh
  • ديسمبر 2007

During 4 years of Bachelor of Science in Information Technology a number of course were taught regarding Computer Software/Hardware and Programming, Applications of IT to business.

Specialties & Skills

Computer Security
Information Security Management
Vulnerability Management
Application Security
Security Monitoring
Information Security
OWASP Application Security Methodlogies
Mobile Financial Solutions Security
Mobile Application Penetration Testing
Web Application Penetration Testing
Application Security Architecture
Information Security Management

اللغات

الانجليزية
متمرّس

التدريب و الشهادات

Computer Hacking Forensic Investigator (الشهادة)
تاريخ الدورة:
September 2014
صالحة لغاية:
September 2017
Certified Ethical Hacker (الشهادة)
تاريخ الدورة:
August 2015
صالحة لغاية:
August 2018
Workshop on Ethical Hacking (الشهادة)
تاريخ الدورة:
December 2009
صالحة لغاية:
December 2009
Workshop on Information Security Tools and Techniques (الشهادة)
تاريخ الدورة:
October 2011
صالحة لغاية:
October 2011